1337bash's profile picture. I hunt for a living. I like breadcrumbs.
Views expressed are my own.

Bashar

@1337bash

I hunt for a living. I like breadcrumbs. Views expressed are my own.

Pinned

My talk @BSidesSATX about building a NextGen Home Lab is out on YouTube. Go watch it now! Thanks again to @BSidesSATX for having me and for all your efforts to provide these recordings to the community. Most of this year's talks are on their channel. youtube.com/watch?v=ex0esb…

1337bash's tweet card. From Kali and a Couple of VMs to NextGen Home Lab - An Approach to...

youtube.com

YouTube

From Kali and a Couple of VMs to NextGen Home Lab - An Approach to...


Bashar reposted

Free Offensive Security Notes (OSCP, OSWE, OSEP, OSED) OSCP NOTES AD: drive.google.com/file/d/14jirVK… OSCP Notes : drive.google.com/file/d/1eYUaea… OSWE Notes: drive.google.com/file/d/1KIc_qs… OSEP Notes: drive.google.com/file/d/1L9mfwf… OSED Notes: drive.google.com/file/d/1_mPHr3… #oscp #osed #oswe #osep #osce³

TheMsterDoctor1's tweet image. Free Offensive Security Notes (OSCP, OSWE, OSEP, OSED)

OSCP NOTES AD:
drive.google.com/file/d/14jirVK…

OSCP Notes :
drive.google.com/file/d/1eYUaea…

OSWE Notes:
drive.google.com/file/d/1KIc_qs…

OSEP Notes:
drive.google.com/file/d/1L9mfwf…

OSED Notes:
drive.google.com/file/d/1_mPHr3…

#oscp #osed #oswe #osep #osce³…
TheMsterDoctor1's tweet image. Free Offensive Security Notes (OSCP, OSWE, OSEP, OSED)

OSCP NOTES AD:
drive.google.com/file/d/14jirVK…

OSCP Notes :
drive.google.com/file/d/1eYUaea…

OSWE Notes:
drive.google.com/file/d/1KIc_qs…

OSEP Notes:
drive.google.com/file/d/1L9mfwf…

OSED Notes:
drive.google.com/file/d/1_mPHr3…

#oscp #osed #oswe #osep #osce³…
TheMsterDoctor1's tweet image. Free Offensive Security Notes (OSCP, OSWE, OSEP, OSED)

OSCP NOTES AD:
drive.google.com/file/d/14jirVK…

OSCP Notes :
drive.google.com/file/d/1eYUaea…

OSWE Notes:
drive.google.com/file/d/1KIc_qs…

OSEP Notes:
drive.google.com/file/d/1L9mfwf…

OSED Notes:
drive.google.com/file/d/1_mPHr3…

#oscp #osed #oswe #osep #osce³…
TheMsterDoctor1's tweet image. Free Offensive Security Notes (OSCP, OSWE, OSEP, OSED)

OSCP NOTES AD:
drive.google.com/file/d/14jirVK…

OSCP Notes :
drive.google.com/file/d/1eYUaea…

OSWE Notes:
drive.google.com/file/d/1KIc_qs…

OSEP Notes:
drive.google.com/file/d/1L9mfwf…

OSED Notes:
drive.google.com/file/d/1_mPHr3…

#oscp #osed #oswe #osep #osce³…

Bashar reposted

Business email compromise doesn't get the same coverage as other cyber attacks, but it's still ubiquitous. If you use Sentinel or M365 Defender this article from @PeteABryan is an absolute must read. Great queries, guidance and threat intelligence for BEC- techcommunity.microsoft.com/t5/microsoft-s…


Bashar reposted

More than half of the breaches investigated by @StrozDFIR in 2022 included phishing as an initial access technique. Learn more about evolving #phishing techniques in our latest blog where we talk about brand impersonation, consent phishing, and the usage of phishing kits.…

StrozDFIR's tweet image. More than half of the breaches investigated by @StrozDFIR  in 2022 included phishing as an initial access technique. Learn more about evolving #phishing techniques in our latest blog where we talk about brand impersonation, consent phishing, and the usage of phishing kits.…

Bashar reposted

New blog post! I love when adversaries use VHD files to distribute malware because VHDs can potentially contain a lot more data than the adversary intends to distribute. To see what I mean, check out this post: forensicitguy.github.io/vhd-malware-an… #malware #vhd


Bashar reposted

Nice series here >> Hunting for Persistence in Linux (Part 1): Auditd, Sysmon, Osquery (and Webshells) pberba.github.io/security/2021/… (and good summary map in pberba.github.io/assets/posts/c…)


Bashar reposted

Citrix Gateway VPN compromised via CVE-2023-3519 (a critical unauthenticated RCE) shows evidence of exploitation on 7th July, 11 days before the official patch. The attackers exfiltrated the system configuration file to then probably use the Metasploit module called…

1ZRR4H's tweet image. Citrix Gateway VPN compromised via CVE-2023-3519 (a critical unauthenticated RCE) shows evidence of exploitation on 7th July, 11 days before the official patch.

