GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by da_667 (da_667@infosec.exchange)

  1. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 17-Oct-2025 20:39:30 JST da_667 da_667

    dawn of a new day, bright and full of possibility

    slams the shades shut

    In conversation about 6 hours ago from infosec.exchange permalink
  2. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 17-Oct-2025 17:37:33 JST da_667 da_667

    :eyes_squint:

    In conversation about 9 hours ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/386/999/440/832/406/original/c70f3bc336d76990.jpg
  3. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Sunday, 12-Oct-2025 12:51:51 JST da_667 da_667
    in reply to
    • Tinker ☀️
    • Cookiefiend
    • Fritz Adalis
    • bsidesnova

    @FritzAdalis @tinker @LPerry2 @bsidesnova I can confirm 11 IoT edition removes most of the odious shit you have to deal with on a W11 install

    • no bing search on the start menu
    • notifications are muted
    • from my experience, local accounts are still allowed
    • No windows store
    • No windows store apps
    • No stupid ass app recommendations
    • One drive nag on the taskbar is gone
    • Onenote spam is gone
    In conversation about 6 days ago from infosec.exchange permalink
  4. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 11-Oct-2025 04:46:20 JST da_667 da_667
    in reply to

    This is the third time I've gotten a phishing exercise e-mail, in which this has happened, and its hilarious every single time because I get to map your company's entirely list of phishing domains.

    In conversation about 7 days ago from infosec.exchange permalink
  5. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 11-Oct-2025 04:46:19 JST da_667 da_667
    in reply to

    DA, you loveable scamp, how is this done?

    grab the e-mail address/domain from the suspected phishing e-mail, input it into virustotal. Click on details for the domain, and pay attention to the "Last HTTPS Certificate" section. See if the Subject Alternate Name section looks like war and peace.

    Done deal.

    Phishing exercise orgs are the only ones who do this, because bad guys just use lets encrypt.

    In conversation about 7 days ago from infosec.exchange permalink
  6. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 11-Oct-2025 04:45:19 JST da_667 da_667

    How to tell a phishing exercise domain is a phishing exercise domain: The SSL certificate specifies a Subject Alternative Names list that is a fucking novel.

    In conversation about 7 days ago from infosec.exchange permalink
  7. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 10-Oct-2025 16:11:28 JST da_667 da_667

    Remember certification camps?

    It's that, except its 2025, and you're trying to get in on the bubble Before it bursts, but you're threading the needle, because you're an inflation fetishist.

    In conversation about 7 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/348/039/348/482/317/original/f9a7fd9b72d9c290.png
  8. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 07-Oct-2025 08:49:28 JST da_667 da_667

    doing a windows 11 IoT Edition install. It's hilarious how much better this experience is over the standard Enterprise edition, and I've barely done anything on it so far.

    In conversation about 11 days ago from infosec.exchange permalink
  9. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 07-Oct-2025 08:49:27 JST da_667 da_667
    in reply to

    Installed 24H2

    • The start menu isn't trying to call out to bing when I search for shit on the desktop. That's right! THERE IS NO DEFAULT SEARCHING FOR SHIT ON THE INTERNET IN THE START MENU
    • There is no embedded weatherbar/weather app in the taskbar
    • Pictured is the complete list of installed apps currently:

    Holy shit this really is a de-shittified W11 install.

    In conversation about 11 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/329/182/520/582/532/original/d3d1ae6f2979c86b.png
  10. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 07-Oct-2025 08:49:27 JST da_667 da_667
    in reply to

    I don't have either enabled for the proxmox VM I've set up. The only hard requirement I've seen so far is that your box has to have at least two cores.

    In conversation about 11 days ago from infosec.exchange permalink
  11. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 07-Oct-2025 08:49:27 JST da_667 da_667
    in reply to

    oh yeah, forgot to mention that IoT Edition doesn't require TPM2.0 or EFI for that matter. Hilarious

    In conversation about 11 days ago from infosec.exchange permalink
  12. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 07-Oct-2025 08:49:27 JST da_667 da_667
    in reply to
    • I was able to configure a local user when the network drivers (virtio) weren't found
    • No nagware tray icon for OneDrive
    • Notifications are muted by default
    • No microsoft store

    Gonna apply 24h2, and see what that does.

