nas_bench Profile Banner
Nasreddine Bencherchali Profile
Nasreddine Bencherchali

@nas_bench

Followers
11K
Following
24K
Media
1K
Statuses
8K

Detection @Splunk & @cisco | previously @nextronsystems | @sigma_hq & @magicswordio maintainer | Eternal Learner

HAL
Joined August 2011
Don't wanna be here? Send us removal request.
@nas_bench
Nasreddine Bencherchali
3 days
That's obviously a lie. Those TLS vulns are super important and are critical to the business. Don't believe the Internet 😉.
@techspence
spencer
3 days
You actually DONT need to patch EVERY vulnerability.
2
0
13
@nas_bench
Nasreddine Bencherchali
3 days
RT @33y0re: I cleaned up the code I have been working on for the last few days into a tool I’m calling “Vtl1Mon”!. Vtl1Mon traces VTL 1 ent….
Tweet card summary image
github.com
Virtual Trust Level (VTL 1) secure call tracing. Contribute to connormcgarr/Vtl1Mon development by creating an account on GitHub.
0
52
0
@grok
Grok
19 days
Blazing-fast image creation – using just your voice. Try Grok Imagine.
284
558
3K
@nas_bench
Nasreddine Bencherchali
4 days
Because I and the rest of the maintainer team we dont have infinite time. I'm going to be pretty aggressive on PRs submitted to @sigma_hq New so called DEs copy pasting random rules and not having the capacity to read the specs will lead to an auto close.
Tweet card summary image
github.com
Main Sigma Rule Repository. Contribute to SigmaHQ/sigma development by creating an account on GitHub.
3
5
37
@nas_bench
Nasreddine Bencherchali
4 days
Reminder that Living of the Land extends beyond whats available on an OS by default. A typical enterprise land will contains. - AV.- RMMs.- Third party drivers.- Custom scripts.- Third party software. And much more. When looking for Lolbins expand beyond the default landscape.
1
13
56
@nas_bench
Nasreddine Bencherchali
4 days
A gentle reminder that comes with every threat report that gets released. You can catch the 80% by focusing on Lolbins and using what's called "brittle rules".
Tweet card summary image
nasbench.medium.com
I never played poker so don’t quote me on that
1
19
74
@nas_bench
Nasreddine Bencherchali
6 days
RT @M_haggis: 🔥💻 New tool drop! Meet MSIXBuilder 🎁 — the ultimate MSIX package creator for security testing, red team ops, and detection en….
0
39
0
@nas_bench
Nasreddine Bencherchali
7 days
RT @_JohnHammond: I FINALLY got a chance to chat with James Kettle @albinowax and hear about his latest research, with a cool caption "HTTP….
0
43
0
@nas_bench
Nasreddine Bencherchali
8 days
RT @33y0re: You can trace calls to VslpEnterIumSecureMode ("enter/exit" into VTL 1) through the (the value is undocumented?) PERF_VTL1_ENTE….
0
19
0
@nas_bench
Nasreddine Bencherchali
9 days
RT @cyb3rops: People on here act like someone decides not to patch. Like there’s a guy who knows the service is vulnerable, knows it runs i….
0
108
0
@nas_bench
Nasreddine Bencherchali
11 days
RT @HackingLZ: Since lots of people turned AI or better yet just LLMs into a religion/cult, it gets lost that while AI can and will be impa….
0
8
0
@nas_bench
Nasreddine Bencherchali
11 days
RT @TeamCherryGames: Hollow Knight: Silksong will be available September 4 on all platforms and day one on Xbox Game Pass!. Watch the relea….
0
21K
0
@nas_bench
Nasreddine Bencherchali
11 days
RT @Wietze: Windows Defender blocks any procdump execution referencing "lsass" on the command line (1️⃣). Simply querying lsass' process ID….
0
140
0
@nas_bench
Nasreddine Bencherchali
13 days
RT @vxunderground: Why do video games use kernel-mode anti-cheats?.
Tweet card summary image
vx-api.gitbook.io
0
69
0
@nas_bench
Nasreddine Bencherchali
13 days
RT @TeamCherryGames: The countdown is on!. Join us in 48 hours for a special announcement about Hollow Knight: Silksong!. Premiering here:….
0
33K
0
@nas_bench
Nasreddine Bencherchali
15 days
Updated Dunning-Kruger effect for AI bros. No Enlightenment in sight. Mount Stupid is the end goal.
Tweet media one
2
1
6
@nas_bench
Nasreddine Bencherchali
16 days
🤔
@netbiosX
Panos Gkatziroulis 🦄
16 days
🧐When Defenders Become the Attackers: The Elastic EDR 0-Day (RCE + DoS)
3
0
23
@nas_bench
Nasreddine Bencherchali
17 days
RT @anton_chuvakin: Just heard a new comical take on #SIEM and AI agents: "I do not need a SIEM . because I can just ask the agent to GO….
0
11
0
@nas_bench
Nasreddine Bencherchali
17 days
Quick poll in regards to my recent blog Posts. Have you been enjoying the philosophical/mindset content?. Yes/No? please share what you like or dislike, and what topics you'd like covered🙏🤝🤍. If you haven't seen them. Please check out
0
1
3
@nas_bench
Nasreddine Bencherchali
19 days
[New Blog 📚] The Fragile Balance: Assumptions, Tuning, and Telemetry Limits In Detection Engineering. If you ever struggle with false positives and the idea of tuning detections. This is for you. Read More -
Tweet media one
3
29
64