Deepfakes are here. Hopefully, a public armed with knowledge, and a healthy dose of critical thinking, will be able to defend themselves against it.

Spot the Deepfake

Spotting deepfakes isn’t as easy as you might think. Learn more about it at

Makes sense. MITRE is now trying to map their ATTACK framework to actual defence tactics.

Example is on exfiltration.

Intro to Hunting Adversaries Using the Attack Lifecycle Methodology
Indicator of Emulation
Leveraging Critical YARA Skills
Low Value Indicators For High Value Decisions
Practical Advice on Threat Hunting Panel
Incident Response & ATT&CK Matrix

My village list!

@R10T Sure. — {OS,GEO}INT, investigative journalism, natsec — natsec, geopolitics — infosec, disinfo — privacy, security, tech policy — security, threat intel — counter-intelligence

I understand none of these sites are technical in nature, but I felt the technical stuff is all too common—just browse r/netsec, if that's what you're looking for. :)

Top 30+ Best Blue Team Tools

A collection of best blue team tools to enrich your security toolkit. Discover different honeypots, incident response, threat hunting and other defensive tools.

Leonidas, a framework for executing attacker actions in the cloud. It provides a YAML-based format for defining cloud attacker tactics, techniques and procedures (TTPs) and their associated detection properties.

Developed and released by F-Secure Labs

I definitely trust my DNS provider - NextDNS - more than my ISP. This is because I willfully chose them after doing research and I also pay for the service to support them and keep them providing me with the tools to filter out crap and transparently show me what is happening on my networks.

Encrypted DNS Query Transports and Their Trust Models – Asinine Tech

@sillystring Yeah very interesting area. I found out recently that RDAP is becoming the next or sucessor of whois

VirusTotal and ThreatConnect is good for the community availability. Also passive Dns offerings, and a couple more that is paid/enterprise solutions.

Good luck with the threat hunting

Pandemics & Propaganda: How Chinese State Media Creates and Propagates CCP Coronavirus Narratives | HKS Misinformation Review

To gain insight into how Chinese state media is communicating about the coronavirus pandemic to the outside world, we analyzed a collection of posts from their English-language presence on Facebook.

Udemy (momentarily free)

- Computer from Scratch to Advanced:

- , , - Certification Course:

- the Boring Stuff with Programming:

- Pass Solutions Architect Associate in first attempt:

- Masterclass - Beginner to Expert:

Coping with a lot personally, but meanwhile everyone be safe and stay sane. If you can muster it, it is a *hell* of a time to read and study, and do.

"Fox Kitten" Campaign

Info on techniques/methods:

Pre-access/Access Tools:
VPN system vulnerabilities
A pre-access tool

Local priv esc tools
Juicy Potato, Procdump, Mimikatz, Sticky Keys, other accessibility tools settings, local admin user

Lateral movement tools:
STSRCheck, port.exe, Invoke the Hash

Backdoor/C&C tools:
POWSSHNET, socket based backdoor for socket opening, servo, Ngrok, FRP, webshells, archives (winrar, z-zip)


Thank you @kde for all your work on KDE & Plasma. Thank you @mozilla for Firefox. Thank you to all the kernel hackers for their restless work on the Linux kernel. Thank you to everyone involved working on the GNU tools! Thank you to all the devs working on libraries and the backend, who clearly get to little love!


Is anyone having weird issues with the Barracuda RBL?

