ex_raritas Profile Banner
Andrew Northern ๐“…“ Profile
Andrew Northern ๐“…“

@ex_raritas

Followers
5K
Following
23K
Media
2K
Statuses
17K

๐Ÿ”ฎ Principal Researcher at Censys ๐Ÿ”ฎ | formerly Proofpoint | Knowledge Piรฑata ๐Ÿช… | Attack Chain Connoisseur | Epicurean

Joined April 2009
Don't wanna be here? Send us removal request.
@ex_raritas
Andrew Northern ๐“…“
1 year
Earlier this year I discovered and identified a novel sub-technique of defense evasion, which I have named โ€œByte Order Masking.โ€ This technique was included in the April 2024 release of the @MITREattack framework. This is my third contribution. ๐Ÿฅ‡๐Ÿฅ‡๐Ÿฅ‡ Read about it here:
6
9
67
@ex_raritas
Andrew Northern ๐“…“
2 days
Please include network indicators in your malware write ups. Ty.
0
1
23
@ex_raritas
Andrew Northern ๐“…“
4 days
If you wonder what the owl in my name is for:
1
0
9
@ex_raritas
Andrew Northern ๐“…“
4 days
Right by my house. So stoked.
@ThunderWolf08
โšก๐™๐™๐™ช๐™ฃ๐™™๐™š๐™ง ๐Ÿบ
5 days
KC Streetcar Mainstreet extension opens today!! Extending the line 8 new stations. Hopefully the city keeps expanding!!
0
0
5
@ex_raritas
Andrew Northern ๐“…“
5 days
I know I posted about this earlier, but if you missed the linked thread, take a moment to read it. Imagine being a SOC analyst responding to an alert. Most IOC or reputation feeds tell you something was flagged, but not why. Or even in some cases if itโ€™s just stale data creating
@ex_raritas
Andrew Northern ๐“…“
5 days
When is the last time your vendor gave you receipts?
2
3
18
@ex_raritas
Andrew Northern ๐“…“
5 days
When is the last time your vendor gave you receipts?
@censysio
Censys
5 days
๐ŸŽ‰ Introducing Threat Evidence in the Threat Hunting module! Censysโ€™s near real time validated threat data contextualizes alerts so you can make quick decisions. Now, with Threat Evidence, you can get additional context into how Censys detects specific threats to enhance your
0
1
12
@ex_raritas
Andrew Northern ๐“…“
6 days
Gotta take time to say that Iโ€™m having a really good time at the new job. I get to look at some really wild stuff.
2
0
18
@ex_raritas
Andrew Northern ๐“…“
6 days
Time context when it comes to iocs is important
0
0
1
@ex_raritas
Andrew Northern ๐“…“
6 days
๐Ÿ”ฅ โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ
@censysio
Censys
6 days
๐Ÿ”Ž The Censys Research Team investigated the fallout from a recent extortion campaign targeting Oracleโ€™s E-Business Suite (EBS). The campaign leveraged a zero-day vulnerability, exfiltrated data, and leaked said data if extortion fees remained unpaid. ๐Ÿ—บ๏ธ Today, Censys observes
0
0
6
@ex_raritas
Andrew Northern ๐“…“
6 days
Having one of those ADHD mornings where I canโ€™t remember if I took my medication. Now I have to wonder if I took it twice.
4
0
4
@censysio
Censys
9 days
๐ŸŒ Censys analyzed todayโ€™s AWS outage (Top 1,000) ๐Ÿ‘‰ 11.5% use AWS; 9.9% AWS-only ๐Ÿ‘‰ 24.2% IPs on AWS ๐Ÿ‘‰ Most in AS16509 (N. America & Europe) โšก ~25% of infra behind zillow, espn & imdb lives on AWS showing how outages impact the Internet. โžก๏ธ See more: https://t.co/vu9dSS2oco
0
6
10
@WaldronKC
Jason Waldron
10 days
New #kcstreetcar route maps are ๐Ÿ”ฅ. See you Friday.
2
7
74
@ex_raritas
Andrew Northern ๐“…“
12 days
don't talk to me unless you use the Alibaba web browser.
6
1
13
@censysio
Censys
14 days
๐Ÿš€ Excited to partner with @vtxproject The Synapse + Censys power-up enriches investigations with real-time & historical internet data. Stay tuned for whatโ€™s next! #CyberSecurity #ThreatIntelligence https://t.co/MwvA3CzVxb
@vtxproject
The Vertex Project
14 days
Analysts, take note: Censys just leveled up in proactive threat hunting. Weโ€™ve updated our Synapse @Censysio Power-Up to matchโ€”bringing faster discovery, richer context & repeatable enrichment. Try it: https://t.co/DDMDddAXTn
0
4
5
@ex_raritas
Andrew Northern ๐“…“
13 days
Want to slice and dice Censys data right in your terminal? ๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡ CC: @greglesnewich ;)
@censysio
Censys
15 days
๐Ÿš€ Introducing the Censys CLI โ€” the power of Censys, now in your terminal. โšก Work where youโ€™re fastest: Run Censys searches directly from your terminal. ๐Ÿ” Instant visibility: Quickly lookup IPs, certificates, and web properties to make investigative decisions. ๐Ÿ“Š Smarter
1
2
5
@censysio
Censys
13 days
๐Ÿšจ New from Censys: ICS/OT Internet Intel ๐Ÿšจ Unmatched visibility into ICS systems: โšก 26 protocols ๐Ÿญ 68 vendors ๐Ÿ›ก๏ธ 226 unique fingerprints Spot, validate & secure exposed assets at scale. ๐Ÿ‘‰ Learn more: https://t.co/bs1v88Uzmr #CyberSecurity #ICS #OT #CriticalInfrastructure
0
2
9
@JayCuda
Jay Cuda
16 days
the remaining MLB team closest to each county in the contiguous united states
133
181
7K
@ex_raritas
Andrew Northern ๐“…“
21 days
Very tempted to set off some fireworks ๐ŸŽ† #RepBX
0
0
2
@ex_raritas
Andrew Northern ๐“…“
21 days
I wrote a JQ wrapper that enumerates the keys and lets you pick the fields in a tui and then saves the field selections as a name that can be called later.
@GrahamHelton3
Graham Helton (too much for zblock)
22 days
I have a confession to make I would rather use grep on json files over JQ
0
0
4
@ex_raritas
Andrew Northern ๐“…“
24 days
Toronto putting up a football score
0
0
4
@ex_raritas
Andrew Northern ๐“…“
24 days
MVP or sum
@KutterIsKing
KutterIsKing
24 days
Correct me if Iโ€™m wrong but usually you donโ€™t want your face planted in the fence when the ball is right there
0
0
3