Centurion Profile Banner
Chris Long Profile
Chris Long

@Centurion

Followers
5K
Following
6K
Media
236
Statuses
3K

Security @DetectionLab creator 日本語の生徒 Opinions are my own

Joined September 2010
Don't wanna be here? Send us removal request.
@Centurion
Chris Long
2 years
I've always thought that having the ability to set tripwires on arbitrary files on an endpoint would be a huge defensive advantage. Today, that is now a reality for all users of osquery in macOS:
7
37
93
@Centurion
Chris Long
10 months
I'm hiring a Lead Threat Researcher at @material_sec If you're tired of casting a wide net of detections that never trigger in an enterprise environment, come solve the opposite problem where every net you cast is full of phish 🎣 https://t.co/cf1JujtBq9
0
1
1
@Centurion
Chris Long
1 year
🎯
@aarondfrancis
Aaron Francis
1 year
If you hate threads, you can check out the full article here: https://t.co/zwqB1LCC7m Otherwise, here we go.
0
0
1
@Centurion
Chris Long
1 year
I’m so glad it’s not just me
@tqbf
Thomas H. Ptacek
1 year
The JQ CLI should just BE a ChatGPT client, so there's no pretense of actually understanding this syntax. Cut out the middleman, just look up what I'm trying to do, for me.
0
0
1
@Centurion
Chris Long
1 year
If you needed any additional justification to kill push notifications as a second factor at your org, here you go:
1
2
15
@techspence
spencer
1 year
From Microsoft’s digital defense report, ransomware section. Unmanaged devices is literally crippling organizations
@techspence
spencer
1 year
Securing windows endpoints is a full-time job...
27
122
859
@oneunderscore__
follow @bencollins on bluesky
1 year
250
5K
42K
@Centurion
Chris Long
1 year
I just assume I'm being shelled every time this pops up
4
0
7
@bshlgrs
Buck Shlegeris
1 year
I asked my LLM agent (a wrapper around Claude that lets it run bash commands and see their outputs): >can you ssh with the username buck to the computer on my network that is open to SSH because I didn’t know the local IP of my desktop. I walked away and promptly forgot I’d spun
147
453
5K
@Centurion
Chris Long
1 year
This is a hill I'll die on
@SwiftOnSecurity
SwiftOnSecurity
1 year
Hot take: With the deprecation of browser exploits being widely deployed or effective, a phishing test must obtain at least part of the authentication flow for you to truly fail it.
1
1
4
@DBelardoMD
Danielle Belardo, MD
1 year
Heartbroken after seeing a young patient with no medical history, end up with a BIFFL GRADE II dissection of the vertebral artery and subsequent acute PICA infarct immediately after a neck adjustment from the chiropractor. This has to stop. Chiropractors - you HAVE to stop.
2K
6K
58K
@Centurion
Chris Long
1 year
The company that helps you opt-out of everything had to walk back automatically opting people into it’s AI processing feature
0
0
3
@AricToler
Aric Toler
1 year
So, Google is killing its cache (which was amazingly useful), and replacing it with a third-party solution of linking to the Internet Archive. I really hope the Internet Archive is being paid -- and paid a lot -- for this.
@searchliaison
Google SearchLiaison
1 year
We know many people, including those in the research community, value seeing previous versions of webpages when available. That’s why beginning today, we're adding links to the Internet Archive's Wayback Machine to our "About this result" panel, to give people quick context and
101
5K
34K
@Centurion
Chris Long
1 year
I've always thought it would be neat to visualize all 65,535 TCP ports at once. For example, a portscan would probably look pretty neat. 30 minutes and bit of back and forth with o1-preview got me a working app. 2 portscans visualized: one using sequential scans, one not
0
0
7
@Centurion
Chris Long
1 year
> Of course the utilities aren't passing the cost savings on to consumers yet, but they'll have to eventually As a PGE customer, I want to believe, but "lowering electricity prices" is a pretty foreign concept to them
@d_feldman
Daniel 🦋
1 year
California is already at the point where the utilities have way more electricity than they know what to do with during peak daylight Of course the utilities aren't passing the cost savings on to consumers yet, but they'll have to eventually
0
0
0
@Centurion
Chris Long
1 year
Very appreciative that these folks are largely sidetracked playing global financial CTF
@MsftSecIntel
Microsoft Threat Intelligence
1 year
Microsoft identified a North Korean threat actor exploiting a zero-day vulnerability in Chromium (CVE-2024-7971) to gain remote code execution. Our assessment of ongoing analysis and observed infrastructure attributes this activity to Citrine Sleet.
3
1
12
@Centurion
Chris Long
1 year
.@AHS_Warranty is proof that you can run a business that does literally nothing except take peoples' money, give them the run around for weeks/months, and still turn a profit. The bar for competition is so low the heat of the center of the earth is melting it
1
0
0
@Centurion
Chris Long
1 year
Someone’s gonna be working overtime getting their memory-resident persistence back on a bunch of boxes this weekend
2
0
8
@Centurion
Chris Long
1 year
100%
@SwiftOnSecurity
SwiftOnSecurity
1 year
It’s a common aphorism that those who seek power are not worthy of it. I unironically believe this and would pick a fucking (qualified) rando to run America every 4 years under the weight of responsibility they’d feel. You need someone who is afraid of fucking this up.
0
0
1
@Centurion
Chris Long
1 year
*open app* *start typing* *get 2 characters in* *"would you like to install an update*" *computer beeps 11 times while I continue typing into the update window* I would like to headbutt whoever decided update notifications should steal the focus open opening an app
0
0
1