Chris Bisnett Profile Banner
Chris Bisnett Profile
Chris Bisnett

@chrisbisnett

1,624
Followers
302
Following
144
Media
1,984
Statuses

Cofounder & CTO @huntresslabs , PostgreSQL fanboy, Rails junkie, Former: security researcher, @Blackhatevents trainer Fediverse: @chrisbisnett @infosec .exchange

USA
Joined July 2011
Don't wanna be here? Send us removal request.
@chrisbisnett
Chris Bisnett
3 years
I vote we rename #PrintNightmare to Schrödingers Patch - since this vulnerability appears to be both patched and not patched at the same time
2
32
129
@chrisbisnett
Chris Bisnett
7 years
Microsoft wrote an article about some of the research @KyleHanslovan and I presented. Credit @hasherezade & @subTee
2
61
98
@chrisbisnett
Chris Bisnett
11 months
We're starting to see the results of Microsoft extending 365 audit logging to everyone with increased retention. This morning we started receiving events that were created in March #Microsoft365 #Security
0
6
51
@chrisbisnett
Chris Bisnett
8 years
Want a free Binary Ninja license? Register for my Fuzzing For Vulnerabilities course:
Tweet media one
0
35
48
@chrisbisnett
Chris Bisnett
4 months
Why do we push so hard for small incremental improvements when it comes to code, but small improvements to other things are seen as “less than nothing”? Nothing transforms overnight. It’s always the small changes over time that finally result in real change
@dhh
DHH
4 months
"Changing master to main changed less than nothing. Because nothing was or is ever enough in this arena. As soon as this word battle was won, it was just on to the next and the next (and the next)."
265
208
2K
14
0
38
@chrisbisnett
Chris Bisnett
8 years
Anyone interested in taking my Fuzzing For Vulnerabilities class in October in Maryland? Pls RT. #infosec
4
22
33
@chrisbisnett
Chris Bisnett
9 months
I like Scrum and the idea of breaking down large complex problems into smaller pieces, but it’s funny to think of that process like this. I think this can result in engineers not being able to see the big picture. Credit @rjs
Tweet media one
1
5
27
@chrisbisnett
Chris Bisnett
7 years
Looks like @KyleHanslovan and my talk, Evading Autoruns can be found in todays @derbycon track 1 stream: #DerbyCon
0
11
24
@chrisbisnett
Chris Bisnett
2 years
What about 21bn in 163 days 😏
Tweet media one
@getajobmike
Mike Perham
2 years
If I ran for President: "my fellow americans, let me tell you about my plan for one billion jobs."
6
0
82
0
3
23
@chrisbisnett
Chris Bisnett
7 years
The first day of Fuzzing For Vulnerabilities and students are already killing it
Tweet media one
Tweet media two
2
7
20
@chrisbisnett
Chris Bisnett
6 years
This. Workaholics are not heroes! Burnout is real and will be more devastating to your performance than stopping working at a reasonable time #startups #burnout
1
5
19
@chrisbisnett
Chris Bisnett
6 years
Game On! These arrived just in time for next weeks Huntress Summer Summit.
Tweet media one
0
4
15
@chrisbisnett
Chris Bisnett
6 months
Every day I’m impressed at what @ClickHouseDB can do, especially ClickHouse Cloud with its ability to auto-scale. This is going to be a game changer for many use cases
0
1
15
@chrisbisnett
Chris Bisnett
7 years
Just got back from picking up our limited run of @HuntressLabs shirts. Find us at #BlackHat17 if you want one
Tweet media one
Tweet media two
1
4
13
@chrisbisnett
Chris Bisnett
8 years
Some great info on what all the AFL stats mean and how to troubleshoot them. Highly recommend this for anyone interested in AFL #fuzzing
@SecurityTube
Pentester Academy
8 years
[Video] Bsides San Francisco 2016 - Fuzz Smarter, Not Harder (An Afl-Fuzz Primer)
Tweet media one
0
17
45
0
13
12
@chrisbisnett
Chris Bisnett
8 months
I can’t begin to express how proud I am of the team at @HuntressLabs for putting together this report. @KyleHanslovan @jdferrell3 and I have been talking about how awesome it would be to be in a position to post research like this for literal years
@MaxRogers5
Max Rogers
8 months
Welcome to the first Huntress Threat Report 🚨🦸‍♀️ An in-depth review of real world intrusions @ small & mid-sized businesses. Follow @HuntressLabs for more.
