MarcusDevPlus's profile picture. Security, Coding, Debugging and what's in between 🎩
#SecDevOps #AppSec #InfoSec

Marcus

@MarcusDevPlus

Security, Coding, Debugging and what's in between 🎩 #SecDevOps #AppSec #InfoSec

Marcus reposted

Current CVE-2021-1675 remediation advice:

JGamblin's tweet image. Current CVE-2021-1675 remediation advice:

Marcus reposted

Making sense of #PrintNightmare. A flowchart to help understand exploitation of CVE-2021-34527. Special thanks to @tiraniddo, @dez_, @gentilkiwi and @_f0rgetting_ for their test input and insights.

StanHacked's tweet image. Making sense of #PrintNightmare. A flowchart to help understand exploitation of CVE-2021-34527. 

Special thanks to @tiraniddo, @dez_, @gentilkiwi and @_f0rgetting_ for their test input and insights.

Javascript programmers should not call themselves Software Engineers... they only write scripts 🪠🌽


Marcus reposted

nice trick to avoid suspicious powershell command line

SBousseaden's tweet image. nice trick to avoid suspicious powershell command line
SBousseaden's tweet image. nice trick to avoid suspicious powershell command line

Marcus reposted

Due to issues with @gumroad and their slow support, I will push the updates manually to all clients


Marcus reposted

Best place is to start at docs.elementscompiler.com. And also remobjects.com/tv. Happy to help here or in talk.remobjects.com if you have more questions!


Marcus reposted

I can't stop laughing at this.

gabsmashh's tweet image. I can't stop laughing at this.

Marcus reposted

Time breakdown of a modern red team engagement. 😁

curi0usJack's tweet image. Time breakdown of a modern red team engagement. 😁

Marcus reposted

Niah Text Filter is an extension for #VisualStudio that filters and organizes your debug trace output, build output, and find-in-files results. Maintain organized histories of debug sessions, builds, and search results. Find out more at niahtextfilter.com. #coding


Marcus reposted

Argh, CSS.... Just use a table!

secretGeek's tweet image. Argh, CSS.... Just use a table!

Marcus reposted

Here is an accurate depiction of red teaming. Happy Friday.


Marcus reposted

Huge revamp of the @HunterPlaybook project w/ @ProjectJupyter Notebooks, Mordor 👿datasets for analytics validation, interactive queries & output made available to the whole 🌎 through @mybinderteam #ThreatHunting @ApacheSpark @Cyb3rPandaH @MITREattack github.com/Cyb3rWard0g/Th…

Cyb3rWard0g's tweet image. Huge revamp of the @HunterPlaybook project w/ @ProjectJupyter Notebooks, Mordor 👿datasets for analytics validation, interactive queries & output made available to the whole 🌎 through @mybinderteam  #ThreatHunting @ApacheSpark @Cyb3rPandaH @MITREattack github.com/Cyb3rWard0g/Th…

I do set traps for recruiters to see if they actually hit on any (LinkedIn, website and GitHub)...they hit on nothing, yet they respond back with "we fully assessed your profile" 🙄


Marcus reposted

We discovered an issue with ADFS which allows brute-forcing all domain accounts from the external network, while bypassing the extranet lockout policy. This can easily lead to account compromise / massive accounts lockout. @YaronZi @eyal_karni blog.preempt.com/security-advis…


Marcus reposted

Trying to get Chrome users to run executable files? Send them benign phishing links to the domain a few days ahead of time. Then send them to a landing page on the same domain where they click to start the download. No more angry red "harm your computer" warnings.

scriptjunkie1's tweet image. Trying to get Chrome users to run executable files? Send them benign phishing links to the domain a few days ahead of time. Then send them to a landing page on the same domain where they click to start the download. No more angry red "harm your computer" warnings.
scriptjunkie1's tweet image. Trying to get Chrome users to run executable files? Send them benign phishing links to the domain a few days ahead of time. Then send them to a landing page on the same domain where they click to start the download. No more angry red "harm your computer" warnings.
scriptjunkie1's tweet image. Trying to get Chrome users to run executable files? Send them benign phishing links to the domain a few days ahead of time. Then send them to a landing page on the same domain where they click to start the download. No more angry red "harm your computer" warnings.

Marcus reposted

Tools I recommend to Windows users - reply with your secret tip / tool Setup: Ninite ninite.com Personal FW: GlassWire @GlassWire glasswire.com Anti-Spy: ShutUp 10 @OOSoftware oo-software.com/en/shutup10

cyb3rops's tweet image. Tools I recommend to Windows users - reply with your secret tip / tool

Setup:
Ninite
ninite.com

Personal FW:
GlassWire @GlassWire
glasswire.com

Anti-Spy:
ShutUp 10 @OOSoftware 
oo-software.com/en/shutup10
cyb3rops's tweet image. Tools I recommend to Windows users - reply with your secret tip / tool

Setup:
Ninite
ninite.com

Personal FW:
GlassWire @GlassWire
glasswire.com

Anti-Spy:
ShutUp 10 @OOSoftware 
oo-software.com/en/shutup10
cyb3rops's tweet image. Tools I recommend to Windows users - reply with your secret tip / tool

Setup:
Ninite
ninite.com

Personal FW:
GlassWire @GlassWire
glasswire.com

Anti-Spy:
ShutUp 10 @OOSoftware 
oo-software.com/en/shutup10

Marcus reposted

1/ A little more context on the Firefox 0-day reports. On Monday, Coinbase detected & blocked an attempt by an attacker to leverage the reported 0-day, along with a separate 0-day firefox sandbox escape, to target Coinbase employees.


Marcus reposted

Awsome work as usual! I like the "light blue color"squares, it's P in TTP (I guess), lot of people misunderstand coverage of a MITRE Technique (i.e. simply by having schtask /create under the loop they think it's over, no that's just 1 of many Technique's Procedures), well done!


Marcus reposted

Some news: I’m writing a book for @nostarch titled “The Machine Learning Red Team Manual”. My aim is to provide a practical guide for anyone interested in adversarial ML and red teaming as it relates to in-production ML systems. A short thread on why this project matters:


Loading...

Something went wrong.


Something went wrong.