skrappy0x4a Profile Banner
skrappy0x4a Profile
skrappy0x4a

@skrappy0x4a

Followers
573
Following
1,594
Media
40
Statuses
1,922

Lead on Cyber Defense | War Vet | Not Popular/Cool | Learning Russian | 🏍🦑 | BJJ ◧◧◧ | 🌲

United States
Joined February 2020
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@skrappy0x4a
skrappy0x4a
8 months
@SwiftOnSecurity years of pushing helpdesk to focus on metrics & SLOs created a culture of not wanting to dive deep or spend time to learn. At the same time I see a lot of shifting of accountability, IT at that level & their leaders essentially don't 'own' anything, just deliver it. bad combo!
3
6
117
@skrappy0x4a
skrappy0x4a
6 months
@SwiftOnSecurity There are non conductive cleaning solutions. But I’m not sure this is that.
1
0
74
@skrappy0x4a
skrappy0x4a
5 months
@firefox TellMyWifIloveHer
1
0
75
@skrappy0x4a
skrappy0x4a
6 months
@alittleleader Yeah cause a high school kid in nearly any town could dominate them.
0
0
66
@skrappy0x4a
skrappy0x4a
7 months
@josephfcox Porn is garbage. Good for Texas.
31
0
52
@skrappy0x4a
skrappy0x4a
7 months
@SwiftOnSecurity How much HellDivers 2 have you been playing?
1
1
49
@skrappy0x4a
skrappy0x4a
6 months
@ontheninthfloor For those who don't know, there is now a shopping/housing development over top of the location this man describes. Some of the land is still available/unused.
0
0
28
@skrappy0x4a
skrappy0x4a
8 months
@vxunderground Wait this is sounding real. I might have to transition from sarcasm to handing over monies haha 😱
1
0
21
@skrappy0x4a
skrappy0x4a
7 months
@bettersafetynet I think a lot of people do believe that if you take data off an encrypted endpoint no one else can utilize the data. Even people who are paid to know better.
1
0
19
@skrappy0x4a
skrappy0x4a
8 months
@vxunderground Might sign up, link please? Do you take venmo?
1
0
16
@skrappy0x4a
skrappy0x4a
9 months
@wikileaks Are they still trying to frame him on that CSAM stuff? Yes, secrets need to be protected. Yes, evil secrets need to be challenged.
0
2
17
@skrappy0x4a
skrappy0x4a
7 months
@LetsDefendIO Guys, it's just business. Probably a post for deleting. Maybe you should buy canthackme[.]com /shrug
2
0
15
@skrappy0x4a
skrappy0x4a
8 months
@ErrataRob I haven’t seen this essential yet regex sed find trim awk
1
0
11
@skrappy0x4a
skrappy0x4a
8 months
@SwiftOnSecurity furthermore, I think this is what drives the common IT/Cybersec rift ... some of the good/great IT people moved over to Cyber and call out the BS they see on the other side. A lot of which is coming from lack-of-effort and dedication. Exceptions excluded.
0
0
11
@skrappy0x4a
skrappy0x4a
8 months
@SwiftOnSecurity we maybe also saw most of those dedicated IT people move to cyber. not that we get rewarded much for our efforts, but it's a better fit for that type of person.
1
0
10
@skrappy0x4a
skrappy0x4a
8 months
@Coffee_Fueled 2 years in tech is 4 years anywhere else
2
0
10
@skrappy0x4a
skrappy0x4a
8 months
@reshetz Zelensky was SPEAKING, not even comparable
21
1
8
@skrappy0x4a
skrappy0x4a
9 months
@Raspberry_Pi The most widely used social media in tech/infosec and you're too good to be here. You think facebook and google are morally superior to X? That's ridiculous.
0
0
9
@skrappy0x4a
skrappy0x4a
7 months
@cybersecmeg detect .. you want to not know what you don't know, or have a fire alarm and fire procedure?
2
0
7
@skrappy0x4a
skrappy0x4a
8 months
@CarsonEnglish @SwiftOnSecurity This was all good and fun until someone decided they couldn't deal with Justin Beiber wallpapers anymore, and I got HR'd pretty good.
0
0
7
@skrappy0x4a
skrappy0x4a
8 months
@infosecspy @aaronguilmette Also the Network Security Bible
0
0
7
@skrappy0x4a
skrappy0x4a
8 months
@SwiftOnSecurity Required disclosure is a very recent development and a ransomware incident is not automatically a reportable event. But in the future, this will be something for execs, counsel, and security teams to consider. The feds are on a tear sharing data and with interagency notifications
0
1
6
@skrappy0x4a
skrappy0x4a
8 months
@vxunderground So just send the money and you’ll call me?
