Sharvil Shah Profile
Sharvil Shah

@sharvil

Followers
528
Following
3K
Media
18
Statuses
939

Security Stuff — #osquery Technical Steering Committee member, likes macOS internals | email: [email protected]

Seattle
Joined March 2008
Don't wanna be here? Send us removal request.
@gutterchurl
Erika Noerenberg [email protected]
22 days
Starting to think I should have made #OBTS bingo cards - I don’t think I’ve ever heard a speaker use the phrase “bee’s knees” before 😹 @sharvil dropping some jokes along with FSKit knowledge ❤️
0
3
14
@forensicdave
Doc Dave
22 days
Sharvil (@sharvil) showed #OBTS how Apple’s new FSKit lets you build filesystems in userspace - you can build a pseudo-FS, use it as a honeypot for infostealers and even a hiding spot for malware. DM him if you need help using this as a Canary/tripwire in your environment!
0
4
14
@sharvil
Sharvil Shah
5 months
I’m gonna be @MacDevOpsYVR, come say hello!
0
0
3
@PeteMarkowsky
Pete Markowsky
6 months
Really happy to see this as @sharvil's @osquery work gets called out, along with Santa's FAA.
@northpolesec
North Pole Security
6 months
Very exciting to see Santa called out as a tool that works in the @SpecterOps SO-Con talk on Modern macOS Red Teaming Tactics by Lance Cain and @werdhaihai https://t.co/jgfhc8XGM3
1
1
5
@lorenzofb
Lorenzo Franceschi-Bicchierai
1 year
NEW: We have launched a glossary where we have a series of cybersecurity terms and their definitions. This page will be periodically updated to add more terms, as it's meant to be a live resource for all our readers. Please let us know what to add! https://t.co/IGdruBJvs3
Tweet card summary image
techcrunch.com
This glossary includes the most common terms and expressions TechCrunch uses in our security reporting, and explanations of how — and why — we use them.
2
28
71
@PeteMarkowsky
Pete Markowsky
1 year
This talk by @slashnick0 on stopping CookieTheft on macOS (using Santa and OSQuery) https://t.co/uVW6FcqkSp was solid.
0
2
12
@sharvil
Sharvil Shah
1 year
This WWDC is one big Sherlock-ed event
1
0
2
@sharvil
Sharvil Shah
2 years
I am in Berlin for #offensivecon — come say hello!
0
0
6
@sharvil
Sharvil Shah
2 years
I also do professional services, custom osquery development and macOS agent, EndpointSecurity, systems programming! Hit me up if you would like something implemented!
@Centurion
Chris Long
2 years
Huge shout out to @sharvil who wrote the code and is an absolute pleasure to work with in every way.
0
3
19
@sharvil
Sharvil Shah
2 years
Had so much fun working on this with @Centurion and @material_sec! EndpointSecurity based File Integrity Monitoring in #osquery, particularly for file open events is a game changer for detections on macOS
@Centurion
Chris Long
2 years
I've always thought that having the ability to set tripwires on arbitrary files on an endpoint would be a huge defensive advantage. Today, that is now a reality for all users of osquery in macOS:
1
2
14
@sharvil
Sharvil Shah
2 years
After this talk by @_r3ggi at #OBTS I am afraid to run any Electron apps on my Mac! Excellent overview
1
3
13
@sharvil
Sharvil Shah
2 years
Super stoked about this talk at #OBTS! @PeteMarkowsky and @byaaaaahhh sharing ins and outs of the Santa agent on macOS, very cool!
1
3
13
@sharvil
Sharvil Shah
2 years
Excellent new tool release — Kronos, to augment TCC data on macOS by @rookuu_ and @_calumhall at #OBTS
0
0
7
@sharvil
Sharvil Shah
2 years
Excellent talk (and epic graphics) on reversing RustBucket on macOS by @jbradley89 and @malwarezoo at #OBTS
1
3
14
@herhaxpodcast
herhaxpodcast
2 years
We have some exciting news! Join @patrickwardle @andyrozen and our host @x71n3 to talk about Objective-We on October 10th at 6:30PM CET! Check us out on https://t.co/DESiKWTYoc live or for the replay!
0
6
6
@sharvil
Sharvil Shah
2 years
I am in Marbella for #OBTSv6. Time to soak in the sun, the new macOS and iOS security/research firehose, and meet new && old friends, come say hello. #OBTS
3
2
30
@sharvil
Sharvil Shah
2 years
Nice to see @osquery getting a lot of love from @marczak at @macsysadmin conference. Sometimes working on open source can feel tireless but talks like this make it all worth it!
0
0
12
@sharvil
Sharvil Shah
2 years
Come say hello, I am attending @macsysadmin live for the first time!
0
0
4
@sharvil
Sharvil Shah
2 years
Thank you @MidnightSunCTF! I had such a great time, it was so nice to meet old and new friends, play a few challenges and talk about macOS security tooling.
@MidnightSunCTF
Midnight Sun
2 years
💪 Security is about building as well as breaking! 🍎The next speaker, @sharvil will teach us about building next-gen security tools, with a focus on macOS at #MidnightSun23 ➡️ https://t.co/X9QiEsBWKF
1
2
17
@patrickwardle
Patrick Wardle
2 years
Aloha friends. Yesterday, catastrophic fires destroyed much of Maui💔 Maui, my home, is also the birthplace of the @objective_see foundation & #OBTS conf. We're launching a fundraiser to help those who lost everything: https://t.co/HgtucWrGjn Any support much appreciated 🙏🏽
Tweet card summary image
gofundme.com
Aloha Friends, Recently our home island of Maui was devasted by catastrophic wildfires. T… Patrick Wardle needs your support for Maui Wildfire Relief Fund
7
136
220