Tim Medin 🇺🇦 Profile Banner
Tim Medin 🇺🇦 Profile
Tim Medin 🇺🇦

@TimMedin

Followers
17,886
Following
586
Media
1,712
Statuses
19,804

Kerberoast Guy • @RedSiege CEO • IANS Faculty • Forbes Tech Council • Former SANS SEC560 Author, Senior Instructor • Work Req:

Longview, TX
Joined April 2008
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@TimMedin
Tim Medin 🇺🇦
5 years
I’ve spoken in front of large groups, small groups, technical groups, and executives. I’ve spoken all over the world. But I’m about to have my biggest test. I’m reading Fox in Socks to twenty 4-6 year olds. I’m nervous for the first time in years. #TweetleBeetleBattleBeginsNow
Tweet media one
12
7
231
@TimMedin
Tim Medin 🇺🇦
3 years
At no point did I know what the next word was going to be. For any of it.
Tweet media one
124
4K
18K
@TimMedin
Tim Medin 🇺🇦
3 years
Best description of NFT I've seen
Tweet media one
116
4K
17K
@TimMedin
Tim Medin 🇺🇦
2 months
My favorite CrowdStrike memes 🧵
Tweet media one
128
1K
8K
@TimMedin
Tim Medin 🇺🇦
4 years
GitHub issue LOL
Tweet media one
47
434
4K
@TimMedin
Tim Medin 🇺🇦
7 years
Ok folks, you have failed me for not telling me I can move a process to a screen session 1. Suspend: Ctrl+z 2. Resume: bg 3. Disown: disown %1 4. Launch screen 5. Find pid: prep BLAH 6. Reparent process: reptyr ###
63
1K
3K
@TimMedin
Tim Medin 🇺🇦
2 months
My team at Red Siege has written, instructed and developed some awesome training over the last year with zero involvement from me. Unfortunately, even though they don't work for SANS and I have had zero input or part in their courses, SANS has told me that unless they stop
110
124
1K
@TimMedin
Tim Medin 🇺🇦
3 years
If you’ve ever wondered what “normies” think of security, here you go
@FallonTonight
The Tonight Show
3 years
Microsoft will no longer require users to enter a password to access their accounts. Instead, they'll have to use an app, a verification code or facial recognition. Check it out ⬇️
52
903
3K
25
233
1K
@TimMedin
Tim Medin 🇺🇦
3 years
I am not a quitter! I use vim. I don't know how to quit.
32
111
1K
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
1
66
956
@TimMedin
Tim Medin 🇺🇦
2 years
Weight loss tip: Use this gym. You can never leave.
Tweet media one
39
94
842
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
4
68
741
@TimMedin
Tim Medin 🇺🇦
3 years
Here’s Pole Assassin, the emotional support monkey, and the warning sign for the monkey. (Thanks @matt0177 )
Tweet media one
Tweet media two
Tweet media three
17
88
647
@TimMedin
Tim Medin 🇺🇦
2 years
I forgot the cup. Two days in a row, I forgot the cup.
Tweet media one
137
22
662
@TimMedin
Tim Medin 🇺🇦
3 years
Some dude is all panties in a bundle because I didn’t use “basic OPSEC principles” during a presentation and revealed my city. Look, if you can’t figure out the street address of the only Tim Medin on the planet, you need another gig.
37
21
566
@TimMedin
Tim Medin 🇺🇦
2 months
1
37
577
@TimMedin
Tim Medin 🇺🇦
4 years
Texas Supreme Court met via Zoom and decided that people must vote in person (no absentee). Let that sink in.
20
144
523
@TimMedin
Tim Medin 🇺🇦
3 years
Wife: If Cybersecurity awareness month had a ribbon, what color would it be? Me: Bourbon
Tweet media one
15
75
526
@TimMedin
Tim Medin 🇺🇦
5 years
The more I use AWS the more I’m suprised everyone isn’t leaking data.
29
62
510
@TimMedin
Tim Medin 🇺🇦
4 years
I'm so tired of this meme, but his is funny
Tweet media one
6
140
496
@TimMedin
Tim Medin 🇺🇦
6 months
> Our vendor risk management has decided you are high risk because you don't have an IPS on your network or a physical security program! Homeboy, we work from home. There is no office. There is no network infrastructure. None of this makes sense. > But we have these
Tweet media one
35
45
502
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
4
54
483
@TimMedin
Tim Medin 🇺🇦
4 years
Flash dies tomorrow. It was a run.