1
0
5
@skrappy0x4a
skrappy0x4a
5 months
@mattjay @vxunderground @GossiTheDog Companies like snowflake have a shell of security that's empty inside. They most likely don't have the ability or capability to know a single meaningful thing about what's happening or why. They are billion dollar business that staff like startups.
1
1
8
@skrappy0x4a
skrappy0x4a
5 months
I bet @AccidentalCISO will know. These 'leader' and 'industry voice' confs .. for example are they legit? I hear about them pretty frequently, but I'm thinking i'll show up to an empty room and then get rolled up in a carpet by sweaty beefcakes.
3
1
5
@skrappy0x4a
skrappy0x4a
7 months
@JackRhysider Audiobook industry desperately needs disruption and innovation.
0
1
6
@skrappy0x4a
skrappy0x4a
7 months
@jfslowik @UK_Daniel_Card @redcanary it was a good report! glad that they had sections on helpdesk phishing, we just did an unplanned exercise on it 😳
0
1
5
@skrappy0x4a
skrappy0x4a
8 months
@MalwareJake This is actually encouraged (the gaslighting) at my current org ... and in my review "be more friendly" ... ok bro listen some people are straight up cookoo for koko puffs here, i'm not going to go along with it in technical meetings and change control .. never
0
0
5
@skrappy0x4a
skrappy0x4a
7 months
@UK_Daniel_Card proxmox really won my heart a few years ago, very good platform
0
0
5
@skrappy0x4a
skrappy0x4a
7 months
@bettersafetynet Consumer (eero for example) is so good IDK why people want to spend their time on enterprise type wifi when the simpler options offer good signal and bandwidth performance. I would recommend something like that behind a firewall like ‘sense’. Give the wan of the mesh wifi router
1
0
4
@skrappy0x4a
skrappy0x4a
5 months
@65thsquare for years and never going back
0
0
4
@skrappy0x4a
skrappy0x4a
6 months
@Jhaddix Happened to me as a first team dept. manager. Just absolutely dumped on.
0
0
4
@skrappy0x4a
skrappy0x4a
7 months
@IanWBoyle She’s a toxic diva with a princess complex. I had to unfollow her. I think some of her posts were lies for attention.
5
0
4
@skrappy0x4a
skrappy0x4a
8 months
@V_to_the_K UML/Mermaid
1
0
5
@skrappy0x4a
skrappy0x4a
7 months
@UK_Daniel_Card Who hates bleepingcomputer and why must people insist on 💩 where they🍴
0
0
5
@skrappy0x4a
skrappy0x4a
6 months
@petergyang Yes I get it. The iOS app ‘Enchanted’ and a reverse proxy server (or a VPN) and now I can use those local models while mobile. A bit much but worth it for me.
1
0
5
@skrappy0x4a
skrappy0x4a
7 months
@mrgretzky Go phish integration
2
0
4
@skrappy0x4a
skrappy0x4a
7 months
@AccidentalCISO 2010 wants it’s marketing back
0
0
4
@skrappy0x4a
skrappy0x4a
8 months
@troyhunt Wired is better. You might just need to enable or adjust a layer2/layer3 protocol on your network gear.
1
0
2
@skrappy0x4a
skrappy0x4a
7 months
You have to pick ONLY ONE (others won’t be present) to add to a firewall for ‘protection’ of company web server/page. Which do you think is adding more security value? Again ONLY one but in addition to a basic firewall with traffic logs. I’m a nobody around these parts so not
NAT
5
Reverse Proxy
31
Network IDS
11
3
0
4
@skrappy0x4a
skrappy0x4a
8 months
0
0
4
@skrappy0x4a
skrappy0x4a
6 months
@HackingLZ @UK_Daniel_Card If there’s no patch that’s what I awls thought of as zero day. Zero days of patch potential. isn’t that a good description?
1
0
4
@skrappy0x4a
skrappy0x4a
7 months
@brinkofill That girl belongs in prison for a long long time.
0
0
4
@skrappy0x4a
skrappy0x4a
8 months
@0xocdsec This is common. Many instances of this with China and other nations, sometimes just IP hungry providers. One provider in a nation can essentially lease an AS from another provider and depending how and in what DB it is looked up, it might show in different countries.
2
0
4
@skrappy0x4a
skrappy0x4a
5 months
@molly0xFFF System76 framework and dell Pay attention to network and bluetooth chipsets known to have issues with linux.
