π Windows Security and SDDL: What You Need to Know π
Windows permissions misconfigurations are a goldmine for attackers. SDDL (Security Descriptor Definition Language) remains overlooked yet highly exploitable. π¨
@nasbench.bsky.social and I break it down -->
π§΅ (1/)
Posts by Nasreddine Bencherchali
Hey SDDL SDDL: Breaking Down Windows Security One ACE at a Time www.splunk.com/en_us/blog/s....
Thrilled to share my first blog at @splunk! @mhaggis.bsky.social and I take a deep dive into the weird & exciting world of SDDL and ACEs - what they are, how they work, and how attackers can abuse them.
ποΈ New podcast episode is live! I used my experience as an Incident Responder and provided it to NotebookLM to turn into a podcast. Wondering what it feels like to be in IR? This episode shares most responsibilities, true to life for 99% of IR folks.
Hope you enjoy: creators.spotify.com...
This is just sad to think about π
AI allows you to do more work with the same salary. Allowing companies to make more money, and, it uses your data to train so that it'll replace you later.
When is the utopia we read about in sci-fi books. Looks like we skipped to the doom and gloom and AI overlords chapter too quickly π
I guess we're still here @kostas-sec.bsky.social π
Bsky is chill
Compared to release v2023-08-24, in v2024-11-10 there are 469 more public #detectionrules in the #SigmaRules repository.
www.dogesec.com/blog/analysi...
#threatintelligence #threatintel
π‘Interested in #memoryforensics ? Follow
β
@volexity.com
β
@volatilityfoundation.org
β
@attrc.bsky.social
β
@rmettig.bsky.social
β
@nolaforensix.bsky.social
β‘οΈ more to come!
Iβm looking for a new remote work opportunity starting in April. If you think Iβd be a good fit for your team, let me know!
Cisco Talos Incident Response (Talos IR) recently observed an attacker conducting big-game hunting and double extortion attacks using the relatively new Interlock ransomware. Read the blog here: cs.co/6019SsMIh
#dfir #threatintel #cybersecurity
Windows.edb and WER dumps, just to name a few
Appreciate you brother π
LOLDrivers are cool π