☠️ Andy Piazza ☠️ Profile Banner
☠️ Andy Piazza ☠️ Profile
☠️ Andy Piazza ☠️

@klrgrz

Followers
6,053
Following
2,976
Media
3,033
Statuses
15,223

Christian. Killer grizz w/ a keyboard. Threat Intel & Thrunter. Hack things w/ @bsides_nova . Black Badge @DEFCON & C&E Goon. GSE #344 . (VIEWS ARE MY OWN).

Northern Virginia
Joined June 2017
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@klrgrz
☠️ Andy Piazza ☠️
4 years
Pinning this thread of #CTI tips and lessons learned. I'll add to it at random times. #threatintel
@klrgrz
☠️ Andy Piazza ☠️
4 years
Clarify something for new folks to #CTI , the sexy capabilities you think of from producers (government or commercial) are not exactly the same skills you need in a #BlueTeam #defender role for CTI. Your org needs you to interpret it for them. That's important. Start there.
1
7
47
11
18
113
@klrgrz
☠️ Andy Piazza ☠️
7 months
Gonna make me tap the sign again:
Tweet media one
@arstechnica
Ars Technica
7 months
Formula 1 chief appalled to find team using Excel to manage 20,000 car parts
425
924
7K
19
610
6K
@klrgrz
☠️ Andy Piazza ☠️
5 years
Tweet media one
4
205
2K
@klrgrz
☠️ Andy Piazza ☠️
3 years
Streaming internet cable.
Tweet media one
86
149
2K
@klrgrz
☠️ Andy Piazza ☠️
2 years
I’m not apologizing for this.
Tweet media one
22
231
2K
@klrgrz
☠️ Andy Piazza ☠️
3 years
Can we agree that “learn Linux” is just dumb? It’s non-specific advice that isn’t helping junior folks. Learn what in Linux? Just be a Linux user? Deploy a web server? Deploy a tool? Same w/ “learn wireshark/Splunk/Snort/etc”. Tell new people actionable topics & skills to learn.
79
121
1K
@klrgrz
☠️ Andy Piazza ☠️
2 years
Sooo, I’m starting with IBM today as the Global Head of Threat Intelligence!
@PhiaLLC
phia LLC
2 years
@klrgrz Congratulations on the new opportunity and a big thank you from phamily! We’re proud to have another #phiaalum contributing significantly to the cyber community in a different capacity.
0
0
11
109
18
1K
@klrgrz
☠️ Andy Piazza ☠️
2 years
This is fun… right? Right! #HomeLab #InfosecMemes
Tweet media one
48
88
823
@klrgrz
☠️ Andy Piazza ☠️
3 years
As promised months ago... I wrote out a CTI Study Plan for those that are interested. Hopefully, it is enough info to get you started on your journey.
26
188
659
@klrgrz
☠️ Andy Piazza ☠️
4 years
If I could only recommend one book for #infosec , I’d probably say this is it. The book includes a great introduction to intrusion analysis, incident response, and security operations planning. #BlueTeam #CTI #RequiredReading
Tweet media one
18
76
510
@klrgrz
☠️ Andy Piazza ☠️
3 years
If you struggle to show a PowerPoint on a virtual call in 2021, I may have trouble trusting your cybersecurity solutions to solve any of my problems.
21
46
490
@klrgrz
☠️ Andy Piazza ☠️
7 months
Welp it is official, starting today as the Senior Director of Threat Intelligence for @Unit42_Intel . Let's go!!!
79
12
493
@klrgrz
☠️ Andy Piazza ☠️
3 years
Some might say I’m not vacationing properly, but this is my zen. Anytime infosec is too much, construction is the answer.
Tweet media one
31
14
433
@klrgrz
☠️ Andy Piazza ☠️
2 years
Showed little man some of the @RealTryHackMe challenges yesterday. This morning he asked if we could do some more so we signed him up with his own account and he’s working through the intro lessons.