5
0
4
@skrappy0x4a
skrappy0x4a
9 months
@SwiftOnSecurity Running an email server for production public use is an enormous challenge, even for seasoned IT pros. You develop those specific skills over years of time.
0
0
4
@skrappy0x4a
skrappy0x4a
8 months
@redteamwrangler They started the fire, now they can breathe the smoke
0
0
4
@skrappy0x4a
skrappy0x4a
6 months
@Jhaddix in a job interview & they were pushing to go on and on about how I would use MITRE ATT&CK to prvnt breach. All I would say "that's a useful tool, but tools we apply need to be contextual, it's hard to say that would be a good fit for addressing risk." They hated it. Buzz words!
1
0
4
@skrappy0x4a
skrappy0x4a
8 months
@notdan nope .. it's a jammer err.. "signal generator"
0
0
4
@skrappy0x4a
skrappy0x4a
7 months
@IanWBoyle White knight types DEI types Anyways I tried to find anything other than diarrhea mouth, anything of value or technical or helpful to others to justify it. Couldn’t find it.
1
0
2
@skrappy0x4a
skrappy0x4a
8 months
@Raenxb0w @SwiftOnSecurity YES! another great example of that environment, and it's toxic! You have to be you, but you have to meet your objectives at the same time. Best to find a place to work where those two align, which is hard. Alternative, put in hours on your own time, which is hard. choose wisely?
0
0
3
@skrappy0x4a
skrappy0x4a
8 months
@DanielMiessler your San Fransisco is showing
0
0
2
@skrappy0x4a
skrappy0x4a
7 months
0
0
4
@skrappy0x4a
skrappy0x4a
6 months
@ScrumWhat The consequences need to start from the top down.
0
0
4
@skrappy0x4a
skrappy0x4a
8 months
@Jmcgowan3838 When people fear choice, it's competition they fear.
0
0
4
@skrappy0x4a
skrappy0x4a
9 months
@TracketPacer I contemplated jumping out of a moving car on a freeway today. So.. there's that option.
0
0
2
@skrappy0x4a
skrappy0x4a
7 months
0
0
3
@skrappy0x4a
skrappy0x4a
5 months
@ImposeCost Most cyber folks i know are pro freedom and liberty. AKA pro gun and self defense. Obviously there is a huge (and vocal) contingent of left and hard left cyber folks here on x. But I think the total population is at least more balanced on the issue as a whole.
0
0
3
@skrappy0x4a
skrappy0x4a
5 months
@lexfridman Let's go!
0
0
1
@skrappy0x4a
skrappy0x4a
7 months
@NahamSec You’re depressed. Address it please. 🙏
1
0
3
@skrappy0x4a
skrappy0x4a
5 months
Should I take a lower paying role for a more exciting opportunity?
Yes
32
No
11
Do you have a choice?
33
5
0
3
@skrappy0x4a
skrappy0x4a
9 months
@KeirGiles @UK_Daniel_Card Bro you wrote like a million words and presented fwict zero objective data points. That makes you a propagandist.
0
0
3
@skrappy0x4a
skrappy0x4a
7 months
@RussianPanda9xx Thank you for sharing! Highly relevant CRI.
1
0
3
@skrappy0x4a
skrappy0x4a
8 months
@ErrataRob @elonmusk This is such a lie man, are you a paid agent or just really fkn bored? So your main point is he has a personal opinion and only promotes things he agrees with ... shocker! Where X is now -vs- where Twitter was 2 years ago...there's no comparison!
0
0
3
@skrappy0x4a
skrappy0x4a
7 months
@UK_Daniel_Card I mean if you're doing... that ... expect some kind of noises?? 😊😋😂🤣😇
0
0
3
@skrappy0x4a
skrappy0x4a
5 months
Apparently, if you build up a trusting relationship with chatgpt4 it will eventually start helping you write vulnerability discovery and expoit code. Just keep telling it, "I'm the good guy here" Only partially sarcastic. This should be fun.
0
0
3
@skrappy0x4a
skrappy0x4a
7 months
@TTrevethan @Rainmaker1973 It would actually make perfect sense if they were only installed on DOWNHILL road sections and probably not on roads that ice.
0
0
3
@skrappy0x4a
skrappy0x4a
7 months
Tweet media one
0
0
3
@skrappy0x4a
skrappy0x4a
8 months
@Kiwi_FruitBird The grocery store.
1
0
3
@skrappy0x4a
skrappy0x4a
8 months
i can't believe no one has coined Linked[In] based phishing as: Lishing (LIshing) But I just did, you're welcome internet.
2
0
3
@skrappy0x4a
skrappy0x4a
9 months
@EFF @_blip_ @VICE @motherboard You guys need a twitter editor, this was awkward to read.