Tweet media one
20
151
452
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
3
31
441
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
1
36
438
@TimMedin
Tim Medin 🇺🇦
3 years
what the hell
@m_ou_se
Mara
3 years
🐚 Did you know? Posix shell input/output redirection doesn't need to be at the end of the command. You can put it at the start or in the middle of the command too: $ echo >file hello world ✨
Tweet media one
53
238
2K
30
99
426
@TimMedin
Tim Medin 🇺🇦
3 years
Got an accidental invite to a bachelor party. 100% chance I’d go. Don’t know who anyone is.
Tweet media one
Tweet media two
24
19
424
@TimMedin
Tim Medin 🇺🇦
2 months
@volcaholic1
Volcaholic 🌋
2 months
Todays winner 🤣🤣🤣
Tweet media one
88
2K
16K
1
22
424
@TimMedin
Tim Medin 🇺🇦
2 months
@TimMedin
Tim Medin 🇺🇦
2 months
This CrowdStrike outage is a thing of nightmares. Imagine having to have to walk to each of the downed systems and manually fix it. Even worse with FDE. I have flashbacks of Nimda and the reboot loop, but this is worse.
Tweet media one
12
24
191
2
14
399
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
4
44
393
@TimMedin
Tim Medin 🇺🇦
2 months
2
15
377
@TimMedin
Tim Medin 🇺🇦
5 years
A month
Tweet media one
15
17
371
@TimMedin
Tim Medin 🇺🇦
4 years
I once set my wifi password to “uppercase with no spaces”. I thought it would be funny to tell people, “the password is ‘uppercase with no spaces’ but in lowercase and with spaces.” It was funny for about 10 seconds.
21
34
354
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
1
23
339
@TimMedin
Tim Medin 🇺🇦
6 years
Can we stop calling it the “dark web”. It is just the internet that you can’t find with google. It isn’t a separate internet.
27
77
333
@TimMedin
Tim Medin 🇺🇦
6 years
If you hate the term “purple team” or “fusion team” remember why they exist. They exist because the offensive people have been crap communicators. They exist because red has shamed or humiliated blue. Red only exists to improve blue. Anything else is a waste of time & money.
14
98
333
@TimMedin
Tim Medin 🇺🇦
2 years
“What is Exit?”
Tweet media one
34
31
329
@TimMedin
Tim Medin 🇺🇦
3 years
What a brilliant idea! Phishious provides the ability to see how various Secure Email Gateway technologies behave when presented with phishing material.
1
96
315
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
1
15
311
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
1
18
306
@TimMedin
Tim Medin 🇺🇦
6 years
Headed home. Mileage seems fitting.
Tweet media one
12
18
299
@TimMedin
Tim Medin 🇺🇦
5 years
Looking at individuals' .bash_history and usage of “rm” has taught me things about the users. 1. Well adjusted (as well adjust as a *nix person can be): rm -rf blah 2. A cry for help: rm -fr blah 3. Serial killer rm -Rf blah
23
63
269
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
3
14
277
@TimMedin
Tim Medin 🇺🇦
3 years
Stealing this for my @WWHackinFest talk in a couple of weeks. This is exactly my topic.
@SkelSec
SkelSec
3 years
Tweet media one
18
283
1K
22
38
273
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
2
16
276
@TimMedin
Tim Medin 🇺🇦
3 years
Client requires that we have a business continuity plan. We all work from home. I wrote it.
Tweet media one
18
24
274
@TimMedin
Tim Medin 🇺🇦
5 years
Me: I setup a new Wi-Fi network with additional filtering and protections. It’s called “Wu-Tang LAN”. Wife: huh? Me: Wu-Tang LAN is for the children Wife: 😐
15
43
265
@TimMedin
Tim Medin 🇺🇦
2 years
I single handedly stopped no less that 1,000 attacks by filling out this vendor risk management Excel doc. Rest well everyone. I got you.
17
22
263
@TimMedin
Tim Medin 🇺🇦
4 years
What is the simplest hack you’ve pulled of or witnessed? We’ve had a DA account with Winter2019 MFA bypass by just skipping the login page What else? I finishing up my talk on Hacking Dumberly and how simple stuff item works.
188
41
258
@TimMedin
Tim Medin 🇺🇦
2 years
On average, how many tabs do you have open? Me: In which window in which of my 3 browsers?
57
14
248
@TimMedin
Tim Medin 🇺🇦
5 years
My kid’s math sweatshirt. Love it but it should be longer. :)
Tweet media one
5
46
251
@TimMedin
Tim Medin 🇺🇦
4 years
I see way too many people type "PEN test" as if it is an acronym. What does PEN stand for? Wrong answers only.
343
33
243
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
1
18
234
@TimMedin
Tim Medin 🇺🇦
3 years
I love the magic of SSH. So many useful features packed in that "simple" tool.