Tweet media one
13
17
418
@klrgrz
☠️ Andy Piazza ☠️
3 years
Tweet media one
2
15
405
@klrgrz
☠️ Andy Piazza ☠️
3 years
Say it with me: Outlook is NOT a SIEM nor a storage solution. Its okay to delete those alert emails from last year.
44
31
398
@klrgrz
☠️ Andy Piazza ☠️
4 years
When folks want to get into infosec and don’t know a direction, I generally point them towards Sec+ material. It covers a broad range of topics and is often a gatekeeper in hiring systems. I also point them to SANS Cyber Aces material. Any specific go-to resources I’m missing?
37
66
390
@klrgrz
☠️ Andy Piazza ☠️
3 years
I get this a lot from sysadmins and network engineers: "I want to get into infosec". Like, you're already there! Do your job to secure the network. sysadmins and network engineers have farrrrrr greater opportunity for security in their daily tasks than a SOC or a Sec Engineer.
@Evil_Mog
EvilMog®
3 years
Uncomfortable truth, you don't need to be working in a SOC to be in infosec. Network and Sysadmins do just as much infosec as your high paid security analysts. They directly implement security, from firewall rules to system configurations. Be nice to your sysadmins.
63
183
1K
19
46
314
@klrgrz
☠️ Andy Piazza ☠️
3 years
Hey #CTI Twitter, what are the “must read” APT reports you assign to new analysts coming into the field? Mandiant’s APT1 report is an obvious choice. I’m also a big fan of Threat Connect’s “What’s in a Name Server” because it demonstrates infrastructure analysis well.
23
59
288
@klrgrz
☠️ Andy Piazza ☠️
2 years
You didn’t automate threat hunting, you wrote a detection.
13
31
274
@klrgrz
☠️ Andy Piazza ☠️
2 years
So I did a thing… #GSE344
Tweet media one
42
4
270
@klrgrz
☠️ Andy Piazza ☠️
1 month
Lollll @_JohnHammond I just found this in an IT memes page on Facebook. Can’t get away from you 🤣
Tweet media one
4
14
256
@klrgrz
☠️ Andy Piazza ☠️
3 years
can't wait to see the phishing attempts via Teams external messages
@jeffteper
Jeff Teper
3 years
#MicrosoftTeams users can now chat with any Teams user outside their organization 💜🌍
35
137
466
16
48
251
@klrgrz
☠️ Andy Piazza ☠️
4 years
I feel like the NFL ordered Michael Jackson from Wish.
4
56
234
@klrgrz
☠️ Andy Piazza ☠️
4 years
I’m trying to say this in the most non-hipster way possible: I only want human curated threat Intel. Automated feeds are killing the CTI community. Automation should be how we share, not how “Intel” is produced.
16
28
220
@klrgrz
☠️ Andy Piazza ☠️
3 years
@IanColdwater The more I learn how the internet works, the more I’m confused that the internet works.
3
16
206
@klrgrz
☠️ Andy Piazza ☠️
2 months
Remember that time I won a black badge at ⁦ @defcon ⁩? That was kinda cool. Thank you ⁦ @thedarktangent ⁩ and ⁦ @Grifter801 ⁩!!!
Tweet media one
21
15
202
@klrgrz
☠️ Andy Piazza ☠️
3 years
GWOT vets: unless you wore stars on your shoulders, this isn’t our failure. We did our part. Our tactical success can’t be taken away. Our losses matter too. This is a strategic failure and doesn’t reflect on our service at all. I’m proud to have served with every one of you. 💙
6
39
199
@klrgrz
☠️ Andy Piazza ☠️
3 years
I like this graphic from @CISAgov new IR & Vuln Response Playbook
Tweet media one
3
48
198
@klrgrz
☠️ Andy Piazza ☠️
1 year
My toxic trait is my need to support friends by ordering their books as soon as they’re available - and I’m okay with it Congrats @megan_roddie !
