_devonkerr_'s profile picture. Director of Threat Research and @ElasticSecLabs team lead; custodian of secret histories. Posts are my own.

Devon Kerr

@_devonkerr_

Director of Threat Research and @ElasticSecLabs team lead; custodian of secret histories. Posts are my own.

Devon Kerr reposted

📋 In the latest Microsoft report, the DART team discovered a new backdoor dubbed SesameOp, abusing the OpenAI Assistants API to run covert C2 communication without any model inference! I made a diagram to show how the backdoor works! Great work 👏 microsoft.com/en-us/security…

fr0gger_'s tweet image. 📋 In the latest Microsoft report, the DART team discovered a new backdoor dubbed SesameOp, abusing the OpenAI Assistants API to run covert C2 communication without any model inference! 

I made a diagram to show how the backdoor works!

Great work 👏

microsoft.com/en-us/security…

Devon Kerr reposted

Awesome new threat report from Google Threat Intel Group documenting how threat actors are leveraging Gemini. A lot of information and actionable avalable in the report! Great work 👌 services.google.com/fh/files/misc/…

fr0gger_'s tweet image. Awesome new threat report from Google Threat Intel Group documenting how threat actors are leveraging Gemini. A lot of information and actionable avalable in the report! Great work 👌

services.google.com/fh/files/misc/…

tfw generative AI behaves more like degenerative AI, amirite


Devon Kerr reposted

Elastic PM @jamesspi joins security expert @_JohnHammond to unpack how Elastic’s powerful SIEM, XDR, and EDR solutions—enhanced with cutting-edge AI—help teams detect and respond to threats faster. Watch now: go.es.io/4hkLrDB


Devon Kerr reposted

The HackingTeam is back! New name, new malware, new exploits securelist.com/forumtroll-apt…


One downside no one tells you about aging, is that so much of what you remember is the past. Thoughts inspired by Ghostbusters.


Devon Kerr reposted

Some really cool research from @saab_sec on alternatives to sleep masking 🔥🔥

Interested in an alternative approach to sleep masking for you malware? Check-out our latest blog post "Function Peekaboo: Crafting self masking functions using LLVM" by @saab_sec mdsec.co.uk/2025/10/functi…

MDSecLabs's tweet image. Interested in an alternative approach to sleep masking for you malware? Check-out our latest blog post "Function Peekaboo: Crafting self masking functions using LLVM" by @saab_sec mdsec.co.uk/2025/10/functi…


Growing up, I really thought the Bermuda Triangle and quicksand would play bigger roles in daily life.


Devon Kerr reposted

REF3927 abuses publicly disclosed ASP.NET machine keys to compromise IIS servers and deploy TOLLBOOTH SEO cloaking modules globally. elastic.co/security-labs/…

ngnicky's tweet image. REF3927 abuses publicly disclosed ASP.NET machine keys to compromise IIS servers and deploy TOLLBOOTH SEO cloaking modules globally. elastic.co/security-labs/…

Devon Kerr reposted

Great research from Mandiant, learned a lot from their analysis. cloud.google.com/blog/topics/th… Found more trojanized JavaScripts communicating with the same transaction hash. Sometimes it’s shocking how well DPRK actors understand blockchain mechanics and weaponize them.…


Devon Kerr reposted

@0xkyle dropping some heat on clustering PDFs with PDF object hashing 🔥🤖 This has been paying dividends in our hunting & tracking efforts in house, excited to see it open sourced! proofpoint.com/us/blog/threat…

greglesnewich's tweet image. @0xkyle dropping some heat on clustering PDFs with PDF object hashing 🔥🤖

This has been paying dividends in our hunting & tracking efforts in house, excited to see it open sourced! 

proofpoint.com/us/blog/threat…
greglesnewich's tweet image. @0xkyle dropping some heat on clustering PDFs with PDF object hashing 🔥🤖

This has been paying dividends in our hunting & tracking efforts in house, excited to see it open sourced! 

proofpoint.com/us/blog/threat…
greglesnewich's tweet image. @0xkyle dropping some heat on clustering PDFs with PDF object hashing 🔥🤖

This has been paying dividends in our hunting & tracking efforts in house, excited to see it open sourced! 

proofpoint.com/us/blog/threat…

Devon Kerr reposted

Time-to-Patch Metrics: A Survival Analysis Approach Using Qualys and Elastic — Elastic Security Labs elastic.co/security-labs/…


Devon Kerr reposted

Elastic Security Labsが、公開済みのASP[.]NET machineKeyを悪用したグローバルなIIS感染キャンペーン(REF3927)を公開しました。 elastic.co/security-labs/…


Devon Kerr reposted

#ElasticSecurityLabs joins forces with @tamusystem and discloses TOLLBOOTH, an IIS module used for SEO abuse that relies on publicly exposed ASP. NET machine keys: go.es.io/3L68p57


Devon Kerr reposted

Your team and the customer squashing it from the get go was great! Love talking about good folks doin' the good work!


Devon Kerr reposted

This is good analysis:

bluish_red_'s tweet image. This is good analysis:

Anyway, we wanted to tell a bit later, but we had to rush it now, as fellows did publish about the same toolset today (as "TOLLBOOTH"). We're fewer guys but we may still have found a bit more. IOCs & Yaras: harfanglab.io/insidethelab/r…



Devon Kerr reposted

Always great to work with y'all, we always seem to do some cool stuff when we get together!


Devon Kerr reposted

Thanks for being generous with your time and expertise on this @SreekarMad! Good stuff! @ValidinLLC

#ElasticSecurityLabs joins forces with @tamusystem and discloses TOLLBOOTH, an IIS module used for SEO abuse that relies on publicly exposed ASP. NET machine keys: go.es.io/3L68p57



Loading...

Something went wrong.


Something went wrong.