#PurpleTeam | Ex @RaytheonTech MSSP, @SCYTHE_IO, & @GD_OTS | Taught at BlackHat & DEFCON | #100DaysofSigma | Keep exploring, keep learning, and stay curious

Joined May 2020
1,944 Photos and videos
Pinned Tweet
My SANS Purple Team Series: Threat-Informed Detection Engineering Webinar with @jorgeorchilles is on YouTube! Video: youtu.be/2czm8dhziX8 Blog post: sans.org/blog/purple-teaming…
30
99
17,915
What do you call a technique that’s documented in the popular CTI framework?
67% ATT&CK Technique
33% MITRE Technique
6 votes • Final results
2
2
382
Pretty interesting: retrieves the command-and-control (C2) domain from a blockchain smart contract. Instead of hardcoding the server address... queries multiple Polygon RPC endpoints defined in CONTRACT_CONFIG.RPC_HOSTS levelblue.com/blogs/spiderla…
1
265
GenAI hype - when will we hit peak ignorance?
1
2
787
Christopher Peacock retweeted
Dropping a new tool today: TTPRunner - One-click Vectr deploy - Give it a threat report, PDF, or just plain-english instructions and it'll build an execution & simulation plan for you - Executions are tracked via notes and automatically sync'd with Vectr Works great with: github.com/Antonlovesdnb/Con… Check it out! 🔽 github.com/Antonlovesdnb/TTP…
4
39
148
18,153
Christopher Peacock retweeted
Feb 12
Can LNK files ever be trusted? ⚡ My latest blog post demonstrates several new LNK abuse methods, allowing you to fully spoof the target shown in Explorer. It also introduces tools to create your own LNKs, and detected spoofed ones yourself. 🐬 wietzebeukema.nl/blog/trust-…
11
202
937
139,268
AI can help build C2s and payloads, but often this seems to be the case.
1
274
“Benchmarked frontier AI models on realistic SecOps tasks using Cotool’s agent harness and the Splunk BOTSv3 dataset. GPT-5 achieved the highest accuracy (63%), while Claude Haiku-4.5 completed tasks the fastest with strong accuracy.“ cotool.ai/blog/evaluating-ai…

1
314
👀
PowerShell has a list of suspicious keywords. If found in a script block an automatic 4104 event will be generated regardless of logging policy :) (True for both PWSH 5/7) Look for EID 4104 with Level 3 (Warning) Full List: gist.github.com/nasbench/50c…
349
Christopher Peacock retweeted
🎄 It’s time! The 2025 SANS Holiday Hack Challenge is officially OPEN! Something’s off in the neighborhood… disappearing items, strange sightings, a chill in the air. ❄️ Can you uncover what’s really going on? Play now 👉 sans.org/u/1D01 #HolidayHackChallenge
1
13
28
3,753
IP2LoRa Meshtastic 👀
533
Christopher Peacock retweeted
30 Jul 2025
If you have Active Directory Certificate Services (ADCS) in your environment, run Locksmith now! In Active Directory Security Assessments, we have found critical security issues in *most* ADCS configurations. The great thing about Locksmith is that it doesn't just highlight the security issues in your ADCS environment, but also provides the command to remediate it! If you're a pentester/red teamer, Locksmith is great for you to provide remediation recommendations to your customers. github.com/jakehildreth/Lock… #ActiveDirectorySecurityTip
8
262
1,022
67,004
Christopher Peacock retweeted
Microsoft is aware of active attacks targeting on-premises SharePoint Server customers, exploiting a variant of CVE-2025-49706. This vulnerability has been assigned CVE-2025-53770. We have outlined mitigations and detections in our blog. Our team is working urgently to release a security update and will share more details as they become available. Read the full guidance in our blog: msft.it/6013s8oCc
3
103
228
76,453
Christopher Peacock retweeted
Interesting malware analysis from NCSC on AUTHENTIC ANTICS ncsc.gov.uk/static-assets/do…

3
17
75
7,691