Tweet media one
5
39
192
@klrgrz
☠️ Andy Piazza ☠️
2 years
My first contribution to this sweet meme template.
Tweet media one
@svblxyz
svbl 🇺🇦
2 years
Russian military leadership. I might use these photos in my next Cyber Security presentation. 😬
Tweet media one
Tweet media two
Tweet media three
292
1K
7K
7
27
172
@klrgrz
☠️ Andy Piazza ☠️
2 years
Tweet media one
6
29
170
@klrgrz
☠️ Andy Piazza ☠️
1 year
Tweet media one
@dutch_osintguy
Dutch Osint Guy Nico
1 year
NEW BLOG: Using AI for extracting Usernames, Emails, Phone Numbers, and Personal Names from large datasets #OSINT Read it here :
Tweet media one
3
34
87
9
28
167
@klrgrz
☠️ Andy Piazza ☠️
4 years
First Christmas present opened... and I have my first book for 2021! Cc: @anthomsec
Tweet media one
6
9
157
@klrgrz
☠️ Andy Piazza ☠️
1 year
I’ve done a lot of projects in my time, but this one I’m most proud of because my son (16) did a lot of the work with me. Not just “hand me that tool” stuff. He picked boards, measured & cut, and installed them. We both put some sweat equity into this one- thankfully no blood!
Tweet media one
22
0
153
@klrgrz
☠️ Andy Piazza ☠️
3 years
My son sent this to me 😂
Tweet media one
2
8
149
@klrgrz
☠️ Andy Piazza ☠️
3 years
Cyber threat intel - learn SOC/IR processes. Your SOC is your collection, understand their visibility & how to exploit the data from their tools. The job isn’t reading threat reports. It’s about being able to apply them to your network & write them from your own collection.
@cybersecmeg
meg west
3 years
what is your profession within the cybersecurity field (or IT field!) and what is your most helpful tip for those who are trying to level up to where you are at?
179
54
470
3
29
146
@klrgrz
☠️ Andy Piazza ☠️
4 years
I think blue team needs to learn from red team and start asking for scoping documents from management. Fill out this form: “What systems do you expect us to monitor AND what is our authority to configure/manage them?”
11
22
153
@klrgrz
☠️ Andy Piazza ☠️
2 years
The GoldiLocks CTI Program idea has rattled around in my head for like two years... it's been turned down for multiple cons, so you'd think it would stop burning a hole in my brain eventually, but noooo... so I finally wrote it down. Enjoy, I guess.
8
43
152
@klrgrz
☠️ Andy Piazza ☠️
3 years
I don’t think my kid’s generation understands the beauty of having parents that also play video games Kids: just let me finish this round first Me: of course My parents 20 years ago: turn that shit off now!
10
11
145
@klrgrz
☠️ Andy Piazza ☠️
9 months
Apparently my talking point “threat hunting isn’t proactive” struck a nerve today. Let me explain… You’re not “creating or controlling a situation by causing something to happen”. You are finding evidence of activity after it happened, that is reactive. It just feels proactive
Tweet media one
43
9
145
@klrgrz
☠️ Andy Piazza ☠️
3 years
Threat assessments are nearly useless without considering a specific target/victim. For governments & large corporations, China is probably the bigger threat. For most businesses, it ain’t APTs at all, it’s cybercrime w/ ransomware leading that pack.
@cyb3rops
Florian Roth
3 years
I constantly defend that position in private conversations
Tweet media one
76
126
1K
8
20
140
@klrgrz
☠️ Andy Piazza ☠️
1 year
Tweet media one
@unusual_whales
unusual_whales
1 year
Want to see a crazy trade? Yesterday, someone OPENED $SPLK 127 calls, for $22,000, expiring tomorrow. Then today Cisco Systems $CSCO announced acquiring Splunk for $28B, $SPLK up 20%. The contracts were $0.04 yesterday, now $18.30. They exited today for a 45,650% return...
