Lemon Profile
Lemon

@Lemonitup

Followers
897
Following
395
Statuses
298

Principal Security Engineer @ Red Threat https://t.co/qGxQnY0KNq

Oklahoma, USA
Joined November 2014
Don't wanna be here? Send us removal request.
@Lemonitup
Lemon
8 days
@LucasBotkin 4:20 fuel up with some green before hitting the Jiu Jitsu gym.
Tweet media one
0
0
2
@Lemonitup
Lemon
2 months
@HackingLZ With enough head gasket shims this might work but the lower compression negates any advantage gained from the longer stroke.
0
0
1
@Lemonitup
Lemon
2 months
@chrissanders88 Hope they configured global audit policy more than 3 years ago. Hope you have any logging. Check last login date or if ever logged on. Try the password testuser for lulz
0
0
5
@Lemonitup
Lemon
2 months
@TMDFIR Absolutely! I deploy security onion on every ransomware engagement. EDR only works if you deploy it on EVERY host. NDR along with JA3 signatures are essential for identifying persistence from cobalt strike or RMM tools on host you missed deploying edr on.
1
2
10
@Lemonitup
Lemon
2 months
@techspence Export the folder as a pst. Convert to eml then run it through bitrecover to output as jpg
1
1
13
@Lemonitup
Lemon
3 months
@deadvolvo Scroll through the @ExploitDB feed, it's nothing but exploit code from abandoned college coding projects hosted on RCE in poultry farm or Church management software etc.
0
0
1
@Lemonitup
Lemon
3 months
@jeremiahg I’m surprised any insurance carriers could provide any attribution given the majority of “incident response” companies they engage with just deploy s1 or CS and don’t actually know how to do root cause analysis or forensics.
1
0
7
@Lemonitup
Lemon
3 months
@rd_pentest This is some slick tradecraft! I’ll be using this on my next engagement.
0
0
2
@Lemonitup
Lemon
4 months
@thoughtfault Link to the training?
1
0
2
@Lemonitup
Lemon
4 months
0
0
2
@Lemonitup
Lemon
5 months
@0xTib3rius Detection engineering is a great option for seasoned Pentesters because they understand how attackers think and can execute the tools to create detections in security products or for organizations.
0
0
1
@Lemonitup
Lemon
5 months
Friendly reminder: You can actually buy industrial hardware like crane controllers online and test them for security vulnerabilities. This version allows you to capture and replay button presses.
0
2
8
@Lemonitup
Lemon
5 months
@SwiftOnSecurity @CISAgov Does CISA have this authority, because there are thousands of traffic lights vulnerable to CVE-2024-38944…
0
0
0
@Lemonitup
Lemon
5 months
@azalsecurity Translation
Tweet media one
Tweet media two
0
0
0
@Lemonitup
Lemon
5 months
@techspence I once had a customer dispute the results of a pentest saying any good firm does full packet captures of all their testing. Customer wanted to know the EXACT time we identified specific directories while fuzzing a webapp and when the packet was sent.
1
0
3
@Lemonitup
Lemon
6 months
Help me, Obi-Wan Kenobi. I'm afraid Princess Leia has been turned to the Dark Side.
Tweet media one
0
0
2
@Lemonitup
Lemon
6 months
@HackingLZ The coolant line! That turbo setup! I’m tired of seeing these pie cut titanium setups. 11/10 on your turbo mount execution!
1
0
0
@Lemonitup
Lemon
6 months
@BuildHackSecure I know but I’m typically grabbing a screenshot for the pentest report!
1
0
3
@Lemonitup
Lemon
6 months
The worst part about Responsible Disclosure is the “Responsible” part. I want to share my findings now, but I guess I’ll wait until the patch drops! COMPLETELY unrelated, the top song for the day is “It’s getting hot in here”
0
0
4