adam_cyber Profile
adam_cyber

@Adam_Cyber

5,890
Followers
406
Following
110
Media
3,114
Statuses

I'm from the Internet and I'm here to help

The Internet
Joined April 2009
Don't wanna be here? Send us removal request.
@Adam_Cyber
adam_cyber
11 months
There are a lot of hacktivist groups and known adversaries engaged in the cyber conflict around the #IsraelPalestineConflict . @CrowdStrike pulled together a graphic to highlight some of what we're seeing.
Tweet media one
25
373
894
@Adam_Cyber
adam_cyber
3 years
@CrowdStrike has identified exploitation of #log4j vulnerability by threat actors that more closely resembles targeted intrusion consistent with advanced attackers, such as deploying web shells and conducting lateral movement.
5
67
231
@Adam_Cyber
adam_cyber
1 year
I am very excited to publicly unveil our new @CrowdStrike Counter Adversary Operations! Consolidating our market leading Threat Intelligence and game changing OverWatch Threat Hunting teams into a new entity charged with raising the cost for adversaries!
1
31
126
@Adam_Cyber
adam_cyber
3 years
@CrowdStrike has identified a malicious Java class file hosted on infra associated with a nation state adversary. The Java code is used to download known instances of adversary specific tooling and is likely to be used in conjunction with the recently disclosed #log4j issue.
2
36
120
@Adam_Cyber
adam_cyber
2 years
#threatintel in cars with @JohnHultquist - @CrowdStrike and @Mandiant carpooling and keeping that carbon footprint low
Tweet media one
10
3
123
@Adam_Cyber
adam_cyber
1 year
Does Scattered Spider seem to be everywhere? The scope of their intrusions since March 2022 from a @CrowdStrike perspective is pretty broad. They use social engineering, living off the land, and RMM tools before deploying ransomware or conducting extortion.
Tweet media one
3
40
118
@Adam_Cyber
adam_cyber
2 years
Very excited to release the @CrowdStrike 2023 Global Threat Report today - get it here: See key insights into adversary behavior in 2022 and how the threat is evolving including data weaponization, cloud targeting, and more!
0
29
103
@Adam_Cyber
adam_cyber
1 month
As we work with customers and partners to get systems fully restored, we are seeing threat actors try to take advantage of the situation. Here is intel on what we have seen related to the issues today:
2
58
102
@Adam_Cyber
adam_cyber
3 years
In addition to the blog we published () here is a timeline graphic we hope will be helpful in illustrating the years of offensive #cyber operations against #Ukraine by #VoodooBear
Tweet media one
3
45
93
@Adam_Cyber
adam_cyber
26 days
Excited to announce the launch of the @CrowdStrike 2024 Threat Hunting Report - it contains insights from the last year by our Overwatch team. Details the increase in targeting of Healthcare by ecriminals, exposes Famous Chollima, and more!
0
20
73
@Adam_Cyber
adam_cyber
19 days
If you haven’t had a chance to read the @CrowdStrike Threat Hunting Report yet, I've got you covered! I will be providing a quick overview of the report along with a deep dive into an insider threat you may not have heard of we call famous chollima.
0
10
61
@Adam_Cyber
adam_cyber
5 months
The CSRB findings from the summer 2023 breach of Microsoft are both alarming and confirm many of the concerns I've voiced about the risk of overreliance on their products. @Microsoft is a national security threat and it's time to take it seriously! 🧵
1
22
61
@Adam_Cyber
adam_cyber
24 days
Detailed blog regarding kernel access and security architecture, hopefully this helps dispel some common misinterpretations about kernel access, specifically regarding the architecture of the Falcon sensor:
1
13
59
@Adam_Cyber
adam_cyber
10 years
Overlap in Silent Chollima (DPRK) malware with spelling error #Secruity http://t.co/BHHZOGeiMR
Tweet media one
6
62
51
@Adam_Cyber
adam_cyber
8 years
On the left is the legitimate д-30 app mentioned in @CrowdStrike report, on the right is the one manipulated by fancy bear.
Tweet media one
3
48
52
@Adam_Cyber
adam_cyber
2 years
In light of todays announcement - I’ll reshare this tweet @JohnHultquist
@Adam_Cyber
adam_cyber
6 years
Tweet media one
3
1
28
1
4
49
@Adam_Cyber
adam_cyber
7 months
@vxunderground @CrowdStrike Scattered Spider, Aquatic Panda, Nemesis Kitten, and Labyrinth Chollima
1
1
48
@Adam_Cyber
adam_cyber
6 years
@CrowdStrike and @FireEye lowering our carbon footprint by car pooling!
Tweet media one
8
3
46
@Adam_Cyber
adam_cyber
3 years
I never thought I could dislike Java more than I did in college… But here I am 20 years later, up for multiple nights… cramming
2
1
42
@Adam_Cyber
adam_cyber
8 years
On the left are strings from FANCY BEAR linux implant, on the right are strings from the Android implant used against Ukraine military
Tweet media one
6
43
42
@Adam_Cyber
adam_cyber
6 years
If you are a researcher looking for a challenging and fun environment to fight bad guys @CrowdStrike Intelligence has a few positions open: #ThreatIntel #Cybersecurity
0
24
37
@Adam_Cyber
adam_cyber
8 years
FAQ slide from @CrowdStrike presentation on FANCY BEAR X-Agent for Android that @DAlperovitch and I just wrapped up