Tweet media one
Tweet media two
Tweet media three
3K
4K
25K
0
27
137
@klrgrz
☠️ Andy Piazza ☠️
3 years
If you know a Marine, please read them all of the “Happy Birthday Marine” posts today. It’s their day, they shouldn’t have to struggle with reading the big words themselves.
12
8
133
@klrgrz
☠️ Andy Piazza ☠️
1 year
Tweet media one
@SwiftOnSecurity
SwiftOnSecurity
1 year
PROTIP: Notepad++ has a bunch of cool native tools in the edit menu you should explore. I use this stuff multiple times a week. The plugins system also has a bunch of useful tools others have built. Trust me, you're not the first person with your problem!
Tweet media one
Tweet media two
40
62
553
6
10
128
@klrgrz
☠️ Andy Piazza ☠️
1 year
This actor should be behind bars, not given their own persona and super hero character. Seriously bad form that’s only going to encourage more larpers to do badness on nights and weekends.
31
18
132
@klrgrz
☠️ Andy Piazza ☠️
5 years
@tonyhawk These stories need their own hashtag so they can be grouped as a series. They are truly one of my favorite things on Twitter.
2
2
124
@klrgrz
☠️ Andy Piazza ☠️
4 years
I love getting these messages about the team and I send them to the rest of the leadership team every chance I get. Normalize celebrating coworkers!
@SwiftOnSecurity
SwiftOnSecurity
4 years
Normalize sending Thank You notes to people with their Manager Cc'd. It's like hacking but for organizational clout.
59
368
2K
4
16
124
@klrgrz
☠️ Andy Piazza ☠️
3 years
Creating more Splunk dashboards isn’t helping anyone. Check the 500 your org already created and now ignore. Stop confusing activity with productivity.
12
17
123
@klrgrz
☠️ Andy Piazza ☠️
7 months
Tweet media one
0
12
122
@klrgrz
☠️ Andy Piazza ☠️
2 years
Hey little buddy, @Official_NAFO . Love the Russian bonking bat!
Tweet media one
3
14
118
@klrgrz
☠️ Andy Piazza ☠️
3 years
Vacation begins with margaritas, big a$$ margaritas
Tweet media one
8
1
118
@klrgrz
☠️ Andy Piazza ☠️
7 months
Always prioritize the stuff the NSA says is a priority or something to pay attention to in security. Related:
Tweet media one
@NSA_CSDirector
Dave Luber
7 months
This is a threat to watch. My concern is elevated because this variant is a more powerful AcidRain variant, covering more hardware and operating system types.
6
73
175
4
21
120
@klrgrz
☠️ Andy Piazza ☠️
3 years
Also “set up a lab and play around!” Wut. We can give better guidance and point to better resources then “here are random words newbie, good luck on your own!”
8
5
113
@klrgrz
☠️ Andy Piazza ☠️
7 months
Today is my last day with @XForce , after 2 amazing years. I am blessed by the friendships I’ve made & the cool projects we’ve worked on - like multiple reports exposing Russia’s capabilities & targeting of global allies (f!ck Putin!). I’m humbled to have led X-Force Threat Intel.
Tweet media one
15
2
111
@klrgrz
☠️ Andy Piazza ☠️
4 years
I picked up a bunch of new followers this week from a few different posts about infosec career stuff. Welcome. Just so we’re all clear, I’m also a complete dork and will do stupid stuff like this to make my wife cringe.