Tweet media one
11
84
277
0
2
13
@chrisbisnett
Chris Bisnett
10 months
As a founder, when your team crushes it, it’s your job to reward and motivate them. Our team crushed it and for that, I’m rocking the ShadyCorn onesie.
Tweet media one
0
3
13
@chrisbisnett
Chris Bisnett
5 years
Luck Is What Happens When Preparation Meets Opportunity
@marcusjcarey
Marcus J. Carey
5 years
My boy just sent me a timeless classic quote. I’m paraphrasing here: “The outcome of hard work looks a lot like luck.”
5
53
250
2
5
11
@chrisbisnett
Chris Bisnett
1 year
@ErrataRob @simulator5g @su_andrewk The benefits to their bottom line. I’m not sure if it’s still the same price but a few years ago when they made a big push for new TLDs, the cost to become the registrar for a new TLD was something like $800k
2
0
12
@chrisbisnett
Chris Bisnett
6 years
Why are developers still blocking users from pasting into the confirm password field? This breaks many password managers, especially on mobile, and impacts security negatively because users use shorter, easier to type passwords. Please don’t do this
0
0
11
@chrisbisnett
Chris Bisnett
7 years
Startup idea: Slack but for users with less than 32gb of ram
3
5
12
@chrisbisnett
Chris Bisnett
5 years
We’ve seen the same behavior at @HuntressLabs . One of the hardest parts for most orgs is getting ALL of it. Even one machine that’s infected and powered off can restart the infection days or weeks later when powered on
0
2
10
@chrisbisnett
Chris Bisnett
6 years
Ended my BlackHat trip today with a BOOFUZZ from the bar. How did you manage to get this on the menu @b00fuzz ? #fuzzing
Tweet media one
2
3
11
@chrisbisnett
Chris Bisnett
6 months
How cool is this?! I love that we put in this kind of care for our employee swag before our summit #huntress
Tweet media one
2
3
11
@chrisbisnett
Chris Bisnett
5 months
. @HuntressLabs is all over X and the news and I can’t be more proud of the work this team has put in. It’s really be a big effort by a lot of folks behind the scenes. We’ve got more stuff cooking so watch out for what’s next!
0
3
11
@chrisbisnett
Chris Bisnett
1 year
Last week tragedy struck a Huntress team member. Katie is an amazing person and a friend and she can really use our help right now. Please consider donating to support this family Honoring Kyle's Legacy
3
4
6
@chrisbisnett
Chris Bisnett
6 years
#TrickOrTreat from my kids and the team at @HuntressLabs
Tweet media one
0
2
10
@chrisbisnett
Chris Bisnett
6 years
Tweet media one
0
3
10
@chrisbisnett
Chris Bisnett
6 years
Pair this with the @citusdata blog post on creating statistics manually and you’ve really got something.
@PostgreSQL
PostgreSQL
6 years
Take a look at a new @postgresql extension called "pg_badplan" by Claes Jakobsson and see if it helps you determine if using multicolumn statistics will help improve your query plans.
0
2
15
0
1
8
@chrisbisnett
Chris Bisnett
3 years
When you call a timeout at the perfect time
Tweet media one
0
0
9
@chrisbisnett
Chris Bisnett
2 years
I’ve been conscious of my habit of saying “you guys” to mixed company for a while (it’s a tough habit to break). I often resort to “you all” or “folks”, but today I heard someone say “yoos”
6
0
9
@chrisbisnett
Chris Bisnett
7 years
We're giving everyone who attends Fuzzing For Vulnerabilities a free Binary Ninja license. #BHUSA
0
7
9
@chrisbisnett
Chris Bisnett
8 years
Don't be like Trend Micro. Come to our #fuzzing training and learn to find vulns before shipping code #BHUSA
0
1
7
@chrisbisnett
Chris Bisnett
2 years
The biggest losers of the Uber hack: the nation state actors who have been in the infrastructure for years and will now lose their footholds. If it was this easy for the hacker to own everything, it was already owned by multiple parties
1
0
8
@chrisbisnett
Chris Bisnett
7 years
Here is a preview of my Meltdown research I plan to submit for this years @DerbyCon .
