woanware Profile
woanware

@woanware

Followers
780
Following
444
Media
13
Statuses
532

Principal Security Researcher @ Microsoft (MSTIC). Software development, detections, security and DFIR. Thought/opinions are mine, not those of my employer.

UK
Joined July 2010
Don't wanna be here? Send us removal request.
@woanware
woanware
1 year
Lots of MSFT jobs going at the moment:. 🕵️.👻.🎯.
1
0
2
@woanware
woanware
1 year
RT @ElroyMcThomas: MSTIC is hiring Threat Intel Analysts in the UK:
0
2
0
@woanware
woanware
1 year
RT @MalwareRE: MSTIC is looking for Senior Security Researchers (Malware Reverse Engineers) in the US and Australia to join our MSTIC-RE te….
0
41
0
@woanware
woanware
3 years
Not that I post too often but available at "the other place": @woany@infosec.exchange.
0
0
1
@woanware
woanware
3 years
Yet another VirusTotal lookup tool. This one is super basic, just does SHA256 file hash report lookups currently, dumps basic data to CSV. Mainly aimed at those with Enterprise API access e.g. large batch sizes. With a batch size of 100, it does 10000 hashes in about a minute.
1
1
4
@woanware
woanware
3 years
RT @ItsReallyNick: 👋 Microsoft security teams are hiring. Several #MSTIC roles:.•(APT technical analysis required)….
0
58
0
@woanware
woanware
3 years
New version for etw-event-dumper (v1.0.1), fixes a BOM issue on the output file. Thanks @williballenthin for reporting!.
Tweet card summary image
github.com
Fixed BOM issue on output file. Thanks @williballenthin!
0
0
2
@woanware
woanware
3 years
New tool (ewt-event-dumper) using code from the Mandiant SilkETW project, it's designed for bulk hooking/collection of ETW events for large numbers of ETW providers e.g. I want to collect over 150 providers, using a simple configuration:.
1
38
113
@woanware
woanware
4 years
Updated RiskIqSharp lib, published as v1.0.0, with more API's implemented:.
Tweet card summary image
github.com
C# library (.Net 6) to interact with the RiskIQ/PassiveTotal API - woanware/RiskIqSharp
0
0
0
@woanware
woanware
4 years
0
0
0
@woanware
woanware
4 years
Started working on a library (.Net 6) to interact with the RiskIQ/PassiveTotal API:.
Tweet card summary image
github.com
C# library (.Net 6) to interact with the RiskIQ/PassiveTotal API - woanware/RiskIqSharp
1
0
0
@woanware
woanware
4 years
Has anyone dumped PRT's via mimikatz recently? e.g. using "Sekurlsa::cloudap" function. Tried replicating on both Win10 & Win11, all machines AAD joined, dsregcmd showing AzureADPrt: Yes.
2
0
2
@woanware
woanware
4 years
RT @MalwareRE: Today we are releasing an in-depth analysis of a #NOBELIUM post-exploitation backdoor that Microsoft Threat Intelligence Cen….
0
137
0
@woanware
woanware
4 years
RT @ItsReallyNick: We’re hiring for our cyber crime / counter-ransomware intelligence mission. Senior analyst position, some details flexib….
0
103
0
@woanware
woanware
4 years
Verifying myself: I am woany on j4guAPg049D-JylYh7zCKg5jOc5AbffYY9NJ /
0
0
1
@woanware
woanware
4 years
RT @TimbMsft: Sysmon goodness coming to #Linux!.
0
2
0
@woanware
woanware
4 years
New security analyst/investigator on my team (Identity).
1
3
1