Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

🤓 I've built the ultimate threat actor attribution tool!! Okay, okay… not quite ultimate, but still pretty useful. 😅 Let me explain. 👇 When you investigate an attack, sometimes you know what you are looking at—maybe you are an experienced analyst or have tracked a threat actor long enough...

21,542 Aufrufe • vor 1 Jahr •via X (Twitter)

11 Kommentare

Profilbild von (╯°□°)╯︵ S︵ T︵ ✍️
(╯°□°)╯︵ S︵ T︵ ✍️vor 1 Jahr

That is pretty useful, definitely help reduce attribution bias

Profilbild von Thomas Roccia 🤘
Thomas Roccia 🤘vor 1 Jahr

It works pretty well, it is not perfect but with some adjustments it can be very powerful. The quality of the data source here is the most important.

Profilbild von SecBriefs | Making Cybersecurity Simple
SecBriefs | Making Cybersecurity Simplevor 2 Jahren

🚨 Don't just read about cyberattacks; understand them. 🧠 Knowledge is the best defense against cyber threats. Stay ahead of the hackers. 💡 📖 Cybersecurity Dictionary for Everyone is your essential companion. Available on Amazon:

Profilbild von Andrew Thompson
Andrew Thompsonvor 1 Jahr

Love it with all my normal cautions.

Profilbild von Bjørnar Borge
Bjørnar Borgevor 1 Jahr

Nice job! 👌

Profilbild von Thomas Roccia 🤘
Thomas Roccia 🤘vor 1 Jahr

Thanks 🙏

Profilbild von J⩜⃝mie Williams
J⩜⃝mie Williamsvor 1 Jahr

@cyb3rops 👀💎🦾

Profilbild von BSIDES TLV
BSIDES TLVvor 1 Jahr

This is so cool ! Would you consider submitting to our CFP and presenting in #Telaviv this summer?

Profilbild von Thomas Roccia 🤘
Thomas Roccia 🤘vor 1 Jahr

Honestly, I would love to! I will see what I can do. 🤩

Profilbild von Alice Sn0w •ᴗ•
Alice Sn0w •ᴗ•vor 1 Jahr

@cyb3rops This tools seems wonderfull. Will you open it to let us use it ?

Profilbild von Thomas Roccia 🤘
Thomas Roccia 🤘vor 1 Jahr

@cyb3rops It is part of my training but I will see to have something for the community. This POC needs improvement though :)

Ähnliche Videos

(4 DAYS BEFORE SUBMISSIONS CLOSE) I get this question a lot about the Find Evil! hackathon: What does “find evil” actually mean? In this case, the name comes from a real command. I built an autonomous incident response agent I built on the SIFT Workstation. Then I typed “find evil” as a prompt into Claude Code. And it did (watch the demo). I was blown away to watch the autonomous agent run a complete C drive forensic analysis, across 200+ tools via MCP. The agent identified threat actor and context, the attack chain, malware deployment method, persistence mechanisms, code injection analysis, network connections, command-and-control (C2) infrastructure, a complete malicious process tree, and a chronological activity timeline. Two days after I shared initial findings, Anthropic released their report on how threat actors were deploying Claude Code with operational tools and letting it go do evil. (Same thing I was doing.) Find Evil! is the first hackathon dedicated to building autonomous AI agents for incident response. 4,178 defenders are working on final Find Evil! hackathon submits. (This number makes me very happy to see so many diving in. And wishing that the thousands more in our community were experimenting with us.) Your job: teach an AI agent to think like a senior analyst, how to sequence its approach, recognize when something doesn’t add up, and self-correct when it gets it wrong. There are FOUR DAYS left to build with us! (Very few of us are actual AI experts. The rest of us including me are learning.) Register: Apply to judge: We need DFIR, AI, cybersecurity, and open-source reviewers who can separate useful autonomous response tools from polished demos. Apply: I am SO EXCITED to see what comes out of this hackathon and goes back to the community. Sponsored by SANS Institute

Rob T. Lee

14,405 Aufrufe • vor 3 Monaten

Trump: Now they'll say all these stories are terrible. Well, these stories have, you know, you heard my story in the boat with the shark, right? I got killed on that. They thought I was rambling. I'm not rambling. We can't get the boat to float. The battery is so heavy. So then I start talking about asking questions. You know, I have an, I had an uncle who was a great professor at MIT for many years, long, I think the longest tenure ever. Very smart, had three different degrees and you know, so I have an aptitude for things. You know, there is such a thing as an aptitude. I said, well, what would happen if this boat is so heavy and started to sink and you're on the top of the boat. Do you get electrocuted or not? In other words, the boat is going down and you're on the top, will the electric currents flow through the water and wipe you out? And let's say there's a shark about 10 yards over there. Would I have to immediately abandon or could I ride the electric down and he said, sir, nobody's ever asked us that question. But sir, I don't know. I said, well, I want to know because I guarantee you one thing, I don't care what happens. I'm staying with the electric, I'm not getting over with it. So I tell that story. And the fake news they go, he told this crazy story with electric. It's actually not crazy. It's sort of a smart story, right? Sort of like, you know, it's like the snake, it's a smart when you, you figure what you're leaving in, right? You're bringing it in the, you know, the snake, right? The snake and the snake. I tell that and they do the same thing

