mcp's Avatar

mcp

@securitydumpster

Opportunity Threat Hunter | Recovering snowboarder | my views are my own

34
Followers
183
Following
6
Posts
14.11.2024
Joined
Posts Following

Latest posts by mcp @securitydumpster

Preview
Phishing platform Rockstar 2FA trips, and “FlowerStorm” picks up the pieces A sudden disruption of a major phishing-as-a-service provider leads to the rise of another…that looks very familiar

Just put out this research on MiTM PaaS kits labeled Rockstar and Flowerstorm over the past few months. While my name is on this I partnered with two researchers, Josh Rawles and Jordon Olness who did a bulk of the work alongside @thepacketrat.net, and Colin Cowie who are all individually brilliant!

19.12.2024 16:17 👍 4 🔁 2 💬 1 📌 0
Malspace | Operation Crimson Palace On this episode, Mark Parsons, Senior Threat Hunter at Sophos MDR, discusses his team's investigation into Operation Crimson Palace, which uncovered Chinese state-sponsored cyberespionage targeting...

Excited to share that I was on the finale episode of Malspace to discuss Operation Crimson Palace, a year and a half long intrusion into a government agency located in Southeastern Asia, where we identified 3 PRC-aligned apt actors operating within the same environment simultaneously #cti #apt

10.12.2024 03:24 👍 1 🔁 0 💬 0 📌 0
Preview
a cartoon character giving an ok sign with his hand ALT: a cartoon character giving an ok sign with his hand
29.11.2024 18:34 👍 0 🔁 0 💬 0 📌 0
Preview
Dissecting JA4H for improved Sliver C2 detections Background On November 18, 2024, Palo Alto Networks announced the discovery of two critical vulnerabilities, CVE-2024-0012 and CVE-2024-9474, in the operating system that powers their firewall device...

I love posts like this one, sharing out easily translate-able methods, like the cc recipe for gen’ing ur own hashes

29.11.2024 18:34 👍 1 🔁 0 💬 1 📌 0
Preview
two men are standing next to each other with the words " we open it up " on the screen ALT: two men are standing next to each other with the words " we open it up " on the screen

#PIVOTcon25 registration is now OPEN 🤟📥📥📥
pivotcon.org
#CTI #ThreatResearch #ThreatIntel
Please read carefully the whole 🧵 for the rules about invite -> registration (1/5)

19.11.2024 14:00 👍 42 🔁 22 💬 2 📌 11
Preview
Hawt Hot GIF ALT: Hawt Hot GIF

Me when I saw the theatre showing The Fifth Element on a random Sunday night

18.11.2024 00:02 👍 0 🔁 0 💬 0 📌 0
Talks My talks in different conferences.

My Microsoft BlueHat talk "Deprecating Azure AD Graph API is Easy and Other Lies We Tell Ourselves" is now on Youtube!
Link to recording & slide deck at aadinternals.com/talks/

11.11.2024 23:20 👍 11 🔁 2 💬 1 📌 0
Post image

Researchers say Twitter changed its algorithm to promote Elon Musk and Republican posts leading up to the election.

"The date at which [the spike] in engagement occurs coincides with Elon Musk's formal endorsement of Donald Trump on 13th July 2024." eprints.qut.edu.au/253211/

13.11.2024 12:39 👍 1276 🔁 549 💬 99 📌 134
BlueHat 2024: S13: Patterns in the Shadows: Scaling Threat Hunting & Intel for Modern Adversaries
BlueHat 2024: S13: Patterns in the Shadows: Scaling Threat Hunting & Intel for Modern Adversaries YouTube video by Microsoft Security Response Center (MSRC)

Check out my most recent talk on scaling threat hunting and threat intelligence at this years BlueHat! youtu.be/n7GVxDxwOUc?...

16.11.2024 13:41 👍 1 🔁 0 💬 0 📌 0
Video thumbnail

Here's why Adam thinks a Linux malware variant that recently turned up in Russia was probably developed by Western SIGINT. More details in this week's Risky Business podcast, available on YouTube (www.youtube.com/watch?v=s7iP...) or wherever you get your audio podcasts...

13.11.2024 23:35 👍 19 🔁 2 💬 0 📌 1