r3nzsec Profile Banner
Renzon Profile
Renzon

@r3nzsec

Followers
4K
Following
5K
Media
300
Statuses
3K

IR/Forensics @Unit42_Intel | Co-Founder @guidemtraining | Contributor/Analyst @TheDFIRReport @XintraOrg | CTF member @_hackstreetboys

Joined July 2018
Don't wanna be here? Send us removal request.
@r3nzsec
Renzon
10 months
I recently co-authored a @Unit42_Intel blog about a unique IR case in which a threat actor’s custom EDR bypass (using #BYOVD) exposed their toolkit, methods, and even identity. Check out how we unmasked them through an opsec slip-up! #dfir .
Tweet card summary image
unit42.paloaltonetworks.com
A threat actor attempted to use an AV/EDR bypass tool in an extortion attempt. Instead, the tool provided Unit 42 insight into the threat actor.
6
64
222
@r3nzsec
Renzon
3 hours
RT @XintraOrg: Sharing some more feedback from this week!
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
1
0
@grok
Grok
2 days
Join millions who have switched to Grok.
46
73
610
@r3nzsec
Renzon
7 days
Ah, so that's how you do it @zachxbt!! 🤣
Tweet media one
0
0
1
@r3nzsec
Renzon
8 days
RT @EncapsulateJ: There's pretty much never been a better time to start learning or get hands on blue team experience through labs. The ava….
0
4
0
@r3nzsec
Renzon
9 days
🧐.
@watchtowrcyber
watchTowr
9 days
We're back - returning to the scene of the "crime" - to demonstrate 2 pre-auth RCE chains against Commvault (CVE-2025-57788, CVE-2025-57789, CVE-2025-57790, CVE-2025-57791) . Enjoy, and speak soon 😉.
0
0
5
@r3nzsec
Renzon
9 days
RT @orange_8361: Turns out my #PHRACK article is live! 🔥. > The Art of PHP — My CTF Journey and Untold Stories!. Kinda a love letter to tho….
0
208
0
@r3nzsec
Renzon
10 days
Super fun working on this lab with the @XintraOrg gang!! Enjoy and let us know your feedback! . #ScatteredSpider #MuddledLibra #UNC3944.
@inversecos
inversecos
10 days
NEW LAB: Scattered Spider (UNC3944) 🕷️🕸️. Scattered Spider hits indie studio AB Projekt Blue, deploying ransomware and stealing unreleased game code. Test your skills on:. 👀 Social Engineering & MFA Fatigue.👀 Credential Theft via OST Files.👀 Bring Your Own Vulnerable Driver
Tweet media one
Tweet media two
2
4
41
@r3nzsec
Renzon
11 days
RT @Seifreed: 🎉 Excited to release #r2inspect - my malware analysis framework using @radareorg . 🔍 Analyze PE files with 28+ modules. 🛡️ De….
Tweet card summary image
github.com
Advanced Malware Analysis Tool using Radare2 and r2pipe - seifreed/r2inspect
0
72
0
@r3nzsec
Renzon
16 days
RT @zachxbt: 1/ An unnamed source recently compromised a DPRK IT worker device which provided insights into how a small team of five ITWs o….
0
892
0
@r3nzsec
Renzon
22 days
RT @virusbtn: Palo Alto Networks has observed multiple incidents targeting the telecommunications industry in Southwest Asia. CL-STA-0969 a….
0
12
0
@r3nzsec
Renzon
24 days
SEO > #Bumblebee > AdaptixC2 > Akira RW.
@TheDFIRReport
The DFIR Report
24 days
🚨 Search for software, end up getting ransomware!. SEO-driven #Bumblebee malware campaigns observed throughout July led to domain compromise, data theft & #Akira ransomware. Tools included #AdaptixC2 & #Netscan.
0
0
7
@r3nzsec
Renzon
25 days
RT @Unit42_Intel: A telecom-focused group active most of last year employed custom tools and DNS tunneling for stealth and also routed traf….
0
22
0
@r3nzsec
Renzon
29 days
Fun times! 6hrs of CTF against some of the best DFIR professionals in North America. Thanks for this incredible event @sansforensics @SANSInstitute . #dfir
Tweet media one
Tweet media two
4
5
101
@r3nzsec
Renzon
1 month
Anyone going to SANS #dfirsummit in Salt Lake, Utah this week? See you all!! 🫶🏻
Tweet media one
6
0
44
@r3nzsec
Renzon
1 month
Riyadh 🫶🏻
Tweet media one
5
0
25
@r3nzsec
Renzon
2 months
RT @mathias_fuchs: Attackers love RDP for sneaky lateral moves—but every pixel leaves a clue! 🕵️‍♂️ Check out my latest blog on tracking at….
Tweet card summary image
medium.com
Introduction
0
87
0
@r3nzsec
Renzon
2 months
Fantastic project that can be used to visualize your SOD!! Great stuff @Arimb00R! 🔥.
@Arimb00R
Jinto Antony
2 months
🚀 **Kanvas** - my new open-source project !!. If you're in IR, Forensics, or part of a SOC dealing with security incidents/ breaches, , Give it a spin and let me know what you think 🤞. Quick writeup 📌 Github Repo 📌
1
1
13
@r3nzsec
Renzon
2 months
RT @inversecos: Become a contributor at XINTRA @XintraOrg 🔎. We're looking for RED and BLUE team contributors . 🔴Red Team – Emulate real AP….
0
20
0
@r3nzsec
Renzon
2 months
Classic #ransomhub execution baked into the encryptor itself. Check out the latest report here and learn how that exposed RDP on your network can trigger a massive ransomware attack. #dfir . @TheDFIRReport
Tweet media one
0
10
56
@r3nzsec
Renzon
3 months
RT @LambdaMamba: BSides Pyongyang when??? @dprkcert
Tweet media one
0
34
0