Florian Roth(@cyb3rops) 's Twitter Profileg
Florian Roth

@cyb3rops

Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇

ID:1538299243

linkhttps://linktr.ee/cyb3rops calendar_today22-06-2013 08:46:16

32,4K Tweets

180,8K Followers

2,3K Following

Follow People
Sam Stepanyan(@securestep9) 's Twitter Profile Photo

It is 2024 and here we have yet another critical SQL Injection ( ) vulnerability in a commercial product by a *CyberSecurity* vendor - F5! (PaloAlto vuln was a couple of weeks ago)



my.f5.com/manage/s/artic…

It is 2024 and here we have yet another critical SQL Injection (#SQLi) vulnerability in a commercial product by a *CyberSecurity* vendor - F5! (PaloAlto vuln was a couple of weeks ago) #OWASPTop10 my.f5.com/manage/s/artic…
account_circle
Nathan McNulty(@NathanMcNulty) 's Twitter Profile Photo

Did you know Entra stores LAPS password history? :)

The Entra/Intune portal only shows the most recent one, so if you happen to do a lot of snapshots/reverts for testing like I do, the below command will show you all passwords and when they changed

$name is device name

Did you know Entra stores LAPS password history? :) The Entra/Intune portal only shows the most recent one, so if you happen to do a lot of snapshots/reverts for testing like I do, the below command will show you all passwords and when they changed $name is device name
account_circle
PC_Nation(@PC_Nation__) 's Twitter Profile Photo

Windows 11 24H2 will enable BitLocker encryption for everyone, happens on both clean installs and reinstalls.

BitLocker has been proven to impact system performance, particularly SSD performance.
SSD performance can drop by up to 45% depending on the workload

Even worse, if…

Windows 11 24H2 will enable BitLocker encryption for everyone, happens on both clean installs and reinstalls. BitLocker has been proven to impact system performance, particularly SSD performance. SSD performance can drop by up to 45% depending on the workload Even worse, if…
account_circle
dragosr(@dragosr) 's Twitter Profile Photo

So DHCP options have always been an ugly mess. Sure RFC3442, let's let mostly unauthenticated network broadcasts install static routes into client routing tables. What could possibly go wrong?

Combined with the 0.0.0.0/1 trick from Leviathan folks' recent post, using DHCP to…

So DHCP options have always been an ugly mess. Sure RFC3442, let's let mostly unauthenticated network broadcasts install static routes into client routing tables. What could possibly go wrong? Combined with the 0.0.0.0/1 trick from Leviathan folks' recent post, using DHCP to…
account_circle
Squiblydoo(@SquiblydooBlog) 's Twitter Profile Photo

Debloat is for deflating executables. (github.com/Squiblydoo/deb…)

But if you all see other file formats that attackers inflate, send them my way too!

The following is an image of an LNK with 200 MB of null bytes slapped on the end (the overlay).

(Image is from the tool )

Debloat is for deflating executables. (github.com/Squiblydoo/deb…) But if you all see other file formats that attackers inflate, send them my way too! The following is an image of an LNK with 200 MB of null bytes slapped on the end (the overlay). (Image is from the tool #malcat)
account_circle
OffSec(@offsectraining) 's Twitter Profile Photo

This blog introduces a new 0day technique discovered by OffSec Technical Trainer Victor “Vixx” Khoury, the process he used to exploit it, and the proof of concept code to bypass AMSI in PowerShell 5.1 and PowerShell 7.4: offs.ec/44owQR3

account_circle
Simone Kraus(@simonekrausora1) 's Twitter Profile Photo


'APT28: From Initial Damage to Domain Controller Threats in an Hour' is now updated and has some additional sources with the latest IOCs including own research (at the end of the article as threat hunting opportunities).
link.medium.com/xfX7eNU7mJb

account_circle
Michael Koczwara(@MichalKoczwara) 's Twitter Profile Photo

Hunting Muddy Water 🇮🇷 with Validin

DNS records host mshta.exe/command line queries in TXT records🎯

Intel-Ops

Come and join and we will teach you how to hunt adversaries!

docs.google.com/forms/d/10oy2Z…

/mason.burton.onionmail.org and linked Muddy Water domains…

Hunting Muddy Water 🇮🇷 with @ValidinLLC DNS records host mshta.exe/command line queries in TXT records🎯 @Intel_Ops_io Come and join and we will teach you how to hunt adversaries! docs.google.com/forms/d/10oy2Z… /mason.burton.onionmail.org and linked Muddy Water domains…
account_circle
Florian Roth(@cyb3rops) 's Twitter Profile Photo

We've enabled multi-threading in all THOR versions, including the free THOR Lite. I'm also thrilled about the upcoming 'Audit Trail' mode for our 'Forensic Lab' license, offering detailed JSON output for enriching timelines and performing correlations.

account_circle
Florian Roth(@cyb3rops) 's Twitter Profile Photo

Can’t we get this as an open source tool that disables the other 100 unneeded „features“ like the bing search in Windows?

account_circle
Albert Thomas, Cooling Reviewer(@ultrawide219) 's Twitter Profile Photo

Holy hannah! Disabling web search on the start menu makes it so much faster and effective. No lag at all anymore!

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search

Make a new DWORD (32-bit) called: BingSearchEnabled

Ensure the value = 0

account_circle
Matthew Green(@matthew_d_green) 's Twitter Profile Photo

Europe is maybe two months from passing laws that end private communication as we know it, and folks are looking the other way (understandably.) You’re not going to get a do-over once these laws are passed.

account_circle