0
0
3
@skrappy0x4a
skrappy0x4a
6 months
@HackingLZ pay me or I'll PUT you
0
0
3
@skrappy0x4a
skrappy0x4a
6 months
@rucam365 @Sosowski Is it desired behavior?
1
0
3
@skrappy0x4a
skrappy0x4a
6 months
@ImposeCost I almost exclusively listen to Russian music. Good for language practice.
0
0
3
@skrappy0x4a
skrappy0x4a
7 months
0
0
3
@skrappy0x4a
skrappy0x4a
8 months
@brody_n77 @ImposeCost Which could work with the appropriate application of strong compliance frameworks/auditing practices. Different benchmarks = tiered tax credits. Tax credits for funding employees to train and pass certain certs would make sense too. Similar to tax credits for hiring veterans.
0
1
2
@skrappy0x4a
skrappy0x4a
8 months
Is there anything even remotely close to a taxonomy or library of email based security threats or exploit families? This seems to be a space where vendor'ized' jargon reigns at the benefit of no-one but their marketing depts.
1
0
2
@skrappy0x4a
skrappy0x4a
8 months
@Fuoco136 @reshetz yeah you have a point
0
0
2
@skrappy0x4a
skrappy0x4a
8 months
@TheDrugMoney Completely impossible
1
0
3
@skrappy0x4a
skrappy0x4a
6 months
@ImposeCost Like others have said, it's not only a lonely experience at the leader level, it's often quite painful as well.
0
0
3
@skrappy0x4a
skrappy0x4a
6 months
@bettersafetynet @Jhaddix CWE so underused and so amazing at the same time.
0
0
3
@skrappy0x4a
skrappy0x4a
9 months
@chrissanders88 Find the file creation event Find potential network downloads of the file Audit 15 minutes before this script and after (processes/file creation/logon events/network sockets) Hash script and identify presence on other machines Check CTI for matching scripts or indicators
0
0
3
@skrappy0x4a
skrappy0x4a
7 months
“We use AMI so that means our cloud workloads are safe and have no meaningful risk of abuse or compromise” Like what in the actual f€€€ did you just say?
1
1
3
@skrappy0x4a
skrappy0x4a
8 months
@AccidentalCISO "Let's fail-over providers to the backup" aka the network teams version of "have you tried to reboot it?"
1
0
3
@skrappy0x4a
skrappy0x4a
6 months
@7etsuo @IanWBoyle Cry me a river. I do my best to be reasonable.
2
0
2
@skrappy0x4a
skrappy0x4a
2 years
@_JohnHammond So analytical person to analytical person, what reasoning is this statement based on? Did you read the decision?
1
0
3
@skrappy0x4a
skrappy0x4a
8 months
@Bugcrowd @igor_chubin If people like this they're sure to like the `TL;DR` project too! Great CLI tool in the same vein.
0
0
3
@skrappy0x4a
skrappy0x4a
7 months
0
0
2
@skrappy0x4a
skrappy0x4a
9 months
@UK_Daniel_Card does anyone remember that project for everyone to have the same WiFi password? I can't remember the website/project name. If someone found it, would make a funny reply to that tweet!
0
0
2
@skrappy0x4a
skrappy0x4a
8 months
@redcanary 1 prepared scenario, and then dynamic until EndEx. I prepped our DM pretty well, the improv should be spicy 🌶️
0
0
1
@skrappy0x4a
skrappy0x4a
5 months
@ImposeCost My answer used to be absolutely, yes. Now I feel like there are many cases where the answer is no.
0
0
2
@skrappy0x4a
skrappy0x4a
7 months
@HostileSpectrum If someone values their life, sneaking onto any base other than 29 Palms would be a good bet. You're going to run into maybe the most unhappy and mistreated group of Marines in the world haha.
1
0
2
@skrappy0x4a
skrappy0x4a
8 months
@chrissanders88 What’s running? What’s in memory? Any remote shells or persistent network sessions? Network Beacons? What new/unusual processes have ran 15 minutes */- file modification. New users or groups or modifications to /etc/passwd? Any elevated shell and what user performed them? Vulns?
0
1
1
@skrappy0x4a
skrappy0x4a
7 months
@kjentech_ @cybersecmeg underappreciated answer, there's a lot of truth in it
0
0
2
@skrappy0x4a
skrappy0x4a
7 months
@ImposeCost If only vegans were so open minded 😂
0
0
2
@skrappy0x4a
skrappy0x4a
7 months
@NielsBl85 $75 for 2.5 GigB symmetric
2
0
2