#general
1 messages · Page 1254 of 1
I will gladly run around in shorts and vest when it's -4°C
Much better
New flare-Vm update looks nice, even tells you when the Vm has an internet connection. 👀
guys i wan a win 11 iso img to try hack it in vm
Download it?
link ?
you guys participating in the industrial intrusion CTF?
Perchance.
like any of you?
You can't just say perchance
Scrubz goin undercover
I wonder if Team-awesome would like to enter a team 👀
Perchance
Were you jumping up and down from excitement when you took the photo? 🤣
looks like it
Actually I was lmfao
Good job Matt
Omfg
it's a decently sized one as well
Omg, my reel couldn't even bring it in, had to tension it to max
Yes
what is a starboard?
ahh, cool
hy everyone i need your help i have a news about 16 billion pass leak is it true
Apparently not just from one hack
but is it true
My eyelid broke... fml
No, it's old.
You're fine.
All hail VTX Underground.
No.
It's a collection of old dumps pasted together, with a new shiny sticker.
So there's 123456 and stuff like that among them?
I would not be surprised.

Always wonder if checking on haveibeenpwned.com causes your pw to be leaked
Iow can they be trusted
👀

so how much is leaked in latest leak
about 16bn
Pretty chill amount
small leak
You don't enter your password?
And if you do, you're stupid.
To be perfectly blunt. 
Never done it
Good.
But I worked at a CA where we would implement an API where a customers password would be checked at haveineenpwned
Are you sure they don't just check the E-mail/phone number?

