Pinned toot

Just a reminder, you can support infosec.exchange through liberapay: liberapay.com/Infosec.exchange

Thanks!

Jerry Bell boosted

Everything is fake now and we seem weirdly okay with it

Jerry Bell boosted

m4iler.cloud/2021/04/09/fb-lea Here is another shout in the void! Hope you enjoy it and roast me for all the places where I'm wrong (seriously, I want this to be correct and if I'm not, it's worthless).

Also, thanks @jerry for providing me a lovely quote!

Jerry Bell boosted

Everything you wanted to know about Exchange Zero Days, but were afraid to ask.

Microsoft Exchange Zero Day's - Mitigations and Detections. - Blue Team Blog

blueteamblog.com/microsoft-exc

In more relevant news, I did not realize it was an option to blame the intern

I am quite excited that I now own the place I took this picture from. And get to visit it this week. 🏄🌞

One very trivial upside of the pandemic for me is that I only have to file taxes in 2020 in one state, unlike the usual 3 or 4.

I learned today that my youngest son’s prom is not going to happen this year. Sad because it was also cancelled last year, and this is his final year of high school. Cancelling is likely the right thing to do, but sad for him that it had to happen.

...and we're back. hopefully no more changes for a while.

Jerry Bell boosted

How long does it usually take you to fall asleep?

Feel free to expand on your answer as a reply

Boost for a larger sample size 💕

Infosec.exchange is getting a new IP soon. Site will be unstable tomorrow for a while during DNS propagation.

Jerry Bell boosted

Can't recall which feed I saw this in, but I love this approach to laptop design. If they offer the same in a 15-16" form factor, I think I've found my eventual next laptop

frame.work/blog/introducing-th

Jerry Bell boosted

Yo! $DayJob is looking for to recruit security researchers, developers, engineers team leaders and more to join the team. Seriously...hit me up and I can give you more intel.

has anyone played around with ebpf? The feed of exec() and open() calls seems quite useful from a security monitoring perspective

Jerry Bell boosted

bullshit levels are currently at 84% but fluctuating wildly

(84%) ■■■■■■■■□□

Jerry Bell boosted

Mitigating Web Shells

This repository houses a number of tools and signatures to help defend networks against web shell malware. More information about web shells and the analytics used by the tools here is available in NSA and ASD web shell mitigation guidance Detect and Prevent Web Shell Malware.

github.com/nsacyber/Mitigating

Jerry Bell boosted

I'm hiring two Principal Security Researchers to join my Applied Research Team at Veracode. One focused on application static analysis and auto-remediation, one focused on dynamic analysis of web apps and web APIs.

My team is fully remote always (we have team members in EU, UK, US so far), great support for education (including attending conferences), pursuing your own projects, flexible scheduling, etc.

Boosts appreciated!

More info: mobile.twitter.com/chriseng/st

Jerry Bell boosted

YAML configs for:

1. NSA Events to Monitor List hannahsuarez.github.io/2021/Wi

2. Events from the Windows 10 and Windows Server 2016 Security auditing and monitoring reference hannahsuarez.github.io/2021/Wi

3. Exploit protection events based on attack surface reduction events hannahsuarez.github.io/2021/Ex

And, which Windows auditing events require failure and success logging?
hannahsuarez.github.io/2021/Wh

YMMV!

I have a few more to share next week.

Show older
Infosec Exchange

A Mastodon instance for info/cyber security-minded people.