Tweet media one
0
0
9
@chrisbisnett
Chris Bisnett
3 years
If an attack indicator is logged in a SIEM, but nobody sees it, does it matter? The infosec version of “if a tree falls in the woods…”
1
2
9
@chrisbisnett
Chris Bisnett
8 years
I wrote a quick blog post about some of the changes we're making to Fuzzing For Vulnerabilities for #BHUSA this year
1
2
8
@chrisbisnett
Chris Bisnett
4 months
I’ll probably take some flak for this, but my idea of a vacation is one where I don’t have meeting or a schedule and can relax, BUT can still write code and make progress on the product. It’s more like a period of relaxation with better work life balance. It’s not that I feel I
Tweet media one
3
0
8
@chrisbisnett
Chris Bisnett
1 year
This reminds me of the quote “if you’re the smartest person in the room, you’re in the wrong room.” If you really want to grow and get better at something you need to find folks better than you to help you push yourself. Putting in the work is the only way to get better
@BaryonicBeing
Ellicular Galaxy Resident
1 year
Just chatted w/ someone who, a few years ago, started regularly playing foosball w/ a random group of guys at a nearby bar. He started off playing poorly but over time became decent. One day they told him he should play tournaments...
30
737
17K
0
1
8
@chrisbisnett
Chris Bisnett
10 years
You haven't made it in infosec until you write yet another binary analysis framework and ROP gadget finder
1
11
7
@chrisbisnett
Chris Bisnett
5 months
Continuing to make progress on supporting ES|QL queries in the upcoming @HuntressLabs Managed SIEM product. This is going to be quite amazing when combined with the storage and searching of data. I can’t wait to show this off!
Tweet media one
0
1
6
@chrisbisnett
Chris Bisnett
6 years
That’s why they added garbage collection
@AminaKMoon
Amina
6 years
Brushed up on some Java programming skills today...forgot how trashy #java is
0
1
3
0
0
7
@chrisbisnett
Chris Bisnett
3 years
It’s like I’ve seen this bug before ;) @chrisrohlf @yan
@BugsChromium
Chromium Disclosed Security Bugs
3 years
Security: v8 Array.concat IterateElements OOB access leads to RCE (reward: $22000)
0
36
154
0
2
7
@chrisbisnett
Chris Bisnett
2 years
Start with $100k and invest in bitcoin
@electrifying
✨ɐɹo˥ ✨
2 years
real quick, how do i make 50k?
79
2
100
0
1
7
@chrisbisnett
Chris Bisnett
8 years
Want to find QuickTime bugs like the one patched this week? Come to #BHUSA and @KyleHanslovan and I will show you
1
4
7
@chrisbisnett
Chris Bisnett
6 years
I then drew it on my wife’s Cricut Explore Air 2. It’s a pretty cool little machine. I’m going to try and write up my process in a blog post.
0
1
7
@chrisbisnett
Chris Bisnett
10 years
Learn to find vulnerabilities using this one weird trick (fuzzing). I did and now companies hate me! Register at:
2
5
7
@chrisbisnett
Chris Bisnett
5 months
Oh no…it’s me
@stuartjash
Stuart Ashenbrenner 🇺🇸 🇨🇦
5 months
People say, “This meeting could’ve been an email” with 14,000 unread emails in their inbox.
0
3
34
1
0
7
@chrisbisnett
Chris Bisnett
3 months
When raising the first two rounds of funding for @HuntressLabs (2020-2022), I got a number of questions around Rails and PostgreSQL and whether they would be able to scale. I told everyone “it seems to work for @Shopify ” and that was that
@isamlambert
Sam Lambert
3 months
it's wild that people see and acknowledge the incredible success of @Shopify , but actively shun the tech stack that has allowed them to scale, while shipping constantly.
