1.
Dray Agha
@Purp1eW0lf
WMI lateral movement is all about child processes. Look for the following features of WmiPrvSE.exe children.
β’ Neβ¦ twitter.com/i/web/status/1β¦
β’ Neβ¦ twitter.com/i/web/status/1β¦
Retweet of status by @ACEResponder
13 Mar 23
copy & paste +upvote -downvote WMI lateral movement is all about child processes. Look for the following features of WmiPrvSE.exe children.π
⒠Ne⦠https://t.co/p8t1vgklLa
2.
Dray Agha
@Purp1eW0lf
We are recruiting! Want to join our team as a Cyber Threat Intelligence Analyst? If you like threat intel anβ¦ twitter.com/i/web/status/1β¦
22 Dec 22
copy & paste +upvote -downvote π¨We are recruiting! Want to join our team as a Cyber Threat Intelligence Analyst? π΅οΈββοΈ If you like threat intel anβ¦ https://t.co/cJyPm9rnAm
3.
4.
5.
6.
7.
18 Nov 22
copy & paste +upvote -downvote #Qakbot once again had some surprises π for us this week. See below for a brief overview of what we found. 𧡠1/6
Dray Agha
@Purp1eW0lf
There's a bypass to the fix to the bypass to the mitigation for ProxyNotShell / CVE-2022-41040. β¦ twitter.com/i/web/status/1β¦
05 Oct 22
copy & paste +upvote -downvote There's a bypass to the fix to the bypass to the mitigation for ProxyNotShell / CVE-2022-41040. π€¦ββοΈβ¦ https://t.co/oqC3RgDNRr
Dray Agha
@Purp1eW0lf
Investigating an intrusion?
Start with the security solution on the machine. DON'T work hard to timeline the aβ¦ twitter.com/i/web/status/1β¦
Start with the security solution on the machine. DON'T work hard to timeline the aβ¦ twitter.com/i/web/status/1β¦
29 Sep 22
copy & paste +upvote -downvote Investigating an intrusion? π΅οΈπ
Start with the security solution on the machine. DON'T work hard to timeline the a⦠https://t.co/HU5zO98c3E
Dray Agha
@Purp1eW0lf
Exciting news - Iβm hiring for my team @SentinelOne! If you burn with passion for Digital Forensics, this might bβ¦ twitter.com/i/web/status/1β¦
Retweet of status by @JReisdorffer
22 Jun 22
copy & paste +upvote -downvote Exciting news - Iβm hiring for my team @SentinelOne! π If you burn with passion for Digital Forensics, this might bβ¦ https://t.co/Gi0V5XBNQ2
Dray Agha
@Purp1eW0lf
I started a #Threat_hunting series. In this first post, I cover the basics, including:
What is threat hunting
β¦ twitter.com/i/web/status/1β¦
What is threat hunting
β¦ twitter.com/i/web/status/1β¦
Retweet of status by @Kostastsale
13 Jun 22
copy & paste +upvote -downvote I started a #Threat_hunting series. In this first post, I cover the basics, including:
β
What is threat hunting
β
β¦ https://t.co/hKMozZX2QC
8.
9.
10.
11.
Dray Agha
@Purp1eW0lf
Job Alert
I'm hiring for an open position on my team. We're looking for a technical analyst who can help us reseaβ¦ twitter.com/i/web/status/1β¦
I'm hiring for an open position on my team. We're looking for a technical analyst who can help us reseaβ¦ twitter.com/i/web/status/1β¦
06 Jun 22
copy & paste +upvote -downvote π¨Job Alertπ¨
I'm hiring for an open position on my team. We're looking for a technical analyst who can help us resea⦠https://t.co/9Iw2pJt2bk
Dray Agha
@Purp1eW0lf
Defense evasion is a lot like a broad church.
...at least that's what @Purp1eW0lf on our ThreatOps team claims. β¦ twitter.com/i/web/status/1β¦
...at least that's what @Purp1eW0lf on our ThreatOps team claims. β¦ twitter.com/i/web/status/1β¦
Retweet of status by @HuntressLabs
18 May 22
copy & paste +upvote -downvote Defense evasion is a lot like a broad church.
...at least that's what @Purp1eW0lf on our ThreatOps team claims. πβ¦ https://t.co/qtwFbqAMBQ
Dray Agha
@Purp1eW0lf
Next week on CrackMapExec, a new option will be available pic.twitter.com/ME0VnXM6an
12 Mar 22
copy & paste +upvote -downvote Next week on CrackMapExec, a new option will be available πΈ https://t.co/ME0VnXM6an
Dray Agha
@Purp1eW0lf
Probably the weirdest #LOLBin I have ever found...
wlrmdr.exe -s 3600 -f 0 -t Click me! -m To run calculator -aβ¦ twitter.com/i/web/status/1β¦
wlrmdr.exe -s 3600 -f 0 -t Click me! -m To run calculator -aβ¦ twitter.com/i/web/status/1β¦
16 Feb 22
copy & paste +upvote -downvote Probably the weirdest #LOLBin I have ever found... π
wlrmdr.exe -s 3600 -f 0 -t Click me! -m To run calculator -a⦠https://t.co/V3UiTNfiei
...but wait! There's more!
1.
fakhright
@fakhright
astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat*
14 Jan 13
copy & paste +upvote -downvote astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat* πππ