Tweet media one
10
39
227
@TimMedin
Tim Medin 🇺🇦
3 years
My favorite slide of all time :)
Tweet media one
8
59
205
@TimMedin
Tim Medin 🇺🇦
3 years
Anyone need an invite for Gmail?
19
10
201
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
1
8
192
@TimMedin
Tim Medin 🇺🇦
2 months
This CrowdStrike outage is a thing of nightmares. Imagine having to have to walk to each of the downed systems and manually fix it. Even worse with FDE. I have flashbacks of Nimda and the reboot loop, but this is worse.
Tweet media one
12
24
191
@TimMedin
Tim Medin 🇺🇦
3 years
Every TLS finding
@SiliconShecky
Shecky - Going to BlueTeamCon, Ninja Warrior
3 years
Stolen from the TrustedSec Discord:
Tweet media one
17
162
1K
8
20
189
@TimMedin
Tim Medin 🇺🇦
4 years
Anyone else planning on spending all day on December 31st binge watching all the content before Flash dies? “Gotta checka checka da email, hope it’s from a ... female”
19
32
189
@TimMedin
Tim Medin 🇺🇦
3 years
Often times, APT isn't very "A"... and sometimes not even very "P". Conti ransomware folks having issues exiting vim:
Tweet media one
16
24
186
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
1
11
182
@TimMedin
Tim Medin 🇺🇦
4 years
Want more AV/EDR hooking and bypasses? This article has some solid depth to it (and it is quite readable too). Thank you to Matthew Eidelberg at @optiv for the article.
Tweet media one
0
91
183
@TimMedin
Tim Medin 🇺🇦
3 years
TIL: You can tunnel through RDP (much like SSH) using proxychains.🤔🤔🤔 "Dynamic Virtual Channels ... enable the tunneling of arbitrary packets inside the RDP connection by tagging packets according to the desired source/destination"
4
81
178
@TimMedin
Tim Medin 🇺🇦
3 years
Thanks everybody
@SANSOffensive
SANS Offensive Operations
3 years
Congratulations to Tim Medin ( @TimMedin ) for his promotion to SANS Senior Instructor! Well-deserved recognition for his contributions to our community, industry, & his countless students. Thank you, Tim! Learn more about Tim:
Tweet media one
14
16
100
18
3
171
@TimMedin
Tim Medin 🇺🇦
2 years
Lot's of truth here
Tweet media one
3
22
167
@TimMedin
Tim Medin 🇺🇦
5 years
6yo: Dad, making friends is easy. Just ask their name and then play. Boom. Done! I’m on the lookout for more friends. Who wants to play?
50
13
165
@TimMedin
Tim Medin 🇺🇦
3 years
A lot of orgs incorrectly defend against password spray attacks but blocking the source IP. This is largely a waste of energy since changing source IPs is trivial. You need to identify the successful auth within the failed ones. Good info from Microsoft.
Tweet media one
2
50
166
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
2
7
164
@TimMedin
Tim Medin 🇺🇦
2 years
A man tried to take my son (he’s fine). He didn’t lure him with candy, he didn’t do it by force. He yelled at him and said he had to come with him. I’ve never heard of this tactic. He scared him into coming with him. He wasn’t that far from us. He’s 10 and smart. Be aware!
Tweet media one
Tweet media two
Tweet media three
24
27
163
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
1
10
160
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
2
15
154
@TimMedin
Tim Medin 🇺🇦
4 years
Wow! Holy Smokes! This blows my mind! "For those who might not see what this is: Fully working SMB protocol implementation is webassembly, it runs in your browser"
@SkelSec
SkelSec
4 years
I waited 2 years for this, rewrote impacket for this, asked cryptographers to remake algos in python for this, spent enormous time of my life to make this happen. and it's finally here this finally works and I can't find the words to express my satisfaction.
Tweet media one
79
749
2K
7
43
155
@TimMedin
Tim Medin 🇺🇦
3 years
I'm his boss. I'm a bigger moron. You CAN do this.
@hardwaterhacker
🇺🇦Mike Saunders
3 years
Stop worrying about imposter syndrome. I've got a job and I'm a fcking moron. You're more than adequate for the job.
5
16
243
6
8
155
@TimMedin
Tim Medin 🇺🇦
4 years
Since we are living in a simulation, can we revert to snapshot?
14
23
150
@TimMedin
Tim Medin 🇺🇦
4 years
This post from CrowdStrike is spot on. #2 Network Shares is an issue we see in 100% of @RedSiege tests. That is not hyperbole. Remember, attackers don't need all the data. How much would it take to make a breach notification or put you in the news?