9
6
162
1
0
7
@chrisbisnett
Chris Bisnett
3 years
Gotta support the underground
Tweet media one
0
0
6
@chrisbisnett
Chris Bisnett
8 years
My Fuzzing For Vulnerabilities training w/ @KyleHanslovan on August 1-2 sold out! @BlackHatEvents just opened 4 more seats. Get them quickly
0
3
6
@chrisbisnett
Chris Bisnett
4 months
I’m so tired of having to pay a security tax every time we want to setup single sign-on. We’re only 300 employees and for many services we don’t need the other functionality that comes with the “Enterprise” plan. So we’re paying significantly more just for SSO. 😩
2
1
7
@chrisbisnett
Chris Bisnett
7 years
For reference:
0
1
6
@chrisbisnett
Chris Bisnett
1 year
Occasionally I see comments about how #rails doesn’t scale and I wanted to add some perspective from my experience at @HuntressLabs . We switched to Sidekiq 17 months ago and have already run over 100 billion jobs. This is how we protect 2.3M endpoints and identities
Tweet media one
1
0
6
@chrisbisnett
Chris Bisnett
4 months
@NathanMcNulty The fact that Dmitri was the deputy chair on this and the co-founder of their arch rival CrowdStrike must have really pissed off some folks in the security organization, especially with recommendations like this
2
0
6
@chrisbisnett
Chris Bisnett
7 years
Vulnerable VLC found in the wild at the #BlackHat17 vendor hall. Take our fuzzing course and find the bugs.
Tweet media one
Tweet media two
0
2
6
@chrisbisnett
Chris Bisnett
9 months
This is probably the single greatest slide I’ve ever made. I’m pretty sure I’ve peaked and it’s only downhill from here
@KyleHanslovan
Kyle Hanslovan
9 months
EDR: Using feedback from the community, we're now reporting where users are actively using/accessing password files. Lots of epic feedback received here today and can't wait to roll out today's suggestions.
Tweet media one
1
0
3
0
1
6
@chrisbisnett
Chris Bisnett
6 months
Being a parent means dragging your kids out of bed in the morning because they are so tired and also forcing them to go to bed because they aren’t tired
1
0
4
@chrisbisnett
Chris Bisnett
6 months
@Infosec_Taylor We’re working on this at @HuntressLabs to make this more of an educational experience for folks rather than a negative one. This is the training you get if you click the phishing link. What do you think?
Tweet media one
1
2
4
@chrisbisnett
Chris Bisnett
9 years
Refrigerator refuses to dispense water unless the water filter has a valid RFID tag. Looks like this is the #dystopian future for products
2
5
4
@chrisbisnett
Chris Bisnett
9 months
Lots of people pointing out the SQL injection. It’s even easier than that. Just open developer tools and add a cookie named “login” with the value “1” and you’re money
@Hac10101
Hac
9 months
Can you spot the vulnerability in this code 🔍? #infosec
Tweet media one
87
31
329
1
0
4
@chrisbisnett
Chris Bisnett
6 years
Rails 6 is set to ship with a parallel test executor using either threads or forked processes! Nice work @eileencodes and @tenderlove #rails #railsconf
0
2
5
@chrisbisnett
Chris Bisnett
9 months
He’s not wrong here. Understanding how the technology works and how to build to its strengths requires care. In this age of unlimited cloud resources I see folks reach for the scale lever too quickly and that results in excess cost
@jamonholmgren
Jamon
9 months
The more experienced I get, the less I think that the specific tech matters for performance, and the more I think just … the developer *caring* about performance matters.
26
21
266
0
0
4
@chrisbisnett
Chris Bisnett
4 months
We actually built in some additional visibility for this after the last ScreenConnect incident. We should probably look at sending new ScreenConnect callback domains to the SOC for review
@MaxRogers5
Max Rogers
4 months
🚨 Mass exploitation of FortiClient Enterprise Management Server (EMS) is being observed by @HuntressLabs Post Compromise activity appears to download and execute ScreenConnect on the system. Thank you to Huntress SOC Analyst @bumbucha for raising the flag internally.
7
27
104
1
1
5
@chrisbisnett
Chris Bisnett
7 years
Fuzzing SMB is quite hard. Variable length params, hundreds of diff structures, handles to objects, etc. modeling the spec is a nightmare
@daveaitel
Dave Aitel
7 years
lotta smb fuzzers in the world - all of them missed ETERNALBLUE?
