Christophe Tafani-Dereeper Profile
Christophe Tafani-Dereeper

@christophetd

Followers
6K
Following
4K
Media
774
Statuses
11K

302 Location: https://t.co/tP3JTD3HQp

🇨🇭+ 🇫🇷
Joined September 2009
Don't wanna be here? Send us removal request.
@christophetd
Christophe Tafani-Dereeper
3 years
📢 Today, I'm thrilled to announce "Stratus Red Team", an open-source adversary emulation tool for the cloud!. Comes with a catalog of cloud-native attack techniques that you can easily detonate to test your threat detection. 📝
Tweet media one
Tweet media two
13
277
742
@christophetd
Christophe Tafani-Dereeper
7 months
RT @arstechnica: Yearlong supply-chain attack targeting security pros steals 390K credentials
0
8
0
@christophetd
Christophe Tafani-Dereeper
7 months
RT @__steele: Back in 2022 I started a project I called vpcshark. Since then, AWS has launched three generations of EC2 instances without t….
0
14
0
@christophetd
Christophe Tafani-Dereeper
8 months
I don't want to fully commit to never using Twitter ever again, but I'll try to post my content mostly on Bluesky and Mastodon.
0
0
1
@christophetd
Christophe Tafani-Dereeper
8 months
Come say hi on Bluesky!
Tweet media one
2
0
2
@christophetd
Christophe Tafani-Dereeper
8 months
RT @Frichette_n: I’m very excited for this to be released! RCPs cover a need to restrict external access to resources across your organizat….
0
14
0
@christophetd
Christophe Tafani-Dereeper
8 months
Fun with Google Cloud's default service accounts (and how to leverage them for offensive purposes).
1
21
50
@christophetd
Christophe Tafani-Dereeper
9 months
RT @net_code: Fresh from the oven 📷. Analysis of NPM malicious packages connected to contagious interview campaign.
0
4
0
@christophetd
Christophe Tafani-Dereeper
9 months
RT @datadoghq: Our team created a K8s sidecar container to support cross-cloud access in a multi-cloud environment. It simplifies access to….
0
2
0
@christophetd
Christophe Tafani-Dereeper
9 months
Excited to share some research I've been working on for the past few months, based on real-world data from thousands of environments using AWS, Azure and Google Cloud!.
1
32
79
@christophetd
Christophe Tafani-Dereeper
9 months
Stratus Red Team now supports an Amazon Bedrock attack technique to simulate LLMjacking, thanks to a contribution from @_brucedh!.
Tweet media one
Tweet media two
Tweet media three
0
8
30
@christophetd
Christophe Tafani-Dereeper
9 months
RT @0xdabbad00: Interesting update to the quarantine policy. 👀.
0
2
0
@christophetd
Christophe Tafani-Dereeper
9 months
RT @healdevHQ: Today we’re happy to announce that is moving to private Beta. At heal, we’re building an AI-powered….
0
19
0
@christophetd
Christophe Tafani-Dereeper
9 months
RT @fwdcloudsec: The recordings for fwd:cloudsec Europe talks are now on YouTube!
0
25
0
@christophetd
Christophe Tafani-Dereeper
9 months
RT @ericonidentity: I��ve had this research from @_sigil bookmarked for a thorough read through. Excellent technical dive into abusing AU’s….
0
9
0
@christophetd
Christophe Tafani-Dereeper
10 months
RT @_sigil: 🦎 It's up! Using Entra ID AUs for sticky accounts and hidden permissions:.
0
22
0
@christophetd
Christophe Tafani-Dereeper
10 months
github-scanner[.]com.github-scanner[.].shop.2x[.]si/l6E.exe / fac2188e4a28a0cf32bf4417d797b0f8 (FormBook infostealer).
2
0
6
@christophetd
Christophe Tafani-Dereeper
10 months
Interesting phishing website registered a few hours ago that automatically copies malicious PowerShell code in your clipboard, then asks you to "press Windows+R and Ctrl+V". Currently spamming 1k+ GitHub issues:
Tweet media one
Tweet media two
4
20
112
@christophetd
Christophe Tafani-Dereeper
10 months
RT @fwdcloudsec: We're incredibly excited that fwd:cloudsec Europe is happening tomorrow, in Brussels. All the talks will be livestreamed….
0
15
0
@christophetd
Christophe Tafani-Dereeper
10 months
RT @0xdabbad00: Oof, AWS had a bug that allowed Transit Gateway peering requests to be accepted by the requestor, so an attacker could acce….
0
65
0
@christophetd
Christophe Tafani-Dereeper
10 months
Just in time for fwd:cloudsec Europe, Stratus Red Team now supports 6 Microsoft Entra ID (Azure AD) attack techniques!🌩️ 😈. brought to you by my awesome colleague @_sigil and yours truly!
Tweet media one
Tweet media two
1
13
54