Daniel Stinson
banner
shellcromancer.io
Daniel Stinson
@shellcromancer.io
Building something new! Used to be a security engineer @ Brex & Cloudflare. Hobbyist reverse engineer of 🍎 and 🐧 things… dogs are better than humans.
Talk about helping to build a better Internet -> har-sanitizer.pages.dev

Thanks @cloudflare.social 🔥
HAR Sanitizer
har-sanitizer.pages.dev
October 25, 2023 at 9:35 PM
Customer: Are we safe?
Okta: Give me a HAR and we’ll let you know when we find out from other customers.

Helpful context: www.beyondtrust.com/blog/entry/o...

Much less helpful context response: sec.okta.com/harfiles
BeyondTrust Discovers Breach of Okta Support Unit | BeyondTrust
This blog shared details of the Okta support unit attack to educate other Okta users and infosec professionals. For BeyondTrust customers who leverage our Identity Security Insights product, we have a...
www.beyondtrust.com
October 20, 2023 at 9:14 PM
Reposted by Daniel Stinson
I really believe that if your infrastructure can’t survive a user clicking a link, you are doomed. I’m the director of cybersecurity at NSA and you can definitely craft an email link I will click…

r.mtdv.me/TrustThis
October 17, 2023 at 4:12 PM
My team is hiring for a new member of our D&R team based in 🇨🇦 www.brex.com/careers/6952...

I'm very biased but I think we're a great team in the D&R space across a production & corporate environment. Big fans of open sourcing projects, managing components via source control where possible
Security Engineer, Detection & Response | Career Opportunities
Want to work at Brex? Explore all of our current remote job openings right here. Apply today & join our team!
www.brex.com
October 2, 2023 at 6:01 PM
Some new 🔥 reporting on everyones least favorite threat actor by Permiso: 0ktapus, Scattered Spider, UNC3944, and STORM-0875 and now LUCR-3 👀
permiso.io/blog/lucr-3-...
September 20, 2023 at 4:42 PM
All these security vendors are trying to define XDR (eXtended Detection & Response) but Apple has been using XDR screens for years and improving it in iPhone 15 🧠
September 12, 2023 at 5:43 PM
Friday afternoons are a great time for releasing and deploying new software! 🔥🚀

Substation v0.9.2 is here: github.com/brexhq/substation/d…

In addition to a new bitmath inspector I wrote, this release brings some QoL improvements, let us know if you find use-cases for these additions. XDR onwards!
GitHub
GitHub is where people build software. More than 100 million people use GitHub to discover, fork, and contribute to over 330 million projects.
http://github.com/brexhq/substation/d…
August 11, 2023 at 9:15 PM
🔥 an at cost registrar, with WebAuthN support adding more domains to help migrate off of Google/Squarespace 👏
Shhh… 🤫 @Cloudflare Registrar just quietly rolled out support for the following TLDs:

.app
.boo
.channel
.dad
.day
.dev
.esq
.foo
.how
.mov
.new
.nexus
.page
.phd
.prof
.rsvp
.soy
August 1, 2023 at 11:13 PM
One of my biggest pet peeves within infosec is how people still refer to "knowing your network". In the era of cloud networks that really aren't yours, SaaS networks that definitely aren't yours... let's rebrand to "knowing your environment" which consists of: endpoints, SaaS, servers, and cloud.
July 29, 2023 at 3:01 AM
More macOS stealers 👀

A simple detection for command lines w/ “security find-generic-password ” catches most 😂

https://iamdeadlyz.gitbook.io/malware-research/july-2023/fake-blockchain-games-deliver-redline-stealer-and-realst-stealer-a-new-macos-infostealer-malware#realst-stealer-macos
Fake Blockchain Games Deliver RedLine Stealer & Realst Stealer - A New macOS Infostealer Malware
iamdeadlyz.gitbook.io
July 25, 2023 at 10:26 PM
Latest hacking from the DPRK with macOS payload details 👀 Great reporting from the Mandiant team!

https://www.mandiant.com/resources/blog/north-korea-supply-chain
North Korea Leverages SaaS Provider in a Targeted Supply Chain Attack
We responded to a supply chain compromise by a likely DPRK-nexus threat actor, who we believe leveraged JumpCloud.
www.mandiant.com
July 24, 2023 at 1:04 PM
Besides using it regularly to load and interrogate data - the Vertex blog is a great way to learn Storm recently 🔥
Vertex Project intel analyst "savage" has published a new blog on integrating Mitre ATT&CK data into your #synapse workflow! 😁 She includes some cool examples of using raw text search as well as #storm queries to ask useful questions 💚

https://vertex.link/blogs/mitre-attack/
July 12, 2023 at 2:22 PM
🔥 lineup coming for the Objective-by-the-Sea v6 conference all on macOS & iOS security: https://objectivebythesea.org/v6/talks.html

