Welp, I was directly rejected for The Masters. I’ve been there twice and it was the best time ever. How’s everyone else looking?
Chris Truncer
@christruncer.bsky.social
Deputy Chief Red Team @ CISA && BJJ && Open Source Dev
Scarface movie said he would buy a $550 suit to look real nice. That would be nice.
I love it when I get a letter saying some information was likely taken in a breach by a company I never shared my data with or worked with. Great that all these companies just share with each other and then get owned.
Man, I try to watch the World Cup every time it starts. The amount of flopping and faking penalties kills me and just makes me continue to not be able to stand the sport. It’s miserable. The faking everything just sucks. Don’t even get me started about tie games.
People who still use sourceforge for hosting code /binaries might be the same people still using MySpace
There are other offensive services CISA does and there are other openings. But this one specifically is for red team, and we are every sense of that, an actual red team. We don’t do pen tests, mobile app reviews, etc. It’s one of the coolest missions you could join.
You interested in hacking and want to red team the government? CISA’s red team has an opening! Our assessments are typically 90 days and we’re performing actual red team work here. Check out the opening, and let me know if you have any questions! usajobs.gov/job/871378500
Our assessments last typically around 90 days. We get dev time to build out our tools to help ensure success on our assessments. We build our labs to model exactly what we are testing prior to prod. We don’t just take every “customer”, we can and do say no. The team is solid.
You interested in hacking and want to red team the government? CISA’s red team has an opening! Our assessments are typically 90 days and we’re performing actual red team work here. Check out the opening, and let me know if you have any questions! usajobs.gov/job/871378500
Figure I’d give more info. Our red team is a small team, but we target the entire federal government. We can also go after state, local, territorial, tribal, and critical infrastructure. Tired of everything being scoped out? We require everything is in scope.
You interested in hacking and want to red team the government? CISA’s red team has an opening! Our assessments are typically 90 days and we’re performing actual red team work here. Check out the opening, and let me know if you have any questions! usajobs.gov/job/871378500
You interested in hacking and want to red team the government? CISA’s red team has an opening! Our assessments are typically 90 days and we’re performing actual red team work here. Check out the opening, and let me know if you have any questions! usajobs.gov/job/871378500
Offensive Cybersecurity Operator
This announcement is issued under the Direct Hire Authority (DHA) to recruit for positions for which there is a critical hiring need. Selectee(s) will receive a career or career-conditional appointmen...
usajobs.gov
I might be out of the loop, but sounds like ever since Nate Warfield left MSRC things have been rough (purely based on stories posted). We also don’t hear the inside story, so I’m sure there are two sides, but I really hope there’s some compelling info.
Hell yes, the Avs beat the Wild! What an amazing game to go see!
I cannot wait for this Strickland and Chimaev fight. The Avs lost, sad day, but now this fight should be solid. I think Strickland is losing, but I hope he wins.
I love what @PrivacyHQ does allowing you to generate one off credit cards. But I really wish they let you fund it without tying a bank account as the only source. Keeps me from diving in with it.
Man, I love Makar and MacKinnon, but boy did Makar make USA sweat after making that goal to tie it up, along with all the shots Canada had, including Toews.
Woke up early to get to watch Team USA win hockey gold. Such an amazing thing to see, I am so pumped. First time since 1980!
To go off my previous post. I think testing AI is more than valid security testing. But in my mind red teaming is about testing defenders, detections, and improving response. When targeting AI, that isn’t it. It’s not red teaming. But I’m open to different opinions.
So, question if the day from me. Can you “red team” AI? I’ve seen groups and people state that they red team AI. Is it more prompt injection? Are you actively helping defenders build and scale their defenses or test their responses? Is this more a pen test vs real red team?
There are other ways to setup your system for telemetry if you are looking to see what can avoid detection. But if you want to test your latest hotness against prevention of code execution, definitely test it against WDAC. Find something that gets around it? Now that’s useful.
WDAC will block everything you don’t trust, even to the point you could theoretically end up boot looping your Windows box if you’re trying to load untrusted drivers, or drivers you didn’t actually allow that you need. Ask me how I know….
Since a lot of talk I’m seeing lately is about good defenses, especially for initial access, I’ve been preaching the good news about WDAC (formerly my fav name of Device Guard) for a while. I think a properly set up WDAC is the bar which to test access - youtu.be/sWjhuVsSEks?...
SAINTCON 2018 - Chris Truncer - Introducing Effective Controls in your Environment with Windows Defe
Title: Introducing Effective Controls in your Environment with Windows Defender Application Control Speaker: Chris Truncer Conference: SAINTCON 2018 Location: Track 1 Date: 2018-09-26 Time: 10:00am…
youtu.be
Loving the start of my day with an email from @ISC2 saying they are auditing submission that I uploaded (with a screenshot), for a total of 1 credit hour. ¯\_(ツ)_/¯ Enjoy
Oh great, looks like a ton of data from a Wired breach just was published.
I’ve had zero clue there was even a heisman race this year
I’ve not been at gyms before where they give stripes, so this is a first, typically just belts. But I’m now a one stripe brown belt in jiu jitsu. I plenty of rolls after. And a good day
I assume a lot of people have been playing with it, but I love testing and using @tailscale. It’s been nice being able to set up a private network, and love the wireguard usage overall. Anyone using it for anything niche or cool?
Man, 3 rounds in and Schevchenko is dominating this fight so far.
My kid just asked me if dishwashers were around when I was a kid. What the f
Why is isc2.org asking to know my location just when going to their main website? That’s absolutely unnecessary.