Joey Dreijer (@joeydreijer) 's Twitter Profile
Joey Dreijer

@joeydreijer

github.com/d3vzer0

ID: 15829860

calendar_today12-08-2008 23:25:24

99 Tweet

327 Followers

415 Following

Philipp Krenn (@xeraa) 's Twitter Profile Photo

Slides for #devBcn23: "Enriching Data with the Elastic Stack" — xeraa.net/talks/enrichin… * when: index- vs runtime * where: edge vs central vs in-cluster * how: logstash vs beats vs agent (fleet) vs OTel collector vs elasticsearch ingest pipeline vs elasticsearch runtime fields

Slides for #devBcn23: "Enriching Data with the <a href="/elastic/">Elastic</a> Stack" — xeraa.net/talks/enrichin…
* when: index- vs runtime
* where: edge vs central vs in-cluster
* how: logstash vs beats vs agent (fleet) vs OTel collector vs elasticsearch ingest pipeline vs elasticsearch runtime fields
Avigayil Mechtinger (@abbymch) 's Twitter Profile Photo

Can 9 lines of Python make history in cloud security? We believe that #PyLoose is the first publicly documented Python-based #fileless attack targeting cloud workloads in the wild. Read more about it 👇 wiz.io/blog/pyloose-f… Oren Ofer Itamar Gilad

Can 9 lines of Python make history in cloud security?

We believe that #PyLoose is the first publicly documented Python-based #fileless attack targeting cloud workloads in the wild.

Read more about it 👇
wiz.io/blog/pyloose-f…

<a href="/oren1ofer/">Oren Ofer</a> <a href="/TrustingTrust/">Itamar Gilad</a>
msticpy (@msticpy) 's Twitter Profile Photo

MSTICPy 2.6.0 released - Parallel queries for multiple instances of MS Sentinel workspaces and Kusto clusters - Parallel split queries (large time-range queries divided by smaller time periods) - Velociraptor data provider for querying exported data sets github.com/microsoft/msti…

MSTICPy 2.6.0 released
- Parallel queries for multiple instances of MS Sentinel workspaces and Kusto clusters
- Parallel split queries (large time-range queries divided by smaller time periods)
- Velociraptor data provider for querying exported data sets
github.com/microsoft/msti…
SpecterOps (@specterops) 's Twitter Profile Photo

We're thrilled to announce BloodHound Community Edition (CE) -- the next evolution of #BloodHound. Scheduled for release on 8/8, BloodHound CE has many new features & enhancements, making it easier for users to deploy, manage, and utilize. Learn more: ghst.ly/458lIGX

We're thrilled to announce BloodHound Community Edition (CE) -- the next evolution of #BloodHound. 

Scheduled for release on 8/8, BloodHound CE has many new features &amp; enhancements, making it easier for users to deploy, manage, and utilize. 

Learn more: ghst.ly/458lIGX
mbg (@mbrg0) 's Twitter Profile Photo

some unofficial info about how Python in Excel works: we have Excel that allows running Python in Jupyter notebook initiated by a .NET dll running in a Linux CBL-Mariner container inside of a Windows VM which are both managed by Azure Service Fabric 🙃

Joey Dreijer (@joeydreijer) 's Twitter Profile Photo

Experimenting with Elastic and built a (wip) search engine to aggregate open source detection content from multiple platforms. Currently indexing elastic, sigma, splunk and sentinel content ☺️ decon-search.vercel.app

Joey Dreijer (@joeydreijer) 's Twitter Profile Photo

Made some changes to the detection search engine and started importing hunting queries + added the additional filter to the UI ☺️ Next up is looking into indexing content from Jupyter notebooks as well. PS. I moved the page to decon.optyx.io

Made some changes to the detection search engine and started importing hunting queries + added the additional filter to the UI ☺️ Next up is looking into indexing content from Jupyter notebooks as well. PS. I moved the page to decon.optyx.io
Andrii Bezverkhyi (@andriinb) 's Twitter Profile Photo

Starting today, if you know one of the SIEM, EDR or Data Lake languages, you know them all! Dear industry, please meet RootA roota.io RootA is a public-domain language for collective cyber defense, created to make threat detection, incident response, and actor

Starting today, if you know one of the SIEM, EDR or Data Lake languages, you know them all! 
Dear industry, please meet RootA roota.io

RootA is a public-domain language for collective cyber defense, created to make threat detection, incident response, and actor
msticpy (@msticpy) 's Twitter Profile Photo

MSTICPY 2.9.0 released Includes new Threat Intel provider IPQualityScore and updated M365D to use MS Graph API for hunting queries. Fixes to startup, Synapse compat issues, Entities and more. See the release notes for a full rundown github.com/microsoft/msti…

