curtw Profile Banner
Curt Wilson, human Profile
Curt Wilson, human

@curtw

Followers
3K
Following
10K
Statuses
10K

Exploring systems security since 1985. Malware+{cybercrime/espionage} analysis, threat intelligence + full-spectrum tech security research. Personal account.

Earth
Joined August 2008
Don't wanna be here? Send us removal request.
@curtw
Curt Wilson, human
2 minutes
Related to the last post.
@ITguySoCal
Joe Stocker
1 month
if you operate Sentinel, and are licensed for Entra P2 or M365 E5, you may have experienced a lack of visibility during token theft events. To reduce noise, Defender XDR auto remediates any incident when an MFA claim is present in the token. The system is not yet smart enough to differentiate between a stolen token and a valid MFA claim, so the work-around is to create a new analytic rule to raise an alert for any elevated user risk, by excluding events flagged as 'remediated.' The following KQL is designed for an analytic rule so that the analyst can see recent sign-ins that caused the user risk to elevate. Feedback and questions encouraged! let a=( AADRiskyUsers | where RiskLevel in ('medium','high') and RiskDetail !in('adminConfirmedUserCompromised','adminConfirmedSigninCompromised') | distinct tolower(UserPrincipalName)); SigninLogs | where tolower(UserPrincipalName) in (a) | where RiskLevelDuringSignIn != 'none' and RiskState != 'remediated'
0
0
0
@curtw
Curt Wilson, human
2 minutes
My current vantage point doesn’t allow visibility into this particular matter but it is interesting.
@malcomvetter
Tim MalcomVetter
18 hours
This is a super hot attack vector right now and probably a ton of orgs aren't working these alerts at all, or maybe just incorrectly. Don't trust `riskState: remediated` !!
0
0
0
@curtw
Curt Wilson, human
6 days
@bquintero Great read! I’m a happy virustotal user for many years now.
0
0
1
@curtw
Curt Wilson, human
8 days
@JeffreyAppel7 @HackingLZ Glad to see.
0
0
0
@curtw
Curt Wilson, human
8 days
New practical mitigations for AitM phishing activity.
@JeffreyAppel7
Jeffrey Appel | Microsoft MVP
9 days
NEW BLOG: AiTM/ MFA phishing attacks in combination with “new” Microsoft protections (2025 edition) After the successful 2023 and 2024 edition, created the blog based on the latest protections and innovations against AiTM attacks #MicrosoftSecurity
0
0
0
@curtw
Curt Wilson, human
8 days
RT @gothburz: We identified a new #ZeroDay vulnerability exploiting 7-Zip (CVE-2025-0411) being actively exploited in-the-wild on September…
0
143
0
@curtw
Curt Wilson, human
8 days
RT @TheHackersNews: 🔐 Russian cybercriminals are exploiting new 7-Zip vulnerability (CVE-2025-0411) to target Ukrainian organizations. Thi…
0
173
0
@curtw
Curt Wilson, human
10 days
RT @cyb3rops: CyberSec Trends Q1/25🔮 ⬆️Lumma Stealer ↗️EDR killers (vulnerable drivers) ↗️Abuse of legit remote access tools ↗️0days in Fo…
0
106
0
@curtw
Curt Wilson, human
13 days
RT @craiu: In case you are a medical institution, it may be worth blocking this in your firewall or if you're using the CMS features, at le…
0
70
0
@curtw
Curt Wilson, human
13 days
RT @binitamshah: Windows CLFS heap-based buffer overflow analysis (CVE-2024-49138) – Part 1 : credits @MrAle_98 htt…
0
29
0
@curtw
Curt Wilson, human
17 days
@bquintero Excellent read. Well done.
0
0
1
@curtw
Curt Wilson, human
21 days
RT @cyb3rops: Kevin published the email addresses in the #Fortigate config dump
Tweet media one
0
92
0
@curtw
Curt Wilson, human
21 days
RT @IceSolst: NEW TOOL: It's a fully in-browser binary/file analysis tool with a hex editor. Features: - Hex edito…
0
224
0
@curtw
Curt Wilson, human
22 days
RT @HackingDave: Smart phish via github - email comes from github - issue is created on repo that suspicious activity was detected and to c…
0
140
0
@curtw
Curt Wilson, human
22 days
@bquintero Just ordered. Kudos!
0
0
1
@curtw
Curt Wilson, human
1 month
@REverseConf Looks like a stellar event. I’m unlikely to be able to come down due to timeline issues but I hope everything goes really well. I can feel the wave of brain power reaching backwards in time.
0
0
0
@curtw
Curt Wilson, human
1 month
@lcamtuf Loading the anti-malware apps from a Commodore 64 datasette.
0
0
0
@curtw
Curt Wilson, human
1 month
@cyb3rops This is on-point. Another factor is comparisons between people who work in different areas of the field. Ideally all of us work together in a large synergy, but it can be easy to lose sight of this idea
0
0
0
@curtw
Curt Wilson, human
1 month
RT @ItsReallyNick: Security Advisory: Ivanti Connect Secure, Policy Secure & ZTA Gateways 1️⃣ CVE-2025-0282 CVSS 9.0 (Critical) ⚠️ Exploite…
0
66
0
@curtw
Curt Wilson, human
1 month
RT @k8em0: One of the finest hackers & humans to ever hack the planet needs our help. @marcwrogers is lucky to be alive & we are luckier…
0
100
0