Headquarters

2,056,689 Aufrufe • vor 2 Jahren

🚨Medical coder/whistleblower: Here's how Palantir's "KILL CHAIN" programs were used to target and "EXECUTE" American citizens with COVID jabs/remdesivir/ventilators. "They identified different hospitals or different individual patients based on [their 'threat risk score'] and [that's how they] determined [who]...to execute...with their AI kill-chain Gotham program." This clip of author, former medical coder, and whistleblower Zowe Smith (Sheldon Diedericks) is taken from an interview with James Corbett posted to Rumble on June 17, 2025. ----------------Partial transcription of clip--------------- "So there was a program called HHS Protect during Operation Warp Speed, was part of Operation Warp Speed. That's where I think most of the public-facing infrastructure began. Although I was looking into Operation Stargate, and I'm seeing documentation on CIA databases that say it's more than 10 years in the making. So, definitely it's, it's a planned thing. It didn't just come out with day two, Trump administration. "But, so this HHS Protect program is really interesting because what it did, it used two different Palantir programs. So the AMA, HHS, the CDC specifically, all partnered with Palantir. And then Palantir developed a program for Operation Warp Speed. And that program, what it did was it assigned people a Threat Risk Score. And then that was a program called Tiberius, which they also use for other purposes. "So I want to make this point about AI, because when I was a medical coder, I was using a program which is a partner of Palantir, both 3M and Epic, and those are two different programs that I use that both have AI built into them that are partners of Palantir. And so all of these AI databases talk to each other as a condition of working with each other. So this has been going on for a very long time. But within Epic there are programs and you can rename them whatever you want, but it's the same program at any hospital across the country. So, like your program, Epic, might not be named Epic at Johns Hopkins or Mayo, it might have a different name at Johns Hopkins or Mayo, but it's still the same program. "So this program from Palantir called Tiberius, they can rename that whatever they want, but the program will still do what it was programmed to do. It's, it's just a function really. And HHS had two programs built in. Tiberius was the thing that assigned you a Threat Risk score. And that was if you were following lockdown criteria, if you were actually distancing from people, if you had been vaccinated, if you were masking, you know, how obedient were you, that was your threat risk score. They also could determine down to the zip code where you were and how compliant areas were. "And so, as Whitney Webb covers from the Unlimited Hangout, she wrote a article covering this program, HHS Protect, and highlights how this was used to target ethnic groups. So this threat risk score also incorporated your ethnicity and they thought, you know, you're higher risk if you're certain ethnic groups. So of course that was part of the risk score. And then Gotham is the AI kill chain program created by Palantir and that was used within HHS Protect to execute. "So the Gotham program, it takes the threat risk score from Tiberius and then it executes the threat or tells, does an AI decision making process and decides when and how and where to deploy the countermeasures. Which was your vaccine, your remdesivir and your ventilator. That is why HHS Protect was created so that they could monitor all of this. And that is how they identified different hospitals or different individual patients based on some algorithm and determined that's how we're going to execute people with their AI kill chain Gotham program."

Sense Receptor

275,734 Aufrufe • vor 1 Jahr

Qullamaggie shows Exit Strategy for Long Swings “What’s your exit strategy for such long swings? How do you decide this? Okay, that’s easy. Let’s take an example, ROKU. So I bought it here, on the opening range size. It gapped up on earnings, huge volume. All the things I’m looking for. You know, long range break had like a 6, 7-month range break had surprising good earnings. Great growth, etc. I sell some, maybe 15 to 20%. A quarter of my position, and then I trail it. Then I just start trailing it like the first close below this purple line. That’s the 10-day moving average. I sell maybe say a quarter or a third of what I still have left. The shares I have left after the ones I bought. Sold into strength, and then I sell another third or quarter when it hits the first close below the 20-day moving average, which is the yellow line. And then the next level is the red line, which is the 50-day, etc. So that’s how I scale out. So that’s what I use these moving averages for. I wait for them to be my stop pretty much. So I wait until the end of the day and I sell it. Then I also have a level. Let’s just take an example right here. I usually use the previous swing’s lows as my stop. Then I would get out at 79. Even though it turns up intraday and closes above this yellow line, I would have to stop. You know, you can get stopped out because you know. I can, so you know. Sometimes stocks, they go, they can go down, you know, 20%.50% in a day, even. You know mid and large cap names can do that sometimes. So, you know, if it hits my last resort stop, it is my last resort stop. I just sell it. If that was helpful, those are my sell rules, sell into strength and I trail the rest.”

Lone

25,761 Aufrufe • vor 11 Monaten