![Andrew Profile](https://pbs.twimg.com/profile_images/1577790557115617283/9mdM1vTH_x96.jpg)
Andrew
@4ndr3w6S
Followers
2K
Following
8K
Statuses
999
Senior Manager of Detection Engineering @HuntressLabs | Prev. Practice Lead, TAC (Purple Team) @TrustedSec | @SpursOfficial Super Fan - COYS!
Joined April 2017
Incredibly excited to share my first blog with @HuntressLabs ๐ I explore detecting Kerberoasting attacks using Perfmon as a data sourceโhighlighting the rich metadata in Perfmon counters and their potential for enhancing detections. ๐ Check it out:
3
31
146
This is a prime example of reading/learning code + learning internals (with rinse and repeat) ๐ฆพ Fantastic read and writeup! ๐ฅ
Join @olafhartong in his journey down the rabbit hole in search of new detection opportunities in the #Zeek telemetry embedded in Microsoft's EDR #MDE! Detection engineering is sometimes hard โฆ ๐ #detectionengineering #kql #blueteam
1
1
11
Amazing work by my awesome colleagues @HuntressLabs ๐ฅ Check it out below, for the details on Cleo (CVE-2024-50623) ๐
0
0
6
@N7WEra @odiesec @Octoberfest73 @exploitph and I identified many of the flag differences 2 years ago, and baked them into our tool:
1
0
2
LOL sorry @gentilkiwi ๐๐
๐ Exciting update for Haunt: it can now execute C# assemblies directly from memory! ๐ก๏ธ Enhancing covert operations and expanding capabilities. Huge thanks to my incredible Patreons for making this possible!
2
1
7
@techspence Burning tradecraft to phish your way in, only to realize you actually are in a pure Mac environment and there is no Active Directory ๐
1
0
5