One very trivial upside of the pandemic for me is that I only have to file taxes in 2020 in one state, unlike the usual 3 or 4.

I learned today that my youngest son’s prom is not going to happen this year. Sad because it was also cancelled last year, and this is his final year of high school. Cancelling is likely the right thing to do, but sad for him that it had to happen.

...and we're back. hopefully no more changes for a while.

How long does it usually take you to fall asleep?

Feel free to expand on your answer as a reply

Boost for a larger sample size 💕 is getting a new IP soon. Site will be unstable tomorrow for a while during DNS propagation.

Can't recall which feed I saw this in, but I love this approach to laptop design. If they offer the same in a 15-16" form factor, I think I've found my eventual next laptop

Yo! $DayJob is looking for to recruit security researchers, developers, engineers team leaders and more to join the team. Seriously...hit me up and I can give you more intel.

has anyone played around with ebpf? The feed of exec() and open() calls seems quite useful from a security monitoring perspective

bullshit levels are currently at 84% but fluctuating wildly

(84%) ■■■■■■■■□□

Mitigating Web Shells

This repository houses a number of tools and signatures to help defend networks against web shell malware. More information about web shells and the analytics used by the tools here is available in NSA and ASD web shell mitigation guidance Detect and Prevent Web Shell Malware.

I'm hiring two Principal Security Researchers to join my Applied Research Team at Veracode. One focused on application static analysis and auto-remediation, one focused on dynamic analysis of web apps and web APIs.

My team is fully remote always (we have team members in EU, UK, US so far), great support for education (including attending conferences), pursuing your own projects, flexible scheduling, etc.

Boosts appreciated!

More info:

YAML configs for:

1. NSA Events to Monitor List

2. Events from the Windows 10 and Windows Server 2016 Security auditing and monitoring reference

3. Exploit protection events based on attack surface reduction events

And, which Windows auditing events require failure and success logging?


I have a few more to share next week.

I did not have on my bingo card “Wall Street traders monitor Reddit memes for clues to next breakout stock”

In other news, This is going to be my bug out spot soon.

Not very good for a bugout spot, but it does have a nice view.

Forgot to announce that the upgrade completed successfully. Currently pruning preview cards and old remote media - freed up >150GB so far 😅

Upgrading to Mastodon 3.3.0. Hold on to your hats...

Shifting Cloud Security Left — Scanning Infrastructure as Code for Security Issues

Nice overview of a number of tools (Checkov, Regula, Terraform-compliance, Terrascan, tfsec) with examples of custom check writing and more.

us pol 

Dept of State says that Trump's term ends tonight at 7:49PM. Definitely a defaced website, but we can dream.