0
52
146
@TimMedin
Tim Medin 🇺🇦
4 years
2020 24 hours to go I wanna be sedated
10
45
151
@TimMedin
Tim Medin 🇺🇦
4 years
The two most important work from home tips 1) MUTE YOUR DAMN MIC! 2) Double check the mute setting before flushing!
10
13
147
@TimMedin
Tim Medin 🇺🇦
3 years
It is called "Recon" and "PrivEsc" because we can't spell. Change my mind.
25
14
145
@TimMedin
Tim Medin 🇺🇦
4 years
My boys got me a Wonder Woman mask thinking I’d be embarrassed and not wear it. I love it.
Tweet media one
10
3
144
@TimMedin
Tim Medin 🇺🇦
4 years
Deescalate This is the seemingly most ironic lesson I learned from a Ranger and a Martial Arts instructor. The two people I know who are most able to kill people talked about descalation and avoiding violence.
13
24
139
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
1
3
140
@TimMedin
Tim Medin 🇺🇦
6 years
You can learn a LOT looking at someone’s .bash_history. It’s like looking into someone’s tech soul. “This dude is a regex black belt” “Wow, this guy needs a typing lesson” “Why does this fella put `sudo` before every.. singe.. command (ssh)"
15
27
137
@TimMedin
Tim Medin 🇺🇦
6 years
My fantastic wife bought the boys “Future Hacker” shirts. They came running in whilst I was doing a “got root” dance. Today is a good day!
Tweet media one
7
5
134
@TimMedin
Tim Medin 🇺🇦
2 months
If someone is a "seasoned professional", what seasoning is it? Paprika?
125
7
137
@TimMedin
Tim Medin 🇺🇦
2 months
Tweet media one
1
8
134
@TimMedin
Tim Medin 🇺🇦
4 years
Zoom backgrounds are the modern equivalent of Winamp skins
6
21
132
@TimMedin
Tim Medin 🇺🇦
11 months
If you want it, you can have it ⁦ @edskoudis ⁩ 🤣🤣🤣
Tweet media one
14
1
133
@TimMedin
Tim Medin 🇺🇦
2 years
Dude at the airport ordered a double whiskey at 6:15am. Slammed it, then walked to his gate. It’s always 5 o’clock at the airport.
27
1
128
@TimMedin
Tim Medin 🇺🇦
4 years
The irony of "Halp! We need a last minute pen test" mixed with "our payment terms are 90 days"
11
4
131
@TimMedin
Tim Medin 🇺🇦
3 years
If a potential employer asks you for a writing sample, do NOT attempt to redact a work report and send it! 99% chance you miss something 100% chance you demonstrated you can't protect client info I'd fire on the spot if I heard of this
11
6
129
@TimMedin
Tim Medin 🇺🇦
5 years
My #FF is this new little guy
Tweet media one
25
1
130
@TimMedin
Tim Medin 🇺🇦
5 years
I experienced German healthcare today (eye infection) I walked in and filled out a 1/4 page of paper (unlike 4-5 pages in US) Waited 4 minutes (3-10x in US) Dr was efficient and gave Rx in 3m I paid in cash 25€ and I got change Pharmacy was faster than McD Dang efficient!
Tweet media one
10
11
124
@TimMedin
Tim Medin 🇺🇦
2 years
Given the age of the Uvalde shooter, the shooter had likely been through more active school shooter drills than the cops. All new school shooters will have gone through the drills. The shooters know what they are stepping into. Think about that for a sec.
7
37
126
@TimMedin
Tim Medin 🇺🇦
3 years
To the person in Croatia who ordered Pizza Hut using the company card, I hope you enjoyed it. Also, the limit on that sucker meant you could have purchased a house. Should have been faster.
12
5
122
@TimMedin
Tim Medin 🇺🇦
4 years
Those of you who still use two spaces after a period, what type of stone do you chisel your words into?
50
13
124
@TimMedin
Tim Medin 🇺🇦
3 years
It’s a go!
Tweet media one
6
0
121
@TimMedin
Tim Medin 🇺🇦
1 year
. @RedSiege is now more offensive than ever with the acquisition of @FortyNorthSec ! I'm really excited to have them part of the team for all their contributions to infosec, including EyeWitness! Details on the acquisition are below.
@RedSiege
Red Siege Information Security
1 year
MORE OFFENSIVE THAN EVER! Red Siege acquires @FortyNorthSec READ:
Tweet media one
9
20
111
11
23
123
@TimMedin
Tim Medin 🇺🇦
3 years
"We crunched the numbers..." This got me thinking, which number is the crunchiest?
47
9
116