![Tim MalcomVetter Profile](https://pbs.twimg.com/profile_images/1887288692131119104/ExaCc6UF_x96.jpg)
Tim MalcomVetter
@malcomvetter
Followers
12K
Following
26K
Statuses
13K
Co-Founder/CEO at ⚡️ @Wirespeed_ Prev: @NetSPI @CYDERES @FishtechGroup @Walmart Red Team @Sp4rkCon @Optiv @fishnetsecurity. PhD Dropout. BJJ 🟪⬛️⬛️🟪🟪 ⳩
🌎
Joined May 2015
Check out our blog series about what we have seen with an uptick in #identity attacks and how companies have managed to not notice bad guys stealing + logging in with their credentials. 👇
We have bad news for you: Identity compromises happen a lot. WAY more often than organizations know, because most events don't result in material impact. 😢 Read the first post in our series about this problem and what you can do about it. 💡
0
0
2
@ItsReallyNick @ImposeCost And SOC analysts at MSSPs are an even different breed. It’s often an even more difficult challenge. So, we wrote about that, too:
0
1
5
Check out this amazing detection approach! … Followed by: - something cherry picked - unrealistic data - theoretical - not scalable - requiring some third party tool - requiring a paid license for a data format or integration - done in Excel - noisy - too gray … ^ 90% of social posts about new detection approaches
0
0
2
@jamieantisocial @matthewdunwoody @ItsReallyNick In fact, that’s one reason why we built @wirespeed_ to actually NOT use SSO. We still sync the directory and know when people come/go, but we have a very intentional wall between us and the customer’s environment.
1
0
4
@ITguySoCal Do you happen to know if these RiskState values are more robust in their logic? `userPassedMFADrivenByRiskBasedPolicy` `aiConfirmedSigninSafe`
1
0
1
This is a #redteam technique that I somehow completely missed, but would have loved to use with phishes (and other things). Check it out! Also, please give @wirespeed_ a follow to see more like this.
How a Unicode character made a .lnk file look like a .pdf in a phish! And how we triaged and contained that case + a related credential theft in ⚡️seconds!
0
0
5