tas_kmanager@infosec.exchange (@tas_kmanager) 's Twitter Profile
[email protected]

@tas_kmanager

☁️🛡️ opinions are mine. food, music and astrophotography when afk.
@TheDFIRReport @CuratedIntel
#ThreatHunting #DetectionEngineering #DFIR #CloudSecurity

ID: 1042469590608031745

linkhttps://github.com/tas-kmanager calendar_today19-09-2018 17:44:53

276 Tweet

869 Followers

1,1K Following

Kijo Ninja (@kj_ninja25) 's Twitter Profile Photo

Would you be interested in testing LSASS dumping simulation ? 🚀 Testing script is available ↓ ↓ ✅ Simulation : github.com/LearningKijo/R… #MDE #EDR #MDAV #EPP #MicrosoftSecurity

Kijo Ninja (@kj_ninja25) 's Twitter Profile Photo

After running the script, these alerts were generated and correlated into a single incident in Microsoft Defender XDR portal. ✅ Simulation : github.com/LearningKijo/R…

After running the script, these alerts were generated and correlated into a single incident in Microsoft Defender XDR portal.

✅ Simulation : github.com/LearningKijo/R…
Anton (@antonlovesdnb) 's Twitter Profile Photo

Got a new blog out today with some ideas around hunting for cloud session anomalies - I think this is a super relevant topic with cookie/token theft TTPs being all the rage these days! sumologic.com/blog/hunt-clou…

SANSNew2Cyber (@new_2_cyber) 's Twitter Profile Photo

Happening now at #New2CyberSummit: [email protected] and Sylvain Lu share a day in the life of detection engineers. Hear this talk: sans.org/u/1uk7 #CybersecurityJourney

Happening now at #New2CyberSummit: <a href="/tas_kmanager/">tas_kmanager@infosec.exchange</a> and Sylvain Lu share a day in the life of detection engineers. Hear this talk: sans.org/u/1uk7 

#CybersecurityJourney
Zach (@svch0st) 's Twitter Profile Photo

🎁 Today I'm giving away 3 of our DFIR Labs! 🎁 To enter: ✅Follow me ✅RT & Like this post ✅Reply with which case you'd like to take The winners will be selected in 24 hours. #Giveaway

SNOWcon (@snowcon_2025) 's Twitter Profile Photo

Our website is up and will be updated with all the latest informations about the conference. Have a look and give us your feedback! snowcon.info

Will (@bushidotoken) 's Twitter Profile Photo

I am happy to share a new resource I recently created called The Ransomware Tool Matrix: 🔗 blog.bushidotoken.net/2024/08/the-ra… #CTI #ThreatHunting #ThreatIntel #Ransomware

I am happy to share a new resource I recently created called The Ransomware Tool Matrix: 

🔗 blog.bushidotoken.net/2024/08/the-ra…

#CTI #ThreatHunting #ThreatIntel #Ransomware
Kostas (@kostastsale) 's Twitter Profile Photo

I created the first draft of a website for the EDR telemetry project to help people quickly compare vendor telemetry visibility. What do you think about it? Are there any specific features you want to see for the website? Built with ChatGPT 4o with canvas (wanted to test it

Microsoft Threat Intelligence (@msftsecintel) 's Twitter Profile Photo

Between July 2023 and June 2024, Microsoft observed nation-state threat actors conduct operations for financial gain, enlist cybercriminals to collect intelligence, and make use of the same tools and frameworks favored by cybercriminals: msft.it/6018mf9Sm

Jeremy Kirk (@jeremy_kirk) 's Twitter Profile Photo

Microsoft has been running massive deception campaigns that flood new phishing sites with bogus credentials for bogus companies on MS tenants. When attackers log in, they deliver a torrent of fresh threat intelligence that can be used to defend: #infosec youtube.com/watch?v=78qnM_…

Thomas Roccia 🤘 (@fr0gger_) 's Twitter Profile Photo

If you're up for some Frenglish 😛 my @DEFCON talk about the XZ backdoor is now available on YouTube! And If you are at BSides Melbourne, come say hello—I’ll be presenting a shorter version of the talk there. 🤓 #infosec #threatintel youtu.be/hwuIb-Vv2Ew?si…

Will (@bushidotoken) 's Twitter Profile Photo

Very happy to hear my talk has been accepted to BSides London! 💂🏻🇬🇧 This is something I’ve wanted to do for a long time. Join me to hear about a new resource I’ve created to help prevent ransomware attacks 🔒☣️

Very happy to hear my talk has been accepted to <a href="/BSidesLondon/">BSides London</a>! 💂🏻🇬🇧

This is something I’ve wanted to do for a long time. Join me to hear about a new resource I’ve created to help prevent ransomware attacks 🔒☣️
Dr. Nestori Syynimaa (@drazuread) 's Twitter Profile Photo

Just pushed a new versions for #AADInternals and AADInternals-Endpoint modules! Some bug fixes plus support for: 1️⃣ Microsoft Authentication Library (MSAL) 2️⃣ Token Protection 3️⃣ Continuous Access Evaluation (CAE)

Florian Roth ⚡️ (@cyb3rops) 's Twitter Profile Photo

We’re seeing a clear trend: attackers are bypassing the endpoint entirely. Not just avoiding traditional EDR-monitored systems by pivoting to embedded and edge devices, but now also operating purely in the cloud. No shell, no malware, no persistence on the endpoint. Just an OAuth

Kijo Ninja (@kj_ninja25) 's Twitter Profile Photo

New table in Advanced Hunting 🎯 OAuthAppInfo table contains information about Microsoft 365-connected OAuth applications !! Make sure you enabled MDA App Governance !! learn.microsoft.com/en-us/defender…

The DFIR Report (@thedfirreport) 's Twitter Profile Photo

🌟New report out today!🌟 Hide Your RDP: Password Spray Leads to RansomHub Deployment Analysis and reporting completed by [email protected]Aleks and UC2 🔊Audio: Available on Spotify, Apple, YouTube and more! thedfirreport.com/2025/06/30/hid…

Kijo Ninja (@kj_ninja25) 's Twitter Profile Photo

It's been a while since I last wrote a KQL query 🎯 Today, I published a blog post about #ZAP response time in #EOP and how we can analyze the timing using #KQL. 🎯 Blog : osintteam.blog/how-fast-does-… * There may already be other approaches or queries to measure ZAP response time

It's been a while since I last wrote a KQL query 🎯 Today, I published a blog post about #ZAP response time in #EOP and how we can analyze the timing using #KQL.

🎯 Blog : osintteam.blog/how-fast-does-…

* There may already be other approaches or queries to measure ZAP response time