hackpsy's profile picture. Threat Research Team  @splunk
Maintainer of #atomic-red-team

Bhavin Patel

@hackpsy

Threat Research Team @splunk Maintainer of #atomic-red-team

Bhavin Patel reposted

More sysadmins need to know this… User logon restrictions are free. Create a GPO and call it “DC Logon Restrictions - Domain Admins Only” Configure User Rights Assignment for DA accounts to log on locally on domain controllers and deny log on locally on end-user workstations.


Bhavin Patel reposted

Never underestimate a properly caffeinated user and a little PowerShell knowledge ☕🔑😆

techspence's tweet image. Never underestimate a properly caffeinated user and a little PowerShell knowledge ☕🔑😆

Bhavin Patel reposted

Your Fall Reminder to always Hunt Naked. gist.github.com/MHaggis/66dd0b…

M_haggis's tweet image. Your Fall Reminder to always Hunt Naked. 

gist.github.com/MHaggis/66dd0b…

Bhavin Patel reposted

Lua day. Someone has to be the reminder lol

M_haggis's tweet image. Lua day. Someone has to be the reminder lol

Bhavin Patel reposted

🥳 Woah! we got a new #Kubernetes Goat 🐐 scenario on @ciliumproject Tetragon for eBPF-based runtime #security monitoring, detection & enforcement 🚀 🔥Try it out yourself at madhuakula.com/kubernetes-goa… 🌟 Give a start if you like github.com/madhuakula/kub… #CNCF #Hacking #Community

madhuakula's tweet image. 🥳 Woah! we got a new #Kubernetes Goat 🐐 scenario on @ciliumproject Tetragon for eBPF-based runtime #security monitoring, detection & enforcement 🚀

🔥Try it out yourself at  madhuakula.com/kubernetes-goa…

🌟 Give a start if you like github.com/madhuakula/kub…

#CNCF #Hacking #Community

Bhavin Patel reposted

Isn’t it amazing that some of the best research and tools, is literally free because of some passionate skilled people devote their time to sharing?! 🙏🙌💪

🔥💻 New tool drop! Meet MSIXBuilder 🎁 — the ultimate MSIX package creator for security testing, red team ops, and detection engineering! ✨ Features that slap: ⚡ One-click package builds (C# or PowerShell) 🔐 Auto cert creation + signing 🖥️ Sleek GUI w/ progress tracking &…

M_haggis's tweet image. 🔥💻 New tool drop! Meet MSIXBuilder 🎁 — the ultimate MSIX package creator for security testing, red team ops, and detection engineering!

✨ Features that slap:
⚡ One-click package builds (C# or PowerShell)
🔐 Auto cert creation + signing
🖥️ Sleek GUI w/ progress tracking &…
M_haggis's tweet image. 🔥💻 New tool drop! Meet MSIXBuilder 🎁 — the ultimate MSIX package creator for security testing, red team ops, and detection engineering!

✨ Features that slap:
⚡ One-click package builds (C# or PowerShell)
🔐 Auto cert creation + signing
🖥️ Sleek GUI w/ progress tracking &…
M_haggis's tweet image. 🔥💻 New tool drop! Meet MSIXBuilder 🎁 — the ultimate MSIX package creator for security testing, red team ops, and detection engineering!

✨ Features that slap:
⚡ One-click package builds (C# or PowerShell)
🔐 Auto cert creation + signing
🖥️ Sleek GUI w/ progress tracking &…


Bhavin Patel reposted

[New Blog 📚] The Fragile Balance: Assumptions, Tuning, and Telemetry Limits In Detection Engineering If you ever struggle with false positives and the idea of tuning detections. This is for you. Read More - nasbench.medium.com/the-fragile-ba…

nas_bench's tweet image. [New Blog 📚] The Fragile Balance: Assumptions, Tuning, and Telemetry Limits In Detection Engineering

If you ever struggle with false positives and the idea of tuning detections. This is for you.

Read More - nasbench.medium.com/the-fragile-ba…

Bhavin Patel reposted

Picture Paints a Thousand "Codes": STRT analyzed a Quasar RAT campaign using image steganography to hide payloads inside harmless-looking images. 🔍 In our latest blog: How it works Key TTPs Detection for #Splunk & #Cisco NTDR Read: splunk.com/en_us/blog/sec… #int3 Demo tool:


Bhavin Patel reposted

LOLRMM.io now tracks over 290 RMMs, with new ones being added regularly. These tools provide legitimate functionality but are frequently repurposed by attackers. Read here: buff.ly/oNbWfa6 If you're not using them in your setup, why allow them to run?…

magicswordio's tweet image. LOLRMM.io now tracks over 290 RMMs, with new ones being added regularly. These tools provide legitimate functionality but are frequently repurposed by attackers. Read here: buff.ly/oNbWfa6 

If you're not using them in your setup, why allow them to run?…

Bhavin Patel reposted

So I was deep in my webshell era this week 🧙‍♂️🕸️💻 and—plot twist—I totally got owned... by myself 😂 Naturally, I pulled the classic move: Did I read the source? Nope. Did I run it anyway? YOLO 🪂💥 Next thing I know, it casually goes full ninja mode and drops: cmd.exe ➡️…

M_haggis's tweet image. So I was deep in my webshell era this week 🧙‍♂️🕸️💻 and—plot twist—I totally got owned... by myself 😂

Naturally, I pulled the classic move:
 Did I read the source?
Nope.
 Did I run it anyway?
YOLO 🪂💥