- 2 talks on DPRK malware analysis
- 1 talk from Kaspersky on Triangulation (🦅)
- ... and more on bug hunting across the OS and user applications!
#OBTS v6.0: Talks
Conference Talks
objectivebythesea.org
July 11, 2023 at 3:17 PM
2nd ever Apple Rapid Security Response update out for a WebKit bug (CVE-2023-37450):

iOS: https://support.apple.com/en-us/HT213823
macOS: https://support.apple.com/en-us/HT213825
July 10, 2023 at 7:50 PM
I’m not hoping to start an big anti-OST flame war but it’s sad that the place that hosts a whole podcast drops offensive Atlassian tooling without a section on detection :(

https://posts.specterops.io/sowing-chaos-and-reaping-rewards-in-confluence-and-jira-7a90ba33bf62
Sowing Chaos and Reaping Rewards in Confluence and Jira
Introducing AtlasReaper
posts.specterops.io
July 2, 2023 at 3:06 PM
Woo, my addition to the LOOBins project got released today! https://github.com/infosecB/LOOBins/releases/tag/v1.1.0

I added the mdls command used by common adware like Genio
Release LOOBins v1.1.0 · infosecB/LOOBins
What's Changed Additions launchctl by @caffeinatedJAC in #132 mdls by @shellcromancer in #134 log by @infosecB in #135 scutil by @ethan-nay in #136 mktemp by @bobby-tablez in #137 Updates Update...
github.com
June 29, 2023 at 2:28 AM
Seems like the answer to this was to some extent: yes, 0-day was used.

New *OS releases (see https://support.apple.com/en-us/HT213814) from today include a mention of the Kaspersky team for CVE-2023-32434 so it seems like there was some level of 0-day with the Triangulation attack
June 21, 2023 at 5:32 PM
Just a moment...
www.bitdefender.com
June 19, 2023 at 6:17 PM
Iconic way for @killedbygoogle.com to enter this new platform.
Google pushing out .zip as a TLD and then divesting their registrar business is the equivalent on pooping in the punch bowl as you leave a party

https://9to5google.com/2023/06/15/google-domains-squarespace/
June 15, 2023 at 10:19 PM
Today also brings us more attackers hacking where security software like EDR doesn't run 🤦‍♂️ https://www.mandiant.com/resources/blog/vmware-esxi-zero-day-bypass

Refuse to buy appliances where you can't maintain the security your customers deserver (ESXi, Fortinet, routers, etc)
VMware ESXi Zero-Day Used by Chinese Espionage Actor to Bypass Authentication Checks and Perform Pri...
Additional techniques UNC3886 utilized across multiple organizations to evade EDR solutions.
www.mandiant.com
June 13, 2023 at 3:17 PM
This week in why trendy ccTLDs (like .ai) are bad 🤣
Imagine your VC-backed startup has a .ai domain...

https://hackcompute.com/hacking-epp-servers/
can I speak to your manager? hacking root EPP servers to take control of zones
Finding vulnerabilities in global domain infrastructure to take control of ccTLD zones. Vulnerabilities in EPP
hackcompute.com
June 13, 2023 at 3:12 PM
Great blog(s) here from https://infosec.exchange/@ozurie on the Emerging Threats detection team regarding finding network exploitation and tagging rules 👀

ozuriexv.github.io/rule-metada…

I highly recommend adding this site to your RSS feed to catch all new posts as they come 👏
404 - Page not found
Detection Engineering Ramblings
https://ozuriexv.github.io/rule-metada…
June 12, 2023 at 3:37 PM
@apenwarr.bsky.social is here but they haven’t posted their 🔥 article on tech debt which dives into analogies for:
- tech-debt interest rates
- tech-debt to equity/income
- tech debt risk and leverage
- tech debt refinancing/bankruptcy

https://apenwarr.ca/log/20230605
Tech debt metaphor maximalism
I really like the "tech debt" metaphor. A lot of people don't, but I think that's because they either don't extend the metaphor far enough,...
apenwarr.ca
June 11, 2023 at 9:41 PM