    In conversation about 11 days ago from infosec.exchange permalink
  13. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 07-Oct-2025 08:49:26 JST da_667 da_667
    in reply to

    search and connected experiences still needs to be thoroughly disabled

    search suggestions needs disabling.

    appearance > co-pilot and sidebar needs to be disabled.

    privacy search and security > use secure DNS (DoH) still needs to be disabled.

    In conversation about 11 days ago from infosec.exchange permalink
  14. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 07-Oct-2025 08:49:26 JST da_667 da_667
    in reply to
    • system will idle the screen after a few minutes, but doesn't lock the screen.

    Oh, I like that.

    In conversation about 11 days ago from infosec.exchange permalink
  15. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 07-Oct-2025 08:49:26 JST da_667 da_667
    in reply to

    I'm considering moving my physical malware windows 11 host to Iot Edition now. Holy shit this is insanely better so far.

    In conversation about 11 days ago from infosec.exchange permalink
  16. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 07-Oct-2025 08:49:25 JST da_667 da_667
    in reply to

    install ublock origin lite
    dark reader
    sponsorblock
    and startpage... and there you go. It's almost a usable browser.

    In conversation about 11 days ago from infosec.exchange permalink
  17. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 26-Sep-2025 01:11:10 JST da_667 da_667

    RE: https://infosec.exchange/@sans_isc/115265397054651431

    This is a really nice write-up on the .well-known directory being abused to drop webshells. This would make for a good hunting rule for Suricata/Snort, so I'll be working on that today.

    In conversation about 22 days ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.infosec.exchange
      SANS Internet Storm Center - SANS.edu - Go Sentinels! (@sans_isc@infosec.exchange)
      from SANS Internet Storm Center - SANS.edu - Go Sentinels!
      Attached: 1 image Webshells Hiding in .well-known Places https://isc.sans.edu/diary/32320
  18. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 20-Sep-2025 12:37:13 JST da_667 da_667
    • GAYINT

    @gayint inquiring minds gotta know: is it an ass shooting out a rainbow, or pair of balls and a rainbow autoloader?

    In conversation about a month ago from infosec.exchange permalink
  19. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 19-Sep-2025 12:05:22 JST da_667 da_667

    Hey, thought I'd let you all know that an opportunity for a staff security researcher has opened up in the proofpoint threat research team.

    The work is remote, the pay scale is included in the job listing, etc. Benefits are really good. It's not the exact division that I work in (emerging threats) but we're in divisions that work together.

    https://proofpoint.wd5.myworkdayjobs.com/en-US/ProofpointCareers/job/Staff-Security-Research-Engineer_R12883-1

    In conversation about a month ago from infosec.exchange permalink
  20. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 16-Sep-2025 23:36:23 JST da_667 da_667
    in reply to
    • sp00ky cR0w 🏴

    @cR0w it certainly is.

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/214/460/740/185/981/original/d0f808d6259d4c88.png
  • Before

User actions

    da_667

    da_667

    Senior Security Researcher, Proofpoint Emerging Threats.I've been doing this cybersecurity thing for the better part of a decade now. Probably longer than that. I'm starting to forget. Time is relative, but it surely isn't kind to my memory.I'd like to think I do cybersecurity well, but blue teamers collectively get told they're doing it wrong constantly. So maybe I just failed forward throughout my career.Oh, I wrote a book. Its a good framework for setting up a virtual machine lab. See my bookmarked toots if you're curious.Finally, I occasionally write about tech/nerd-related things over at https://www.totes-legit-notmalware.site where I expose that I have a short fuse, and no filter.Work-Related hashtags:#Iocs #ThreatIntel #DFIR #Malware #NSM #suricata #snort #BEC #phishing #APT #ThreatDetectionHobbies:#VideoGames #XCOM2 #Minecraft #Synthetik #Fallout #Skyrim #Anime #Manga #Adventure #Fantasy #Isekai #HomeImprovement #WoodWorking #MetalWorking #HomeLab

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          30576
          Member since
          18 Nov 2022
          Notices
          226
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.