Next thing I know, it casually goes full ninja mode and drops:

cmd.exe ➡️…

Bhavin Patel reposted

🚨 NEW BLOG DROP 🚨 A little late to the CitrixBleed party… But still REALLY worth your time 🧠💥 💻 CitrixBleed (CVE‑2025‑5777) 🩸 Memory exposure ➡️ token hijacking 🛡️ Detection + mitigation tips inside! 👉 Read it now: splunk.com/en_us/blog/sec… ⸻ 🔍 What you’ll learn: •🚔…


Bhavin Patel reposted

🚀 Happy to share my latest blog on @splunk: "Unlocking Endpoint Network Security Insights with Cisco Network Visibility Module (NVM) and Splunk" 🔗 Check it out here - splunk.com/en_us/blog/sec… In this post, I walk through how Cisco Network Visibility Module (NVM) works, the…

nas_bench's tweet image. 🚀 Happy to share my latest blog on @splunk:

"Unlocking Endpoint Network Security Insights with Cisco Network Visibility Module (NVM) and Splunk"

🔗 Check it out here - splunk.com/en_us/blog/sec…

In this post, I walk through how Cisco Network Visibility Module (NVM) works, the…
nas_bench's tweet image. 🚀 Happy to share my latest blog on @splunk:

"Unlocking Endpoint Network Security Insights with Cisco Network Visibility Module (NVM) and Splunk"

🔗 Check it out here - splunk.com/en_us/blog/sec…

In this post, I walk through how Cisco Network Visibility Module (NVM) works, the…
nas_bench's tweet image. 🚀 Happy to share my latest blog on @splunk:

"Unlocking Endpoint Network Security Insights with Cisco Network Visibility Module (NVM) and Splunk"

🔗 Check it out here - splunk.com/en_us/blog/sec…

In this post, I walk through how Cisco Network Visibility Module (NVM) works, the…
nas_bench's tweet image. 🚀 Happy to share my latest blog on @splunk:

"Unlocking Endpoint Network Security Insights with Cisco Network Visibility Module (NVM) and Splunk"

🔗 Check it out here - splunk.com/en_us/blog/sec…

In this post, I walk through how Cisco Network Visibility Module (NVM) works, the…

Stoked to present the research #STRT did with our Talos friends alongside @nas_bench and John Levy! And it includes a sweet demo at the end. Come say Hi :)

Let's supercharge your SOC. 🔋 Join the Splunk Threat Research Team alongside @TalosSecurity on July 23 to learn how to seamlessly integrate @Cisco Secure Firewall with #SplunkSecurity to up-level your response strategies.



Bhavin Patel reposted

Come see me at RSAC! I'll be speaking about common threat actor techniques seen in AWS intrusions, and why they're terrible! It'll be a Gordon Ramsey-style critique of cloud threat actors. In addition, we'll talk about how you can attack AWS environments better!

Frichette_n's tweet image. Come see me at RSAC! I'll be speaking about common threat actor techniques seen in AWS intrusions, and why they're terrible! It'll be a Gordon Ramsey-style critique of cloud threat actors. In addition, we'll talk about how you can attack AWS environments better!

Bhavin Patel reposted

Introducing 🚀Eventlog Compendium 🚀 A new Streamlit app, that aims to be the go-to resource for understanding and playing with Windows Event Logs. Explore it 👉 eventlog-compendium.streamlit.app Includes the following utilities and docs ⚙️ Build your own Advanced Audit Policy based on…

nas_bench's tweet image. Introducing 🚀Eventlog Compendium 🚀

A new Streamlit app, that aims to be the go-to resource for understanding and playing with Windows Event Logs.

Explore it 👉 eventlog-compendium.streamlit.app

Includes the following utilities and docs

⚙️ Build your own Advanced Audit Policy based on…

Bhavin Patel reposted

SQL attacks are getting stealthier. Now is your chance to stay ahead with insights from the Splunk Threat Research Team on how your database can turn against you — and how to shut it down fast: splk.it/42likc4 #SplunkSecurity

splunk's tweet image. SQL attacks are getting stealthier. 

Now is your chance to stay ahead with insights from the Splunk Threat Research Team on how your database can turn against you — and how to shut it down fast: splk.it/42likc4 #SplunkSecurity

Bhavin Patel reposted

The new documentation for contentctl buff.ly/4hPEbyR by Lou Stella is awesome. It now includes a straightforward guide for beginners, along with templates to streamline the testing and validation of Splunk content using GitHub Actions. If you haven't explored this…

_josehelps's tweet image. The new documentation for contentctl buff.ly/4hPEbyR  by Lou Stella is awesome. It now includes a straightforward guide for beginners, along with templates to streamline the testing and validation of Splunk content using GitHub Actions. If you haven't explored this…

Bhavin Patel reposted

Cool people add ASCII art to their tools, at #STRT we add a a flag that `recognize` your value threat researcher♥️! github.com/splunk/content… thank you @SnekCharmerr for letting me run with the silly.


Bhavin Patel reposted

AttackRuleMap.com now supports Linux attack and detection rules, in addition to Windows! With 88 new Linux attacks added, this open-source solution, aligned with Sigma and Splunk rules, takes multi-platform threat detection to the next level.


Bhavin Patel reposted

Excited to share my new project: AttackRuleMap This project maps #AtomicRedTeam simulations to open-source detection rules like #SigmaRules and #Splunk ESCU rules (maybe more in the future). Currently for Windows, with plans to support more platforms. attackrulemap.netlify.app


Loading...

Something went wrong.


Something went wrong.