Mika Ayenson (@stryker0x) 's Twitter Profile
Mika Ayenson

@stryker0x

Threat Research & Detection Engineering Team Lead @elastic

ID: 1519307723074162689

linkhttps://github.com/Mikaayenson calendar_today27-04-2022 13:29:42

120 Tweet

254 Followers

167 Following

Ruben Groenewoud (@rfgroenewoud) 's Twitter Profile Photo

🚨 PANIX v2.0 Released! 🚨 Test & upgrade your Linux security with: - 31 persistence modules & 50+ techniques - Easily revert changes post-testing - Map to MITRE ATT&CK - 10+ fresh additions: LD_PRELOAD, PAM backdoors, rootkits, and more! 🔗 github.com/Aegrah/PANIX

🚨 PANIX v2.0 Released! 🚨

Test & upgrade your Linux security with:
- 31 persistence modules & 50+ techniques
- Easily revert changes post-testing
- Map to MITRE ATT&CK
- 10+ fresh additions: LD_PRELOAD, PAM backdoors, rootkits, and more!

🔗 github.com/Aegrah/PANIX
Elastic Security Labs (@elasticseclabs) 's Twitter Profile Photo

#ElasticSecurityLabs has discovered PUMAKIT, a new #linux #malware with advanced stealth mechanisms. The kernel rootkit is capable of privilege escalation, anti-debugging measures, and more. Get the details here: go.es.io/4g9LIHP

Elastic Security Labs (@elasticseclabs) 's Twitter Profile Photo

The beacons have been lit by Mika Ayenson, Miguel Garzon, and Samir! This new research combines Beacon Object Files, Elastic AI Assistant, and Detonate to explore detection capabilities. Check it out: go.es.io/427o76x #ElasticSecurityLabs #detectionengineering #ai

Elastic Security Labs (@elasticseclabs) 's Twitter Profile Photo

We’re adding a new section to Elastic’s HackerOne Bounty Program! Today, we’re opening our SIEM and EDR rules for testing. We’re excited to have another way to thank our community for their efforts on our #detectionengineering. Get more details here: go.es.io/4hdKQCI

Samir (@sbousseaden) 's Twitter Profile Photo

in a year period we had 50% increase in Elastic Defend endpoint behavior rules (coverage as well - 1000+) 💪 for all the 3 supported platforms Windows, macOS and Linux H/T DefSecSentinel Ruben Groenewoud Mika Ayenson Shashank and all the team ofc github.com/elastic/protec…

in a year period  we had 50% increase in Elastic Defend endpoint behavior rules (coverage as well - 1000+) 💪 for all the 3 supported platforms Windows, macOS and Linux H/T <a href="/DefSecSentinel/">DefSecSentinel</a> <a href="/RFGroenewoud/">Ruben Groenewoud</a> <a href="/stryker0x/">Mika Ayenson</a> Shashank and all the team ofc

github.com/elastic/protec…
Elastic Security Labs (@elasticseclabs) 's Twitter Profile Photo

#IoT devices like Wi-Fi cameras are convenient, but exploitable. Take a look at how some of the most popular baby cameras can be abused: go.es.io/4jxG6bV

DefSecSentinel (@defsecsentinel) 's Twitter Profile Photo

Great find and write-up from the team Unit 42. I wrote a small unsafe PyYAML loader script to remotely load and execute the YAML deserialization payload. I also built out a Python+Flask C2 Server on an "attacker" VM to handle all communication as specified in the loader and

Great find and write-up from the team <a href="/Unit42_Intel/">Unit 42</a>. I wrote a small unsafe PyYAML loader script to remotely load and execute the YAML deserialization payload. I also built out a Python+Flask C2 Server on an "attacker" VM to handle all communication as specified in the loader and
Jai Minton (@cyberraiju) 's Twitter Profile Photo

This hurts... Please don't: - Let AI create infographics - Post them with AI created slop text - Claim you created the infographic - Delete any comments with constructive feedback - Let rundll3.exe or certufl.exe run, it probably isn't good despite what the infographic says.

This hurts...

Please don't:
- Let AI create infographics
- Post them with AI created slop text
- Claim you created the infographic
- Delete any comments with constructive feedback
- Let rundll3.exe or certufl.exe run, it probably isn't good despite what the infographic says.
Sam Altman (@sama) 's Twitter Profile Photo

o3 and o4-mini are super good at coding, so we are releasing a new product, Codex CLI, to make them easier to use. this is a coding agent that runs on your computer. it is fully open source and available today; we expect it to rapidly improve.

Elastic Security Labs (@elasticseclabs) 's Twitter Profile Photo

You can access our #detectionengineering repos, but how about a closer look? The 2025 State of Detection Engineering at Elastic is a new #report from #ElasticSecurityLabs detailing how we create and assess our prebuilt rules. Check it out: go.es.io/4jnrXhA

You can access our #detectionengineering repos, but how about a closer look?

The 2025 State of Detection Engineering at Elastic is a new #report from #ElasticSecurityLabs detailing how we create and assess our prebuilt rules. Check it out: go.es.io/4jnrXhA
Nous Research (@nousresearch) 's Twitter Profile Photo

Introducing Minos - A new classifier for detecting refusals from LLMs. A potentially very useful tool for redteamers and jailbreakers - it's a binary classifier that will return the likelihood of a final response in a chat being a refusal. huggingface.co/NousResearch/M… Built on

Introducing Minos - A new classifier for detecting refusals from LLMs. A potentially very useful tool for redteamers and jailbreakers -  it's a binary classifier that will return the likelihood of a final response in a chat being a refusal.

huggingface.co/NousResearch/M…

Built on
Elastic Security Labs (@elasticseclabs) 's Twitter Profile Photo

New research from our #ElasticSecurityLabs team: we dive into how infostealers are leveraging a stolen Shellter evasion tool to deploy data-stealing malware. Learn more & get our unpacker: go.es.io/4ldCM72 #malware #rhadamanthys #ghostpulse

Elastic Security Labs (@elasticseclabs) 's Twitter Profile Photo

New research on NOVABLIGHT, a NodeJS infostealer sold as MaaS! Discover its tactics, from credential theft & cryptowallet compromise to advanced obfuscation & anti-analysis techniques: go.es.io/459JGDA #ElasticSecurityLabs #infostealer

Claude (@claudeai) 's Twitter Profile Photo

We just shipped automated security reviews in Claude Code. Catch vulnerabilities before they ship with two new features: - /security-review slash command for ad-hoc security reviews - GitHub Actions integration for automatic reviews on every PR

Sam Altman (@sama) 's Twitter Profile Photo

our livestream tomorrow at 10 am PDT will be longer than usual, around an hour. we have a lot to show and hope you can find the the time to watch!