MSTICPY 2.9.0 released
Includes new Threat Intel provider IPQualityScore and updated M365D to use MS Graph API for hunting queries.
Fixes to startup, Synapse compat issues, Entities and more. See the release notes for a full rundown
github.com/microsoft/msti…
jason liu - vacation mode (@jxnlco) 's Twitter Profile Photo

is this you? PLEASE RETURN JSON, NO TALKING, ONLY JSON all of that drama only for json.loads() to fail... If you use Pydantic theres a better way to steer llms into models that work within the python ecosystem blog.pydantic.dev/blog/2024/01/0…

Joey Dreijer (@joeydreijer) 's Twitter Profile Photo

Rewrote the detections/threat hunts search UI for more flexibility. Everything should be much more responsive on decon.optyx.io now ☺️

Rewrote the detections/threat hunts search UI for more flexibility. Everything should be much more responsive on decon.optyx.io now ☺️
Fox-IT (@foxit) 's Twitter Profile Photo

We created Skrapa, a zero dependency and customizable Python library for scanning Windows and Linux process memory. Harnessing memory attributes, Skrapa elevates your capability to explore patterns in memory. 🔍 blog.fox-it.com/2024/01/25/mem…

We created Skrapa, a zero dependency and customizable Python library for scanning Windows and Linux process memory. Harnessing memory attributes, Skrapa elevates your capability to explore patterns in memory. 🔍 blog.fox-it.com/2024/01/25/mem…
Thinkst Canary (@thinkstcanary) 's Twitter Profile Photo

Our Cloned Website Canarytoken¹ has caught attackers all over the world. Jacobs new CSS Canarytoken² allows this to work when all u can control is ur sites CSS. (It also works a treat to detect AitM phishing on Azure login portals) blog.thinkst.com/2024/01/defend… __ ¹ Free ² Also Free

Our Cloned Website Canarytoken¹ has caught attackers all over the world.

Jacobs new CSS Canarytoken² allows this to work when all u can control is ur sites CSS. (It also works a treat to detect AitM phishing on Azure login portals)

blog.thinkst.com/2024/01/defend…
__
¹ Free
² Also Free
SwiftOnSecurity (@swiftonsecurity) 's Twitter Profile Photo

The invention of the blue LED, one of the most difficult and important inventions ever, is some of the most Chad shit I have ever heard youtu.be/AF8d72mA41M

Outflank (@outflanknl) 's Twitter Profile Photo

🔥🔥New goody dropped for Outflank Security Tooling customers: PhisherPrice PhisherPrice helps with Device Code Flow abuse without sending codes/QRs via email. Easy to setup and host a phishing website, easy to receive auth tokens. Just as you like it.

Graylog (@graylog2) 's Twitter Profile Photo

Congrats to our #DEFCON32 Logs in the Shell #GraylogCTF winner — d3vzer0! Out of 180 players averaging 110 minutes of playtime, our winner scored a perfect game! 💯👏 🎮 Enjoy the OLED Steam Deck. You've earned it.🥇🏆 #Graylog #DEFCON #HackerSummerCamp Blue Team Village

Congrats to our #DEFCON32 Logs in the Shell #GraylogCTF winner — d3vzer0!

Out of 180 players averaging 110 minutes of playtime, our winner scored a perfect game! 💯👏

🎮 Enjoy the OLED Steam Deck. You've earned it.🥇🏆

#Graylog #DEFCON #HackerSummerCamp <a href="/BlueTeamVillage/">Blue Team Village</a>
Elastic (@elastic) 's Twitter Profile Photo

"Being able to call Elasticsearch and Kibana Open Source again is pure joy." — Shay Banon, Elastic Founder and CTO. Read more from Shay Banon: go.es.io/4dNtVVR #Elasticsearch

SpecterOps (@specterops) 's Twitter Profile Photo

Introducing the BloodHound Query Library! 📚 Martin Sohn & Joey Dreijer explore the new collection of Cypher queries designed to help BloodHound users to unlock the full potential of the BloodHound platform by creating an open query ecosystem. ghst.ly/4jTgRQQ

Martin Sohn (@martinsohndk) 's Twitter Profile Photo

ICYMI: Two weeks ago, we released the 𝗕𝗹𝗼𝗼𝗱𝗛𝗼𝘂𝗻𝗱 𝗤𝘂𝗲𝗿𝘆 𝗟𝗶𝗯𝗿𝗮𝗿𝘆 - a community-driven collection of BloodHound Cypher queries available here: queries.specterops.io Special thanks to LuemmelSec for being the first community member to contribute!