Richard Rushing
@SecRich
Followers
4K
Following
5K
Media
272
Statuses
8K
Long Time Security Guru, CISO, Watching the same problems. same issues. Wireless, Network, Mobile, Exploits, and Malware. So many ways, just so little time :)
Chicago, IL
Joined October 2009
Finding misconfigs in Active Directory is free…outside of your time. Here are 9 of my favorite tools (all free): Overall - PingCastle/PurpleKnight Permissions - ADeleg/ADeleginator* Attack paths - BloodHound Applocker - Applocker Inspector* ADCS - Locksmith Logon scripts -
3
72
403
Fraud Tools, Tactics, and Techniques (FT3) is Stripe's adaptation of ATT&CK-style security frameworks, specifically designed to enhance our understanding of the tactics, techniques, and procedures (TTPs) used by actors in fraudulent activities
github.com
FT3: Fraud Tools, Tactics, and Techniques Framework - stripe/ft3
0
54
210
I see Fortinet is firing back. Apparently my GitHub profile now qualifies as a malicious website in their web filtering appliances. (Okay, probably just an automated trigger on APTSimulator or the ransomware simulator repo. But maybe … )
10
10
136
I used to be very frustrated when security researchers published detailed vulnerability reports - meticulously describing every step of the discovery process but failing to include indicators of compromise or exploitation. It’s not about writing detection rules for us. Just
5
22
151
🤓 Reverse Engineering and LLMs, 2 years ago when I created my first agent for RE, it was already pretty impressive. Fast forward to today, more people are using LLMs for reverse engineering. So here are a few tools for RE you might want to check out: ➡️ Radare AI:
2
38
205
Installing Your Own Command and Control Server on Kali Linux https://t.co/n7cmQZkIEM
7
130
639
9 Platforms to Get FREE Cybersecurity E-Books 1. PDF Drive 2. Heimdal Security 3. CollegeLearners 4. Endureka 5. Freetechbooks 6. Free Computer PDF 7. Online Programming Books 8. Infobooks 9. Simplilearn
6
145
738
IngressNightmare: 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX by @wiz_io this is bad https://t.co/vdOC6VVt1L
9
106
337
Day 2 at #BHMEA24’s Capture the Flag is in full swing. 💰 SAR 1,000,000 on the line. 💻 250 teams, 1,000 minds in a race against time. ⚡ Witness strategy, precision, and speed collide as teams battle for the crown. The final round is coming—be there to see who dominates the
5
7
26
Up close with one of the brightest minds in the industry 🙌 Gary Hayslip, CSO of Softbank Advisors, took the stage for an exclusive book signing, sharing his insights and connecting with cybersecurity enthusiasts. #BlackHatMEA2024 #Cybersecurity #BookSigning
25
1
9
The #BHMEA24 Activity Zone by HABOOB is where theory meets hands-on challenges. ⚙️Critical infrastructure Security Hacking. 🔑 Lock Picking. 🔧Hardware Hacking. Are you ready to jump in? Register now: https://t.co/GLyLBYhIWS
#BHMEA24 #blackhatmea #BlackHat_At_Malham
14
1
10
Dr. Kevin Jones took the stage to share groundbreaking insights on The AI Race in Cyber Security: A Corporate View. This is the thought leadership you won’t find anywhere else. Catch more like this at Black Hat MEA 2024— https://t.co/GLyLBYhIWS
#BHMEA24 #blackhatmea
1
2
4
Day Two of #BHMEA24 is in full swing, and the energy is unbelievable. Catch today's groundbreaking keynotes, experience the immersive Activity Zone, and make connections that matter with the cybersecurity community. Secure your spot and catch the rest of Day Two -
4
3
8