5
2
13
1
3
5
@chrisbisnett
Chris Bisnett
8 years
Free continuous fuzzing for open source projects. This is pretty cool.
0
2
5
@chrisbisnett
Chris Bisnett
7 years
I don't know details in this case but I can confirm VLC is very exploitable from my fuzzing training.
@thegrugq
thaddeus e. grugq
7 years
Sounds like they exploited VLC, and it would be nice to see the affidavit ( @dangoodin001 )
4
17
25
1
0
5
@chrisbisnett
Chris Bisnett
2 months
@JasonSwett 360/12 = 30 degrees between each number. At 15 after the minute hand should be on the three and the hour hand should be 1/4 of the way between the three and the 4. So 30/4 = 7.5 degrees. Is that the answer?
1
0
3
@chrisbisnett
Chris Bisnett
8 years
Well no company wants to admit they got compromised by unsophisticated malware that was there for more than a year
0
4
5
@chrisbisnett
Chris Bisnett
5 years
I’m not a mathematician but the odds of this 2FA code seem really small
Tweet media one
2
0
5
@chrisbisnett
Chris Bisnett
8 months
@nateberkopec Totally agree. The productivity one person can have is immense. One thing I’ve noticed though is that there seems to be junior Rails devs and very senior Rails devs, but a lack of folks in the middle. Any idea why?
2
0
5
@chrisbisnett
Chris Bisnett
4 months
@dhh I’m not suggesting where we draw the line on these kinds of things is easy or obvious, but I am suggesting that many small changes have big results over time. Does the name of the default branch really matter that much? I get it that it can become a death by 1000 cuts, but 🤷‍♂️
5
0
5
@chrisbisnett
Chris Bisnett
2 years
Why does anyone care? I get this is Elon and there are some extra feelings involved, but a degree is a means to an end. If you can learn without needing to go through school that’s fine
@Austen
Austen Allred
2 years
Please mention this as frequently as possible.
Tweet media one
107
44
878
0
1
5
@chrisbisnett
Chris Bisnett
8 years
I really hope more vendors publish known-good binaries like this: . /cc @nvidia @intel
0
2
5
@chrisbisnett
Chris Bisnett
5 years
** Hot Take (mildly hyperbolic) ** Can we get a software engineering version of the bar exam / medical board? So many products are so terribly engineered. Demand has outstripped supply and caused the overall quality of engineers to tank.
2
0
5
@chrisbisnett
Chris Bisnett
4 months
I’m a big advocate of the Always Be Shipping mentality that @denk_tweets wrote about in his essay and @businessbarista discusses in a recent podcast on Founders Journal. Consistently shipping is a huge part of the answer of how you compete in a crowded marketplace
1
2
4
@chrisbisnett
Chris Bisnett
7 years
Sunday afternoon #malware . FML
Tweet media one
1
5
5
@chrisbisnett
Chris Bisnett
2 years
This was my life for several years working for the government. I’m sure this influenced our decision to make @HuntressLabs a very open and transparent culture
@HackingLZ
Justin Elze
2 years
👀
Tweet media one
18
137
1K
0
0
5
@chrisbisnett
Chris Bisnett
8 years
Love the concrete examples of bugs found with AFL+ASAN. RPM and DPKG are the scariest though. #fuzzing #afl
@hanno
hanno
8 years
#QtCon #FSFEsummit talk on American Fuzzy Lop and Address Sanitizer slides (almost same as @BornHax talk)
1
20
27
0
4
5
@chrisbisnett
Chris Bisnett
9 years
Take my Fuzzing For Vulnerabilities course @BlackHatEvents and learn to find bugs like this: http://t.co/lUxlmCOatc #BHASIA #BHUSA #0day
1
2
5
@chrisbisnett
Chris Bisnett
7 years
All the coolest cats I know pronounce WinDBG as "wind bag"
0
0
5
@chrisbisnett
Chris Bisnett
8 months
Scaling a startup sucks because you’re not solving technical or customer problems, you’re solving internal people and process problems and that doesn’t feel like real progress and is not why you started the company 😩
1
1
5
@chrisbisnett
Chris Bisnett
7 years
If you're looking to learn how to fuzz consider our fuzzing training at #BHUSA in July
0
5
5
@chrisbisnett
Chris Bisnett
6 years
A few years ago I was looking for a change in my career and thought about applying to Facebook to see what it was like to engineer massive systems and process lots of data. Boy am I glad I procrastinated on that thought
0
0
5
@chrisbisnett
Chris Bisnett
3 months
This is awesome! I’ve been thinking about doing something similar for those long tail bugs that aren’t showstoppers and so get left at the bottom of the pile
@shortcut
Shortcut
3 months
Shoutout to our Product & Engineering Teams for squashing 176 bugs/paper cuts in our Bug Bash! Awards went out today for: 🐞 Most Bugs Squashed 👏 Customer Team Choice 🗑️ Most Lines of Code Deleted 🧪 Most Tests Added 👀 our Release Notes to view the full list of improvements:
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
0
7
2
0
5
@chrisbisnett
Chris Bisnett
11 months
We’ve been waiting a long time to talk about the Qakbot mitigation we deployed to all Huntress endpoints on Dec 14, 2022. We stopped seeing new Qakbot infections on the hosts we protect and could actively track processes checking for the vaccine with our EDR telemetry. Huge win!
