Twitter | Pretraživanje | |
Emily
DFIR | honeypots | blueteam | MiSec
527
Tweetovi
1.055
Pratim
286
Osobe koje vas prate
Tweetovi
Emily proslijedio/la je tweet
Richard Gold 28. sij
1. Windows Defender 2. EDR 3. Automated defanging of documents 4. Disabling macros, OLE, DDE, etc. 5. Disabling Windows Script Hosting 6. Private VLANs 7. Application whitelisting 8. Users not being local admins 9. 2FA on everything 10. Up-to-date patching
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
alexia 26. sij
I don’t know who needs to hear this, but working on documentation IS NOT A WASTE OF TIME. Quality documentation will help your project proceed efficiently now and in the future.
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
................................................🥰 26. sij
Come sign up for & I's training at in May! Just think DnD mixed with tabletops. It's team vs team in who can survive the longest. You might end up in the CEO role to make some hard decisions! Follow for more
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
Teagan™ 25. sij
If you're not retaining things like DHCP logs, DNS logs, RDP logs, some kind of internal network monitoring/visibility, you should do that. Trying to hunt through 2 month old traffic is hard when you can't correlate IP to Endpoint because DHCP.
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
All Purpose Cultural Chat Girl Emily 24. sij
The Western European medieval mind generally believed the world was coming to an immediate end and that they lived in the end times among the inscrutable ruins of a once-splendorous ancient world. And for this reason progress itself was not conceivable. I think about this a lot.
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
ARBSEC 24. sij
Don't forget - both registration and the Call for Papers for A2Y.asm 2020 are *open*! CFP closes Feb 29. Also, we are looking for sponsors. Info/reg/CFP at
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
SpecterOps 22. sij
Odgovor korisniku/ci @SpecterOps
Here is the link to the SpecterOps Adversary Tactics: PowerShell course material: Enjoy! For information about our current training offerings, information can be found here: (4/4)
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
Br Br 22. sij
Odgovor korisniku/ci @honeycombio @lizthegrey i 3 ostali
So glad we got to spend some time w/ & if you have a chance to see her speak, make the time. You'll learn something. Also, check out her Also, Check out on podcast w/ &
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
Randy Olson 11. sij
The video game "VVVVVV" went today and someone discovered a several-hundred-case switch statement in the code. Beautiful. Disgusting. Source:
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
Ben Goerz 4. sij
Hey SIEM owners: How do you handle documentation & change control for your SIEM rule content?
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
Picard Tips 25. pro
Picard holiday tip: Religion and commercialism will both fade over generations. Generosity and kindness, however, will endure.
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
Amy Renee 24. pro
I, for one, welcome our festive Christmas tree overlords. 🎄🎄🎄😂
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
Anton Nesterov 12. pro
Seems like Rambler filled copyright claim to regarding , nginx office under police raid (unconfirmed). Originally posted by , but somebody asked him to remove his post.
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
Tinker 12. pro
Him: Just grabbed the domain admin’s *user* password. Me: Give it. Let’s see if they reused the pass for their DA account. Him: Surely, they wouldn’t. Me, looking at my access: They would. And don’t call me Shirley.
Reply Retweet Označi sa "sviđa mi se"
Emily 12. pro
Reply Retweet Označi sa "sviđa mi se"
Emily 11. pro
Odgovor korisniku/ci @IanColdwater
👋
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
Jake Williams 10. pro
The containment phase of incident response when you've got a worm in the network.
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
Ian Anderson 7. pro
Cool. This is something normal people know how to do with zero problems.
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
SwiftOnSecurity 5. pro
Odgovor korisniku/ci @SwiftOnSecurity
Smooth user migration between computers is almost literally indistinguishable from ransomware defense.
Reply Retweet Označi sa "sviđa mi se"
Emily proslijedio/la je tweet
Joseph Cox 4. pro
if anyone has done forensics on prison butt phones my DMs are open if you want to talk about it (i'm not joking, that would be interesting)
Reply Retweet Označi sa "sviđa mi se"