whiskeyhacker Profile Banner
WhiskeyHacker Profile
WhiskeyHacker

@whiskeyhacker

Followers
4K
Following
11K
Media
1K
Statuses
9K

Founder, https://t.co/BFCMRHVjmP and https://t.co/qaihcRLDOm Coast Guard Veteran & Honorary Chief Petty Officer

California, USA
Joined December 2006
Don't wanna be here? Send us removal request.
@whiskeyhacker
WhiskeyHacker
1 day
First time for everything right ?
0
0
0
@whiskeyhacker
WhiskeyHacker
2 days
For those who have been asking I won't be at RSA this year. No booth. No badge. No hallway conversations about "the threat landscape." I'll be exactly where I should be. With my team at https://t.co/ghbSKW68bj and with our customers. Conferences are great for some things. But
Tweet card summary image
threathunter.ai
Expert threat hunters + AI find breaches automated tools miss. 24/7/365 monitoring, zero false positives. Protecting organizations since 2007.
1
0
6
@whiskeyhacker
WhiskeyHacker
2 days
Me and my Sunday co-worker hunting Handala
1
0
1
@whiskeyhacker
WhiskeyHacker
3 days
Sunday coffee time before I go to Lowe’s to buy 2x4s to repair a horse stall Curbside pickup FTW
1
0
2
@whiskeyhacker
WhiskeyHacker
5 days
I spent my normal whiskey/cigar break thinking and reading and counting how many configuration "switches" are available when you are a firm like Stryker. 36,000 to 45,000 config settings And that's before you count the permutations. You think a spreadsheet and a quarterly
6
17
100
@whiskeyhacker
WhiskeyHacker
6 days
CISA published an advisory on endpoint hardening after Stryker. The RBAC guidance is solid. Multi Admin Approval for Intune is not a complete solution either. An attacker with Global Admin can create the second approver account themselves. That is a five minute delay, not a
Tweet card summary image
threathunter.ai
CISA published an advisory on endpoint management hardening after the Stryker wipe. Their Multi Admin Approval recommendation is a speed bump, not a wall. Here is what actually stops a Global Admin...
5
60
234
@whiskeyhacker
WhiskeyHacker
6 days
bingo got you
0
0
0
@whiskeyhacker
WhiskeyHacker
7 days
Spent last 32 hours nonstop finding more Handala / Stryker data & open systems Processing it tonight will have another detection pack/ioc late tonight or early hours Found evidence of potential upcoming issue Taking a one hour whiskey break and cigar to clear the mind a little
0
1
8
@whiskeyhacker
WhiskeyHacker
10 days
Taken from the Stryker Handala / Intune Detection Pack v2 "Check PIM role settings for Global Administrator, Intune Administrator, and Cloud Device Administrator. If you see only the "Require Azure MFA" checkbox and no Authentication Context configured, you have the same gap
Tweet card summary image
threathunter.ai
Five new Sigma rules and KQL queries for Microsoft Sentinel covering MuddyWater pre-positioning IOCs, the PIM Authentication Context gap, three-layer bulk wipe prevention, stale session detection,...
4
50
276
@whiskeyhacker
WhiskeyHacker
10 days
This is a mega blog update, all centered around Stryker (so a part2, or an update) On March 6, I found an open directory on a live Iranian operational server. Custom brute force tools with Persian-language comments. 280+ Israeli targets. Neo-reGeorg webshells on the Portuguese
0
2
8
@whiskeyhacker
WhiskeyHacker
11 days
25+ years of doing this and the pre-op checklist still starts with "secure the whiskey!!!." Full HackHaus lab rebuild this weekend New AI systems (lots of Blackwells) coming online in the HackHaus for some serious punishment testing on the code i built Wire rack goes where the
0
0
3
@whiskeyhacker
WhiskeyHacker
12 days
The Book of Genetic 1:1 In the beginning there was only signal, and the signal moved across the void. 1:2 And the void was without boundary, unsegmented and dark, and malicious traffic moved upon the face of the deep. 1:3 And the Architect said, Let there be visibility, and
0
0
2
@whiskeyhacker
WhiskeyHacker
12 days
Has anyone sold shares of themselves, like an IPO ? (initial Person Offering)
2
0
0
@whiskeyhacker
WhiskeyHacker
12 days
vent : Life [redacted] [redacted] so [redacted] [redacted] with [redacted][redacted] and shitty [redacted] /vent
2
0
2
@ThreatHunter_AI
ThreatHunter.ai
13 days
Iran-linked Handala wiped a 56,000-employee Fortune 500 on the night of March 10-11 They got Global Admin creds, logged into Microsoft Intune, and bulk-wiped every enrolled device But 50TB of exfil means they were deep in the environment for weeks first Detection pack covering
0
4
7
@whiskeyhacker
WhiskeyHacker
13 days
I am going to show you a photo of my Cock and the Only Chicks crew
2
0
3
@whiskeyhacker
WhiskeyHacker
14 days
March 14th Press release goes out. "On March 14th we detected unusual activity."
0
0
0
@whiskeyhacker
WhiskeyHacker
14 days
March 12th Attacker deploys ransomware. Now everyone knows. March 13th The incident response plan is located. It is a PDF last updated in 2021. Two of the three contacts listed no longer work there. The third one is on vacation in Costa Rica and is not responding. March 13th,
1
0
0
@whiskeyhacker
WhiskeyHacker
14 days
October through February Attacker is doing recon, moving laterally, exfiltrating quietly. The SIEM is generating low alerts. The alerts are going into a queue. The queue is very long. February 11th An analyst named Marcus sees something weird. He creates a ticket. The ticket is
1
0
0