Matt Graeber

@mattifestation

Father, husband, Navy vet, all around n00b. Security optimist. Security Researcher . A rabbit thriving in his hole.

Bouvetøya
ಏಪ್ರಿಲ್ 2009 ಸಮಯದಲ್ಲಿ ಸೇರಿದ್ದಾರೆ

ಟ್ವೀಟ್‌ಗಳು

ನೀವು @mattifestation ಅವರನ್ನು ತಡೆಹಿಡಿದಿರುವಿರಿ

ಈ ಟ್ವೀಟ್‌ಗಳನ್ನು ವೀಕ್ಷಿಸಲು ನೀವು ಖಚಿತವಾಗಿ ಬಯಸುವಿರಾ? ಟ್ವೀಟ್ ವೀಕ್ಷಣೆಯು @mattifestation ಅವರ ತಡೆತೆರವುಗೊಳಿಸುವುದಿಲ್ಲ

  1. 19 ಗಂಟೆಗಳ ಹಿಂದೆ

    This x 1000. Embracing change both professionally and personally has consistently improved my quality of life. Reminders like this are extremely valuable IMO. Complacency is the worst!!!

    ರದ್ದುಗೊಳಿಸು
  2. ಡಿಸೆಂ 24

    I'm pleased to get this out there as this comprises the knowledge I wish was available to me when I first started digging into ETW from a security perspective. I'm excited for the follow-on post!!!

    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು
  3. ಡಿಸೆಂ 24

    The first in a series of ETW attack/defense posts, I present my first blog post! Windows Event Log Tampering: Background, Offense, and Defense

    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು
  4. ಡಿಸೆಂ 21

    At the risk of embarrassing myself considering I am stupid when it comes to hash collisions, considering a single null byte is a Windows, catalog-signed file, is a SHA256 collision for a single byte much more computationally feasible? /cc

    ರದ್ದುಗೊಳಿಸು
  5. ಡಿಸೆಂ 21

    A little preview of some forthcoming work of mine. These are the ETW providers you (you as in anyone besides MSFT) likely never realized existed. Vendors, defenders, and attackers have some pretty sweet data sources to tap into...

    ರದ್ದುಗೊಳಿಸು
  6. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 21

    Doesn't matter if I'm spending my weekends reading Microsoft documentation to prep for a project or traveling through Chile/Argentina to camp in Patagonia, the journey is the destination

    ರದ್ದುಗೊಳಿಸು
  7. ಡಿಸೆಂ 20

    Early to the best case handler in existence - ! ❤️ Other vendors should learn from this man how to handle reports in a timely, professional, and transparent fashion.

    ರದ್ದುಗೊಳಿಸು
  8. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 20

    Reviewing old bugs of mine and was reminded of this one(CVE-2018-0884). Unsafe BinaryFormatter deserialization in the Windows Firewall MMC snap-in during copy/paste :D (The machine I'm RDP-ing to is Win10S machine, so it had a strict Device Guard policy on it)

    ರದ್ದುಗೊಳಿಸು
  9. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 19
    ರದ್ದುಗೊಳಿಸು
  10. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 18

    Pictured: head -1 <100 random samples of invoke-mimikatz> | sort -u

    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು
  11. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 18

    The video for our recent Q&A webinar is now online! You can view the recording here:

    ರದ್ದುಗೊಳಿಸು
  12. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 18

    Reminder: At 10:00AM PT today and will be doing a special webinar on , answering your questions live. Register at: . Will be recorded for future viewing as well.

    ರದ್ದುಗೊಳಿಸು
  13. ಡಿಸೆಂ 15

    Two of many things I love about climbing: 1) the utter lack of ego in pretty much everyone. Most people cheer one another of different skill levels on and 2) the amount of 50+ men and women cranking out challenging problems/routes. ❤️

    ರದ್ದುಗೊಳಿಸು
  14. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 14

    Following on the the latest release of , I wanted to share a little bit of my experience while integrating the Sigma project via Elastalert. I hope this post helps to provide some more details about it! KSQL post is next 😉🦌🎄🎄 🍻

    ರದ್ದುಗೊಳಿಸು
  15. ಡಿಸೆಂ 14

    shout-out to some of my favorite companies who put out incredible work/tools and hire incredible people: (this is a non-paid, truly genuine endorsement 😊)

    ರದ್ದುಗೊಳಿಸು
  16. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 13

    Interested in osquery for the enterprise? just released two awesome blog posts on it! Learn how osquery and auditd work under the hood, as well as how to tune/operate osquery at scale. Part 1: Part 2:

    ರದ್ದುಗೊಳಿಸು
  17. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 12

    One thing is true of the current set of endpoint security products: they either offer you great visibility or they offer you great protection, writes . None currently offer both.

    ರದ್ದುಗೊಳಿಸು
  18. ಡಿಸೆಂ 11

    Yes, there are orgs out there who implement application whitelisting in enforcement mode at scale and they take that shit _very_ seriously. To those defenders out there putting in the leg work, 💙

    ರದ್ದುಗೊಳಿಸು
  19. ಡಿಸೆಂ 11

    This is a really cool capability. tl;dr: C# compilation and execution w/o any csc.exe command-line or compilation disk artifacts using Roslyn! 😎

    ರದ್ದುಗೊಳಿಸು
  20. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 11

    Ever wanted a .NET scripting engine, but wanted it to be much, much worse than PowerShell? [blog + tool] SharpShell: The Worst Scripting Engine of All-Time -

    ರದ್ದುಗೊಳಿಸು

ಲೋಡಿಂಗ್ ಸಮಯ ಸ್ವಲ್ಪ ತೆಗೆದುಕೊಳ್ಳುತ್ತಿರುವಂತೆನಿಸುತ್ತದೆ.

Twitter ಸಾಮರ್ಥ್ಯ ಮೀರಿರಬಹುದು ಅಥವಾ ಕ್ಷಣಿಕವಾದ ತೊಂದರೆಯನ್ನು ಅನುಭವಿಸುತ್ತಿರಬಹುದು. ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ ಅಥವಾ ಹೆಚ್ಚಿನ ಮಾಹಿತಿಗೆ Twitter ಸ್ಥಿತಿಗೆ ಭೇಟಿ ನೀಡಿ.

    ಇದನ್ನೂ ಸಹ ನೀವು ಇಷ್ಟಪಡಬಹುದು

    ·