Tweet media one
18
2
106
@klrgrz
☠️ Andy Piazza ☠️
2 years
@bettersafetynet Haha, like showing someone Wireshark for the first time. YOU CAN SEE THAT?! 😂
2
2
105
@klrgrz
☠️ Andy Piazza ☠️
2 years
Tweet media one
1
6
89
@klrgrz
☠️ Andy Piazza ☠️
3 years
Tweet media one
4
6
97
@klrgrz
☠️ Andy Piazza ☠️
3 years
Aiden (14) is rehabbing an old Dell tower. He’s installed new RAM, a new SSD, and is currently making a bootable USB with Ubuntu. He runs his first successful Terminal command and says “I did it! I hack the things!” 😂
3
0
97
@klrgrz
☠️ Andy Piazza ☠️
3 years
Tweet media one
2
0
96
@klrgrz
☠️ Andy Piazza ☠️
3 years
Battle station is ready for a few hours of the ⁦ @SANS_EDU ⁩ Core Comp Exam.
Tweet media one
6
1
91
@klrgrz
☠️ Andy Piazza ☠️
3 months
Hahaha I’m now ready for #HackerSummerCamp I plan to hand a stack of these #CyberEdSheeran stickers to @_JohnHammond , so make sure you hunt him down too. LFG!!!
Tweet media one
10
7
91
@klrgrz
☠️ Andy Piazza ☠️
2 years
Hunting is probably the single most effective teacher for CTI analysts. You are forced to learn a lot and to eat your own dog food - you’re finally a consumer of your own intel product and you really get to test your understanding of threat actor capabilities.
3
10
90
@klrgrz
☠️ Andy Piazza ☠️
4 years
As a combat veteran that spent two years in Baghdad, and as a Northern Virginia resident, it breaks my heart to see our nation’s capital set up like the damn Green Zone because of domestic threats. We have to be better than this.
4
5
83
@klrgrz
☠️ Andy Piazza ☠️
3 years
In the Before Times, I had a tense conversation with a client about WFH. Them: “if you’re not in the office, how do we know if you’re working.” Me: “if your only measure of success is my butt in a seat, you have serious process issues.” I think about that convo a lot still.
6
10
83
@klrgrz
☠️ Andy Piazza ☠️
5 years
Awesome. Got another #PII #breach letter from DoD. Is this like pokemon where I want to catch them all?
Tweet media one
19
42
74
@klrgrz
☠️ Andy Piazza ☠️
4 years
Tweet media one
4
2
83
@klrgrz
☠️ Andy Piazza ☠️
3 years
Just passed my final requirement for the @SANS_EDU Masters program!!! Seriously an awesome program, incredible coursework in every class, and amazing instructors. I’m going to miss my student advisor and the program!
12
0
84
@klrgrz
☠️ Andy Piazza ☠️
3 years
2021 and we're still publishing IOCs in big PDF tables? cool cool. If you need me, I'll be copy/pasting/verifying output for the next hour. #CTI
12
6
78
@klrgrz
☠️ Andy Piazza ☠️
2 years
Kinda excited to have a wall dedicated to my team’s amazing work. Super proud of the cool stuff we do. #blackhat2022 #BHUSA
Tweet media one
4
3
82
@klrgrz
☠️ Andy Piazza ☠️
6 years
Welcome back @GenMhayden and Merry Christmas!
2
8
72
@klrgrz
☠️ Andy Piazza ☠️
3 years
Yep I’m #hiring - Mid/Senior SOC Analyst (2nd shift) - ISSO - All Source (Cyber) Analyst All three require a TS clearance and are on-site in DC (no remote). DMs open. #infosecjobs
7
34
75
@klrgrz
☠️ Andy Piazza ☠️
3 years
This guy never ceases to amaze me. Check out @thecybermentor 's new course bundles. These deals are amazing and his courses are awesome. I recommend them for anyone in infosec.
1
4
74
@klrgrz
☠️ Andy Piazza ☠️
4 years
@Wookiee__ SANS certs are definitely out of range for entry level, but SANS Cyber Aces is a few hours of free training videos designed for beginners.