@_JohnHammond
John Hammond
11 months
Quick banter on the FBI Qakbot disruption-- and some behind-the-scenes deets on how we handled Qakbot when it was running rampant. Seriously, huge congratulations to law enforcement and all parties involved!
Tweet media one
3
35
181
0
0
4
@chrisbisnett
Chris Bisnett
4 months
I’ll be over here like the crypt keeper. Good luck getting rid of me. But really, there are some days
@jasonlk
Jason ✨👾SaaStr.AI Sept 10-12✨ Lemkin
3 years
Real founders never quit
63
119
957
1
0
4
@chrisbisnett
Chris Bisnett
3 years
Why would anyone in their right mind do multiple startups? One is punishment enough
0
0
4
@chrisbisnett
Chris Bisnett
7 years
We’re looking for a Senior Rails Engineer at @HuntressLabs to help us accelerate our mission to eradicate malware. AWS, PostgreSQL, Redis stack. Competitive salary - not intern level ;), benefits, equity. Remote or local. careers @huntresslabs .com. Please RT
0
3
4
@chrisbisnett
Chris Bisnett
6 years
Glad you enjoyed it! Get out there and find some bugs
@0x4ndr3
Andre Lima
6 years
Thanks to @chrisbisnett and @KyleHanslovan for a great 2 day course. Definitely inspired by all the knowledge you shared and appreciate all the hard work you put into this. Thank you guys! #fuzzing #BlackHat2018
Tweet media one
0
1
18
0
0
4
@chrisbisnett
Chris Bisnett
7 years
Ok I've been trying to hold back but I can't anymore. WTF happened at Veris Group ATD?! I count at least 6 key employees resigned this week!
1
0
4
@chrisbisnett
Chris Bisnett
2 months
✅ Junior Engineer: I don’t know what tool we should use. I’ll go with whatever gets the job done. ❌ Senior Engineer: We absolutely must use THIS tool because big successful companies use it! ✅ Staff+ Engineer: I don’t care what tool we use as long as it will get the job done
2
0
4
@chrisbisnett
Chris Bisnett
2 years
What a rough week for crypto bros
1
0
4
@chrisbisnett
Chris Bisnett
1 year
I had a great time talking with other Product and Engineering leaders at the @SapphireVC Hypergrowth Engineering Summit today! Thanks to all who gave talks
Tweet media one
0
0
3
@chrisbisnett
Chris Bisnett
7 years
Just booked my ticket to #RailsConf 2018 I've never been, so I'm excited to see and meet new people. If you're a Rails dev and looking for something new, DM me and we can meetup and talk about what we're doing at @HuntressLabs #rails #ruby
0
2
4
@chrisbisnett
Chris Bisnett
8 years
Gate agent in Baltimore just requested anyone with a Samsung Nexus 7 please turn it off
1
3
4
@chrisbisnett
Chris Bisnett
8 years
October fuzzing class is getting some signups. If you want to go from beginner to advanced don't wait to register.
0
4
4