Tweet media one
4
34
35
@Adam_Cyber
adam_cyber
25 days
Setting the record straight regarding alleged vulnerabilities related to the channel file issue, bottom line: there is no mechanism to write to arbitrary memory addresses or control program execution, and we use cert pinning to mitigate MitM
0
13
36
@Adam_Cyber
adam_cyber
1 year
The disruption of Snake malware, which CrowdStrike attributes to Russia-nexus adversary VENOMOUS BEAR, is a huge win for the U.S. & NATO against FSB’s Center 16. Operation MEDUSA highlights the importance of public/private collaboration to take down sophisticated adversaries.
0
7
36
@Adam_Cyber
adam_cyber
6 years
Awesome work by the @crowdstrike Intelligence eCrime Team! #ransomware
0
21
29
@Adam_Cyber
adam_cyber
7 years
This keynote by Cliff Stoll from @CrowdStrike Fal.Con was truly entertaining -
0
11
30
@Adam_Cyber
adam_cyber
6 years
This week on #threatintelincars @CrowdStrike @FireEye discuss attribution
Tweet media one
3
1
28
@Adam_Cyber
adam_cyber
11 years
Interesting code injection technique using a window handle: http://t.co/vUwgvSIlRu by @CrowdStrike Intel's Chris Dietrich
1
36
28
@Adam_Cyber
adam_cyber
9 years
http://t.co/sWtEfAfPmB - Great reversing by Chris Dietrich & nice comments on challenges faced by analysts balancing between intel and RE
0
17
25
@Adam_Cyber
adam_cyber
6 years
@CrowdStrike Intelligence analysis following the interesting posts by @intrusion_truth on STONE PANDA -
0
18
23
@Adam_Cyber
adam_cyber
6 years
Best conference swag ever!
Tweet media one
3
5
23
@Adam_Cyber
adam_cyber
9 months
While I am always happy to speak on what @CrowdStrike is seeing with regards to DPRK offensive cyber activity - this appears to be Velvet Chollima targeting folks. Stay safe out there!
Tweet media one
1
4
23
@Adam_Cyber
adam_cyber
5 years
Katie From @CrowdStrike Intel briefing on Chollima actors at #CYBERWARCON
Tweet media one
0
5
22
@Adam_Cyber
adam_cyber
8 years
@WifeBuey @CrowdStrike fun fact fancy bear named because sofacy malware name reminded analyst of iggy azalea song
3
15
17
@Adam_Cyber
adam_cyber
2 years
@JohnHultquist things escalated quickly
Tweet media one
2
1
19
@Adam_Cyber
adam_cyber
2 years
@JohnHultquist and I have the #threatintel uniform dialed in!
Tweet media one
4
2
17
@Adam_Cyber
adam_cyber
8 years
Announcing a new defense oriented conference - - limited space, cfp now open!
0
7
16
@Adam_Cyber
adam_cyber
3 years
Just gonna leave this here:
1
0
16
@Adam_Cyber
adam_cyber
8 years
So disappointed in the infosec community and capacity for original thought... Smh
2
3
16
@Adam_Cyber
adam_cyber
2 years
@RidT Mila - Contagio Malware Dump
2
0
15
@Adam_Cyber
adam_cyber
5 months
"The Board concludes that Microsoft’s security culture was inadequate." This is a pattern - SunBurst (2020), Lap$us(2022), Storm-0558 (2023), and Cozy Bear (2024) - Microsoft is a national security risk, security is a team sport, when are we putting them on the bench?
0
3
15
@Adam_Cyber
adam_cyber
5 months
"Microsoft acquired a company called Affirmed Networks" ... "Microsoft believes that prior to the acquisition, Storm-0558 targeted an engineer and compromised their device" - Onboarding risk is a huge issue - M&A needs to incorporate compromise assessments as part of DD
1
3
15
@Adam_Cyber
adam_cyber
2 years
@CrowdStrike is excited to be part of JCDC’s new ICS initiative to help empower security teams with actionable knowledge and insights to detect and deter cyberattacks across their operational technology
0
2
14
@Adam_Cyber
adam_cyber
1 month
We’ve published another intelligence alert on threat actors using the disruption last week, this time attempting to deploy lumma stealer:
0
10
14
@Adam_Cyber
adam_cyber
3 years
The @CrowdStrike 2022 global threat report is out! Read about the 82% increase in #ransomwareattack related data leaks we observed in 2021:
0
4
13
@Adam_Cyber
adam_cyber
8 years
Tweet media one
2
2
12
@Adam_Cyber
adam_cyber
4 years
Ways to spot information ops on twitter: 1) look at tweet rate 2) look at account age 3) look at likes/retweets 4) look at description versus beliefs 5) look at operating times - if they say they are a retired cop and they resigned that day might be info op
0
3
12
@Adam_Cyber
adam_cyber
8 years
Come see some new research I've been doing to track down adversaries using natural language tools: #rsac
2
6
11
@Adam_Cyber
adam_cyber
6 months
Looking forward to this!!!
@SLEUTHCON
SLEUTHCON
6 months
SLEUTHCON is coming!!! Registration and CFP are now open for this year's SLEUTHCON! This year's keynote will be given by Bryan Vorndran, FBI's Assistant Director Cyber Division. We are virtual and in-person in Arlington, VA on May 24th! 1/x
4
53
109
1
2
12
@Adam_Cyber
adam_cyber
1 year
0
0
11
@Adam_Cyber
adam_cyber
10 years
Amy Adams just gave first class seat to a US Army Sergeant - classy move!!
0
5
10
@Adam_Cyber
adam_cyber
5 years
My every day...
@_LittleBobby_
Little Bobby
5 years
Threat Intelligence Mileage May Vary |
Tweet media one
2
43
117
2
1
11
@Adam_Cyber
adam_cyber
7 years
@JohnHultquist working hard on a tweet - standby
Tweet media one
4
1
11