Matt Watkins Profile
Matt Watkins

@MattWhatkins

Followers
946
Following
1K
Media
71
Statuses
2K

Threat Hunter / Security Engineer @WhitehattersA Founding Member. Views are my own.

UK
Joined October 2012
Don't wanna be here? Send us removal request.
@MattWhatkins
Matt Watkins
6 days
Does anyone else read @ThinkstCanary ThinkstScapes? How are you opening links to the respective blogs, my PDF reader doesn't recognise them as links and chromium won't let me right click and left click loses my spot in the doc ๐Ÿ˜”.
1
0
1
@MattWhatkins
Matt Watkins
11 months
I'll be at @fwdcloudsec Europe today. @PwnedLabs have kindly gifted some vouchers for their new MCRTP course - Microsoft Cloud Attack and Defence. Come find me if you're interested!.
0
2
6
@MattWhatkins
Matt Watkins
11 months
Anyone at @fwdcloudsec Europe this week?.
0
0
0
@MattWhatkins
Matt Watkins
1 year
If your company has bitlocker enabled and you're looking for a way for employees to get access to their recovery key, they may be about to get it here on work phones:
0
0
0
@MattWhatkins
Matt Watkins
1 year
Does CrowdStrike sensor policy update affect channel files too? Are customers on N-1/N-2 Builds affected?.
0
0
0
@MattWhatkins
Matt Watkins
1 year
CrowdStrike have updated their Tech Note: "Note: Bitlocker-encrypted hosts may require a recovery key.".
1
1
1
@MattWhatkins
Matt Watkins
1 year
Am I missing something? This CrowdStrike "fix" requires that the user knows the Bitlocker recovery key, or Bitlocker be disabled? . In 2024, are organisations not Bitlocker encrypting their devices?. It's going to be a rough weekend! ๐Ÿ™.
1
0
2
@MattWhatkins
Matt Watkins
1 year
Get the report here:
0
0
0
@MattWhatkins
Matt Watkins
1 year
"In nearly all of Mandiant's investigations involving compromised cloud accounts, attackers were observed enrolling their own MFA methods shortly upon gaining initial access." Mandiant M-Trends 2024. Great detection use case, especially with some user automation to validate!.
1
3
5
@MattWhatkins
Matt Watkins
1 year
How is AWS SkillsBuilder so bad as a learning platform? Logged out every time I come back to continue learning. Training video quality varies massively. Labs take an age to deploy and there's no automatic scoring. How is this the most popular cloud? ๐Ÿ˜‚ Is everyone using Udemy?.
2
0
1
@MattWhatkins
Matt Watkins
1 year
Currently working through FOR509 and can't stress how powerful and useful some of the Red and Blue labs are in @PwnedLabs to take the training to another level!.
0
1
4
@MattWhatkins
Matt Watkins
2 years
What custom tools are IR teams using for timelining investigations? Besides Sheets/Excel ๐Ÿ˜‚.
4
0
3
@MattWhatkins
Matt Watkins
2 years
Interesting episode on @riskybusiness about secure enterprise browsers. @island_io sounds very similar to Google's BeyondCorp Enterprise. Anyone looked at both and can share some insights?.
0
0
0
@MattWhatkins
Matt Watkins
2 years
With Google Authenticator now supporting cloud sync, what suggestions do folks have for 2FA apps? Google w/ online sync? Google w/o sync? Authy? An authenticator linked to a Password Manager?.
1
0
0
@MattWhatkins
Matt Watkins
2 years
Any other @dashlane customers happen to have had a random person to their Friends & Family account? I emailed the email and it was a poor user who had been trying to get support and had been given the wrong link to link their account. Pretty poor for a Security company. .
0
0
0
@MattWhatkins
Matt Watkins
2 years
In over 10 years of working on blue teams, only once have I worked with an EDR that could leverage YARA rules for in-memory scanning.
0
0
3
@MattWhatkins
Matt Watkins
2 years
Who actually uses yara rules in their SOC/threat detection capability outside of TI functions? Do many commercial EDR solutions actually support scanning with YARA rules? Are companies deploying random scripts to perform YARA scanning?.
15
5
9
@MattWhatkins
Matt Watkins
2 years
Hey @EastMidRailway Why are your train staff so imposing when trying to get onto a train? It's one thing to enforce having a ticket to travel, another thing to stand and block anyone getting on without showing a ticket. I've never seen this before on any line?.
1
0
1
@MattWhatkins
Matt Watkins
2 years
RT @egre55: I'm excited to announce that @PwnedLabs will soon offer individual and business pro subscription tiers, building on our free ofโ€ฆ.
0
9
0