Erik Van Buggenhout
@ErikVaBu
Followers
2K
Following
1K
Media
125
Statuses
618
Co-founder of NVISO, SANS Instructor & Author. Failed comedian. Red (purple) teaming & incident response.
Brussels, Belgium
Joined June 2010
Our NVISO #IncidentResponse Team has been tracking #VShell campaigns worldwide! More than 1,500 active VShell servers were uncovered, each capable of giving attackers remote control over compromised networks. Read the report here ๐ https://t.co/XjAIIe99UH
3
14
30
"On September 29th, 2025, Broadcom disclosed a local privilege escalation vulnerability, CVE-2025-41244, impacting VMwareโs guest service discovery features. @NVISO_Labs has identified zero-day exploitation in the wild beginning mid-October 2024. The vulnerability impacts both
blog.nviso.eu
NVISO has identified zero-day exploitation of CVE-2025-41244, a local privilege escalation vulnerability impacting VMware's guest service discovery features.
3
51
138
๐ค I have built an MCP for YARA rule creation and it works pretty great! With DocYara MCP, you can: โ Generate YARA rules โ Validate and optimize them โ Deploy your rule directly to VirusTotal Livehunt I did a full walkthrough on YouTube in the second tweet ๐
5
47
169
โน๏ธ Coming to RSACโข 2025: Three cutting-edge SANS sessions lined up for Day 2 next Tuesday ๐น Kubernetes defense w/ Eric Johnson & @thecybergoof ๐น AI & threat modeling w/ @aboutsecurity & @fulmetalpackets ๐น Purple teaming w/ @ErikVaBu & Jeroen Vandeleur Get the full lineup โ
1
4
7
Headed to this year's @RSAConference? From purple teaming to critical infrastructure to the future of detection and response, here are 12 #RSAC talks we think are worth making time for while there:
redcanary.com
How AI agents can help purple teaming, inside the stolen credential ecosystem, and more: We read through the RSA agenda so you don't have to.
2
2
7
I'll be moderating this panel on continuous penetration testing. The panelists are all active practitioners who will provide insight on their experiences and predictions on this topic, along with the general role of AI and automation as an aid. @ChrisADale @ErikVaBu @joswr1ght
โ Annual pen testing isnโt enough. Your offensive security needs a new approach. Tomorrow, a SANS expert panel will break down how Continuous Penetration Testing (CPT), AI, and automation are reshaping offensive security as we know it. ๐ Register now: https://t.co/h9A4uvwxKD
1
5
18
New blog post! Title: Detecting Teams Chat Phishing Attacks (Black Basta) by Stamatios Chatzimangou Link: https://t.co/zPpc6rxCDi
#SOC #BlueTeam #Phishing #Sentinel #KustoQueryLanguage #SIEM #BlackBasta
blog.nviso.eu
Uncover "Black Basta" ransomware tactics: spam floods, fake IT support on Teams, and remote access scams. Learn detection and prevention strategies now.
0
18
56
๐ฎ Ready to see the future of #DetectionEngineering? Join @Steph3nSims & @ErikVaBu TOMORROW to learn how to create an automated, always-on pipeline that integrates #SOC tech, SIEM/XDR, SOAR, & ChatGPT. โก๏ธ Register: https://t.co/EtaPRusTk2
#PurpleTeaming #Automation
0
1
4
What if your #DetectionEngineering pipeline was always on? ๐ฎ ๐ Join @Steph3nSims and @ErikVaBu as they show how to automate your detection analytics with a CI/CD pipeline that continuously tests and deploys in real-time. โก๏ธ Register: https://t.co/EtaPRusTk2
#PurpleTeam
0
1
2
The new 3-day course "SEC535: Offensive AI" is currently in development with "Foster Nethercott" @OSTact13, who just joined Twitter/X. I'm really looking forward to this one! It should be set to beta in a few months.
3
14
46
Learn how to build the always-on purple team through #GenAI automation merged with industry-leading SOC technologies. Speakers @Steph3nSims and @ErikVaBu share their methodology, backed by demo, in this recorded #RSAC 2024 presentation.
rsaconference.com
0
3
3
Quick Hackfest Hollywood keynote announcement: Day One Keynote: David Weston (@dwizzzleMSFT) Day Two Keynote: Yarden Shafir (@yarden_shafir) October 28th & 29th in Los Angeles! Register for virtual (free) & in-person attendance here:
0
26
42
โ ๏ธ Session alert: Did you catch @ErikVaBu, SANS Instructor & Co-founder of @NVISOSecurity, in his compelling session 'From Chatbot to Destroyer of Endpoints: Can ChatGPT Automate EDR Bypasses?' Share key takeaways! @RSAConference | #Cybersecurity #TheArtOfPossible
1
1
5
At RSA 2024 SF I'll be doing a co-talk with @ErikVaBu on "The Always On Purple Team: An Automated CI/CD for Detection Engineering" on May 5th at 10:50AM, as well as a Keynote Panel on "The Five Most Dangerous New Attack Techniques You Need to Know About" on May 7th at 4:15PM!
1
4
23
๐
Join us on May 16 in #Brussels for the 12th EU @MITREattack Community Workshop. Register now for free at https://t.co/WpwoRoU25H
@CCBbelgium
#CenterForThreatInformedDefense #CCBConnectAndShare Speakers: myself, @ErikVaBu @run2obtain @FDezeure @NebzzzV @WLesicki @rmasuoka ...
eventbrite.be
The 12th EU MITRE ATTACKยฎ Community Workshop will take place on 17/05/24 from 9.30am until 5.30pm (CEST) and is hosted by the CCB.
1
5
16
RSA CFP Results: 1 talk Accepted - The Always-On Purple Team: An Automated CI/CD for Detection Engineering with @ErikVaBu 1 talk Declined - The State of Binary Exploitation: How much time do we have left? I fought the urge to do an AI talk! ๐
3
3
19
Our Day 2 keynote speaker at Hackfest Hollywood in November is Lina Lau (@inversecos), delivering some cutting-edge cloud hacking content! The full agenda with all speakers to be announced very soon! https://t.co/99hVRdebwZ
@SANSOffensive
We are thrilled to have @inversecos Keynote #SANSHackFest this November! Join us in Hollywood for 2 days of highly technical talks, a NEW #OffensiveOps CTF, and a chance to connect with legends in the #PenTest community. Learn More: https://t.co/gcBBCfqgy5
#RedTeam #Cloud
0
20
36
How can we ensure purple teaming is not a stand-alone activity and integrate it into Continuous Security Operations efforts? Purple team experts @Steph3nSims & @ErikVaBu have an answer in this #RSAC 2023 Top-Rated Session. https://t.co/MkzdK2O7zF
0
3
7
Quite the turnout for @Steph3nSims and @ErikVaBu of @NVISOsecurity speaking about Building The Always-On #PurpleTeam. #RSA2023 Think we might have to run this as a webcast. Let us know what you think!
0
3
9
๐จ BETA COURSE ๐จ New SANS course SEC598 #SecurityAutomation for Offense, Defense, & #Cloud is now open for registration. Special BETA PRICING applies to this run only! This course will sell out. View the syllabus and register here: https://t.co/ZtW4D9WZwc
0
2
12