Vadim Khrykov(@BlackMatter23) 's Twitter Profileg
Vadim Khrykov

@BlackMatter23

Threat Hunter | Head of SOC | OSCP | GCDA | CRTE | Share my experience with you #ThreatHunting #DFIR #ThreatIntel #Azure #AWS

ID:1022738826383503360

linkhttp://github.com/vadim-hunter calendar_today27-07-2018 07:01:52

3,2K Tweets

4,9K Followers

963 Following

Vadim Khrykov(@BlackMatter23) 's Twitter Profile Photo

is a vital source of events for every SOC.
Check out this GWS audit logs collector, developed by Alexander Bolshakov
github.com/spacepatcher/g…

account_circle
Vadim Khrykov(@BlackMatter23) 's Twitter Profile Photo

Dear MITRE Engenuity,
OS X market share for desktop systems is 14.99% and Linux is only 2.45%.
Why we have seen Linux in MITRE evaluations and never seen OS X?🤔

account_circle
Vadim Khrykov(@BlackMatter23) 's Twitter Profile Photo

So different EDR vendors.
Vendor A: 'We don't provide raw events because our IOAs detect everything'🤔
Vendor B: 'Yes, we didn't detect your attack simulations, but you can write your own rules using our raw telemetry to detect them'👌

account_circle
SEKTOR7 Institute(@SEKTOR7net) 's Twitter Profile Photo

Ukraine needs support! SEKTOR7 has already donated to Polish Red Cross, but there's something we can do more.

Thus we give out a 50% discount on all our courses and donate all the income to the Polish Red Cross

Please share/retweet

🌻

institute.sektor7.net/?coupon=DONATE…

account_circle
Vadim Khrykov(@BlackMatter23) 's Twitter Profile Photo

Considering current situation when my country is running down I see no longer future in Russia for me and my family. I open for any job offers relevant to my LinkedIn profile. Pease DM me, for detailed CV.

account_circle
The New York Times(@nytimes) 's Twitter Profile Photo

The Kremlin is hiding the reality of Russia's attack on Ukraine from its own people, even cracking down on news outlets that call it a “war.” But the truth is that President Vladimir Putin ushered in a crisis for his country, its economy and its identity. nyti.ms/3hj9mVR

account_circle
Ирина(@_roza15) 's Twitter Profile Photo

Люди со всего мира подписывают это открытое письмо против войны. Добавьте свой голос и поддержите народ Украины !
fb.avaaz.org/campaign/ru/st…

account_circle
The Independent(@Independent) 's Twitter Profile Photo

Thousands march in anti-war protests across St Petersburg after Ukraine invasion independent.co.uk/tv/news/russia…

account_circle
CBS News(@CBSNews) 's Twitter Profile Photo

Russians join anti-war protests as prominent artists and journalists reject Putin's claims cbsn.ws/3Ii990J

Russians join anti-war protests as prominent artists and journalists reject Putin's claims cbsn.ws/3Ii990J
account_circle
unbeGames(@unbeGames) 's Twitter Profile Photo

Most russian people are against this stupid war. It is a catastrophe, a disgrace and a crime against humanity. There's no excuse for that. I am ashamed of my country.

account_circle
The New York Times(@nytimes) 's Twitter Profile Photo

Aleksei Navalny, the jailed Russian opposition politician, condemned the invasion of Ukraine at a court hearing on Thursday. nyti.ms/3sdQ76g

Aleksei Navalny, the jailed Russian opposition politician, condemned the invasion of Ukraine at a court hearing on Thursday. nyti.ms/3sdQ76g
account_circle
Check Point Research(@_CPResearch_) 's Twitter Profile Photo

Can you trust a file's digital signature? 🤔
A new campaign abuses CVE-2013-3900 for defense evasion.

🔥 HTA content appended to a signed Microsoft DLL, without breaking trust
🔥 MSHTA used to execute the appended script
🔥 CVE-2013-3900 still unpatched by default

Can you trust a file's digital signature? 🤔 A new #Zloader campaign abuses CVE-2013-3900 for defense evasion. 🔥 HTA content appended to a signed Microsoft DLL, without breaking trust 🔥 MSHTA used to execute the appended script 🔥 CVE-2013-3900 still unpatched by default
account_circle
Vadim Khrykov(@BlackMatter23) 's Twitter Profile Photo

isn't a panacea, as well as traditional SOC. Learning real world pentest/redteam reports from our clients almost every time it is 50/50 visibility. MDR & SOC have their own blind spots for many reasons. Only combined services will give you around 100% visibility.

account_circle