@SecPanda_i
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Bears. Beets. Battlestar Galactica. Cyber Threat Intel. Eater of snacks. 🐼 @SnackPanda@infosec.exchange
Joined March 2020
- Tweets364
- Following2K
- Followers380
- Likes880
Kristen! retweeted
It's always people, process, technology.
EXPLICITLY IN THAT ORDER!!!
To quote @strandjs, "Every time you try to press 'the easy button' God deploys another botnet in your network"
New Robinhood phishing chain that's kinda beautiful:
1. Attacker creates an RH account using the Gmail dot trick of your email (same inbox, different address)
2. Sets device name to HTML
3. RH's "unrecognized activity" email renders the device name unsanitized (html injection)
The result is a real email from [email protected], DKIM pass, SPF pass, DMARC pass, with a phishing CTA
Just because it's real, doesn't mean it's safe... $HOOD
Kristen! retweeted
I know this isn't new but can we talk about the MS threat actor naming scheme again?
It's not just that the scheme itself is ridiculous. Someone consciously chose the most stripper-coded fruit and gems for each one. On purpose.
Kristen! retweeted
Replying to @alex_lanstein
Technical intelligence never displaces the need for good human intelligence collection. A tale as old as metis.
Kristen! retweeted
CrowdStrike Falcon agents are imploding right now and causing a Blue Screen of Death boot loop on every endpoint. Reports of massive outages globally.
reddit.com/r/crowdstrike/com…
A colleagues shared this with me: roadmap.sh/roadmaps
What a cool resource for guided learning - both role based and specific skill based ⭐️
Kristen! retweeted
I am one again reminding people that if you are creating a Windows 11 installer, use Rufus
- You can bypass the RAM, Secure Boot and TPM requirements
- You can remove the requirement for a Microsoft account
- Disable automatic encryption
- Auto-create account and more
Kristen! retweeted
Happy to introduce "Pivot Atlas", a digital pivoting handbook for cyber threat intel analysts. I've been working on this as a personal project with the goal of graphing the "pivotability" of threat intel artifacts and providing real-world examples and reference material. (1/2)🧵
Kristen! retweeted
next time your friend goes to the bathroom, grab their phone and use the new memory feature to add some stochastic whimsy and delight to their chatgpt experience
Kristen! retweeted
If you know a woman in infosec who is looking to learn more, please tell them to subscribe to THE Microsoft threat intelligence podcast. We have a fantastic slate of women talking on subjects like mobile malware RE, Incident Response, data science, and more!
Kristen! retweeted
Today is National K9 Veterans Day. This is one of our favorite pics of Denis. #warrior