2
9
75
@klrgrz
☠️ Andy Piazza ☠️
5 years
Working out today in the garage... Bella: wanna race? Me: let me catch my breath Bella: well daddy, I run and breathe at the same time. Its helpful. #DFIRfit #6yearOldPersonalTrainer
5
5
74
@klrgrz
☠️ Andy Piazza ☠️
3 years
I’m trying to not freak out, but my son just told me that he’s signing up for a weightlifting class for PE and a cybersecurity program for his junior year of high school (next year!) I am so damn excited for both decisions but don’t want to overreact 😂
3
1
73
@klrgrz
☠️ Andy Piazza ☠️
3 years
This Christmas, I’m warming myself by a dumpster fire!
Tweet media one
4
7
72
@klrgrz
☠️ Andy Piazza ☠️
4 years
I don’t know who needs to hear this, but the Downloads folder is not an acceptable method for knowledge management. ... Okay I needed to hear this as I deleted like six months worth of downloaded files.
6
5
72
@klrgrz
☠️ Andy Piazza ☠️
3 years
@kelseyhightower *clears throat* “just export it and we’ll take a look in Excel”
Tweet media one
1
4
67
@klrgrz
☠️ Andy Piazza ☠️
3 years
Tweet media one
0
5
70
@klrgrz
☠️ Andy Piazza ☠️
2 months
Totally normal day at @defcon
Tweet media one
4
5
68
@klrgrz
☠️ Andy Piazza ☠️
3 years
When the internet is a dumpster fire, infosec Twitter makes s’more with gifs and memes. I’m here for it.
1
7
66
@klrgrz
☠️ Andy Piazza ☠️
3 years
Tweet media one
2
8
67
@klrgrz
☠️ Andy Piazza ☠️
4 years
@chadloder Much like troops deploying, its important to separate support for the heroes from the politics that deploy them. (Not saying that you're doing this, but its an easy next step in logic).
4
2
59
@klrgrz
☠️ Andy Piazza ☠️
3 years
This bad boy is hefty! Well done @beauwoods @ithilgore @Einstais @calderpwn @edeirme with an awesome foreword from @HackingDave
Tweet media one
4
16
66
@klrgrz
☠️ Andy Piazza ☠️
2 years
Tweet media one
0
16
66
@klrgrz
☠️ Andy Piazza ☠️
2 months
Thanks @Cannibal for this killer photo!
Tweet media one
5
1
66
@klrgrz
☠️ Andy Piazza ☠️
3 years
I’m hiring a Detection Analyst to write & manage the signature, rules, & alert logic for a client in Northern Virginia or Raleigh NC. Currently remote w/ future on-site required (location matters). Requires Public Trust (we sponsor). PD up soon, DMs open. #infosecjobs #infosec
4
37
67
@klrgrz
☠️ Andy Piazza ☠️
4 years
I HAVE AN APPOINTMENT SCHEDULED FOR THE 5G VACCINE NEXT WEEK! Can’t wait to fight covid and hack carrier pigeons!
7
3
62
@klrgrz
☠️ Andy Piazza ☠️
3 years
Fresh cut, who dis?
Tweet media one
5
0
62
@klrgrz
☠️ Andy Piazza ☠️
3 years
This is my face, come say hi if you see me at #ShmooCon
Tweet media one
5
0
62
@klrgrz
☠️ Andy Piazza ☠️
8 months
This is 41. 🥳🍻
Tweet media one
Tweet media two
9
0
60
@klrgrz
☠️ Andy Piazza ☠️
3 years
What’s longer than a treadmill minute? Watching a 7 year old sign a Mother’s Day card before mommy comes downstairs!
2
1
62
@klrgrz
☠️ Andy Piazza ☠️
2 years
Dinner was epic.
Tweet media one
3
1
59
@klrgrz
☠️ Andy Piazza ☠️
5 years
I love #mentoring people. But please give me some basic info if you reach out. Where are you coming from, where are you at, and where do you want to go? I can do a lot with that. I cant do much with "hey how do i cyberz" #infosec #threatintel #careeradvice #helpmehelpyou
13
10
60