The attackers exfiltrated the system configuration file to then probably use the Metasploit module called…
1ZRR4H's tweet image. Citrix Gateway VPN compromised via CVE-2023-3519 (a critical unauthenticated RCE) shows evidence of exploitation on 7th July, 11 days before the official patch.

The attackers exfiltrated the system configuration file to then probably use the Metasploit module called…
1ZRR4H's tweet image. Citrix Gateway VPN compromised via CVE-2023-3519 (a critical unauthenticated RCE) shows evidence of exploitation on 7th July, 11 days before the official patch.

The attackers exfiltrated the system configuration file to then probably use the Metasploit module called…
1ZRR4H's tweet image. Citrix Gateway VPN compromised via CVE-2023-3519 (a critical unauthenticated RCE) shows evidence of exploitation on 7th July, 11 days before the official patch.

The attackers exfiltrated the system configuration file to then probably use the Metasploit module called…

Bashar reposted

Citrix NetScaler ADC CVE-2023-3519 resources -- Compromise Assessments @CISAgov advisory cisa.gov/sites/default/… Deyda guide deyda.net/index.php/en/2… -- Vuln Checks Python github.com/telekom-securi… Nmap NSE script github.com/RootUp/Persona… I'm gonna add more links in this🧵


Bashar reposted

Yesterday, I presented @jsecurity101 and my Malware Morphology workshop at @NorthSec_io. Thanks to the organizers and everyone who attended. If you missed it, you’re in luck the recording is available! 📼 Video: youtube.com/live/KTAeUjDBW… 🗒️ GitHub: github.com/jaredcatkinson…


Bashar reposted

Today, me and @ateixei are releasing the EDR Telemetry project. This project aims to compare and evaluate the telemetry of various EDR products. ✅Introductory blog post: t.ly/9Ia3 ✅GitHub Repo: github.com/tsale/EDR-Tele… ✅Comparison Table: t.ly/HMht


Bashar reposted

PSA: Major new Timesketch release - the open source #DFIR timeline analysis platform. We have been working on redesigning and improving the user experience. 🧵Thread with screenshots:


Bashar reposted

Some really great sites you should bookmark loldrivers.io (just released) gtfobins.github.io lolbas-project.github.io lots-project.com filesec.io malapi.io


Bashar reposted

Hey defense & blue team people ICYMI Kali released Kali Purple which is essentially SOC in a box with cool tools like TheHive, Suricata, Arkime, Elastic SIEM & Malcolm all bundled together & makes a great starting tool for getting defenses up gitlab.com/kalilinux/kali…


Bashar reposted

Hey #DFIR community... if you want to play with some basic Anti-Forensic stuff related to the NTFS file system, please check the challenge me & @maryst33d created. I don't want to spoil it, but there is probably something in it that not many know about! ashemery.com/dfir.html#Chal…


Bashar reposted

schtasks /create /tn "Task Name" /tr "C:\path\to\program.exe" /sc onstart /ru SYSTEM

UK_Daniel_Card's tweet image. schtasks /create /tn "Task Name" /tr "C:\path\to\program.exe" /sc onstart /ru SYSTEM

Bashar reposted

❗Exciting news!❗ We've published nearly all the #BlueHat 2023 videos on the Microsoft Security Response Center (MSRC) YouTube channel. Happy viewing! 📺 msft.it/60195lV6Z


Bashar reposted

"Parsing Multiple Registry Hives using VSC Toolset and RegRipper" #DFIR Probably one of those underrated tools that I really think you should check!... Hopefully this video will convince you to start using it in your investigations. Thanks @jasonshale youtube.com/watch?v=LokqW4…

binaryz0ne's tweet card. Parsing Multiple Registry Hives using VSCToolset and RegRipper

youtube.com

YouTube

Parsing Multiple Registry Hives using VSCToolset and RegRipper


Bashar reposted

The following 5 workshops simulate multiple security events. Brought to you by the AWS Customer Incident Response Team (CIRT) 👇


Bashar reposted

Great new tool by @bananabr to find folders excluded from antivirus scanning by comparing file write times across tested folders. Writes to excluded folders finish much faster as they don't have their writes intercepted by AV. Clever! github.com/bananabr/TimeE…


Bashar reposted

here are the slides from the talk @eric_capuano and i gave at @cactuscon on "Security Operations with Velociraptor": reconis.co/secops_with_vr you can watch the stream here: reconis.co/secops_with_vr… #CC11 #CactusCon #DFIR #infosec #secops #velociraptor @velocidex @Recon_InfoSec

shortxstack's tweet image. here are the slides from the talk @eric_capuano and i gave at @cactuscon on "Security Operations with Velociraptor": reconis.co/secops_with_vr

you can watch the stream here: reconis.co/secops_with_vr…

#CC11 #CactusCon #DFIR #infosec #secops #velociraptor @velocidex @Recon_InfoSec

Loading...

Something went wrong.


Something went wrong.