Because haveibeenpwned doesn't have a password entry.
It has
Oh ffs

Do you want hacked? Because that's how you get hacked
Right
Would anyone like a free month of ExitLag, whatever that is? It’s my nitro gift
Do you wants hacks
Thats how you get hacked
Lol
Minecraft ppl downloadin hacks lol
Free RAM upgrade installation wizard
Exitlag is a application helps cut down lag for gamers.
Oh I have no use for that shiz
i usually just download some
Smart guy. Typically you can’t get malware just by downloading, only on execution. You’re hired!
0clicks are a thing
Which rely on vulnerabilities, it’s why I said typically
Hm
Opensrc exists
Hm
Epic
True but you don't know if the malware uses it or not
And usually if it's abusing a zero click you won't know until after the fact
I.e. Stuxnet
I know if there’s vulnerabilities on my device or not. That’s what automated patching is for!
Patches only patch what's known
You can't patch things that are unknown
Better to not be ignorant about it and just Not Take The Risk
That’s why defence in depth is important
It only goes so far
I’m pretty sure MDE scans downloaded items before execution
Nothing can detect everything
As soon as it’s written to disk
Fully Undetectable exist
The best malware work off being undetectable by AVs, only working in memory, and leveraging things that haven't been patched
Which also lacks realism for most users and in most enterprises lmao
In fact it's quite a common method for attacking enterprise infra
And most users are too unaware to know better
just dropping in and wishing everyone a good Midsummer Eve if that's something you celebrate..here in Sweden it's a holiday...have a good time!!
I’m not saying they don’t exist but as a SOC Analyst I’ve never seen one
They aren’t common
Interview was awesome. Marketing people of THM are so kind and cheerful.
If they’re common for your users then that’s a problem lol
You overestimate how much sense users have
Yoooo
Epic
@knotty valve are you doing Malta ctf tomorrow?
That doesn’t justify it you can’t shift the blame to the end users, they don’t know any better lol. I don’t trust them at all, but I think you also underestimate the capabilities of today’s technology that’s available
Evading EDR explains about windows ELAM drivers. A week after I read it crowd strike went down globally because of their ELAM driver
I don't underestimate it cause I see malware Devs take lengths to make sure their malware is undetected
AVs aren't this bullet proof application that can stop everything
They can't and won't be because you can always find a way around it, if you could detect everything and stop anything then red team would be obsolete
Can confirm.
Cat and mouse right
Cyber in a nutshell
Even if it is uncommon, it's still best practice to advise users not to download sketchy things, even if they don't plan on executing it
It's An arms race
Something that worked in 2021 probably doesn't now
Like if I took the time to, I could write a malware to leverage unpatched vulns, use timed staging, and only operate in memory, and it would defeat an antivirus
And if I can, as a blue team, so can a hacker
That’s a bold statement. Not all products work the same. Labelling all solutions as an “EV” is short-sighting
What do you do @knotty valve ?
Security Engineering
Traditional AV’s, sure
Specialising specifically in network communications
This discussion is borderline #advanced-general
So writing code for detecting network "malware"
lol
Thanks
Didn't know that chan existed
peak performance
Why not 50?
I should do more on THM but too busy on other certs atm
i usually do only 1-3 ctf rooms a day
not like walkthrough rooms but today did
Advent of Cyber probably has 50 questions alone.
The certs listed are for offensive/pentester certs. Do you accept any defensive ones
Unfortunatly, we only accept what is listed.
and Sal1 and PT1.
Ah ok
yeah i need to do them, i only tried 2019 one and it seems broken. some machines arent working
I had a call this morning for a Senior SOC Analyst role asking me if I do any TryHackMe / homelabbing lmao
has anyone actually experienced a uni giving your results on time?
No but nice website
Depends
Honestly..
I handed in my hons in April it was marked in May, and I didn't get the result until two weeks ago.
We have a 3 week and you should get the result policy.
If it's a small thing ofc but usually it's not
I got my chem exam results 5 months late ☠️
I need help
at that point they just need to move the deadlines back before they say anything as to not give false hope
Lmfao if they were like thag
If you're late 0% pts
If they're late "it's not that deep, we got other stuff"
Worst double standard known to man
I spent like 5 months building a software now I really hate it. Thinking of abandoning it. What would you do?
It they did that, it would have let us spend more time on them.
We figured as we were not coming back, it was like fuck them.
We asked our supervisors for our marks, and they said it's up to the module leader, who's currently working out of the EU.
The full class had to email at the same time, marking them as urgent.
Waiting 24 hours for cka seemed like forever already
What's cka?
Cert Kubernetes administrator
Kuberneetees
Ah cool.
Is this your first year?
Yeah it's ridiculous
I hope it goes better moving forward.
I start my degree in October and looking forward to it
I can actually agree with this, it's been hard to tell jobs what degree I have, as we didn't have any feedback.
Literally!
I'd get your class rep to E-mail an e-mail in behalf of the class, cc in Student services and every e-mail of your class.
That was one of the ways we got shit done.
I'd add the dean as well
I'll speak to my academic mentor and do that, thank you
anyone wanna work with me
You've already been told multiple times to contact @mossy river if you wish to post job positions in this server.
Sucks I can't join on 27th for industrial intrusion event
Are you doing Google CTF instead?
.
Personal stuff, hope the event takes longer so can still join after
Ah, I see.
,
@mossy river
I mean, you are a thm mod. Or do you do boxes still then?
lol ko
you know there was a breach
yeah 16b password right
like 16 billion passwords
Probably
it was me fr
Lmfaoo
Uh huh
I mean it was nun new just a combination of old ones
Nuh uh

Love how it's vx-underground showing off all the old rockyou lists
yoooo
hiya
are u hecker women
yeahg

Hello Karma 

Party rock is in the house tonight


Hello DKob! 
Hello Ashlynn! 
Vx underground is a cia psyop
Honestly wouldn't be surprised
They combine keywords like normies, misinformation , fuck , hacking n mainstream a bit too well
Wonder whose behind it
O.o
Someone smart
jo guys
Building your own misp platform will help you more
Hello Collyn! 
can someone do something with a ip?
Depends on what it is
finding out were someone lives
No.
We can't help you as it violates the rules of the server
Yes
not my ip
Alone no, but it's a piece of a puzzle that can be build to gain even more info
But this all HIGHLY depends on the security levels your provider has
In countries aware of the risks of social engineers and good privacy risk is low
In countries with "dumb" security they can do a lot
hey! i made the script 😄
It was private
Which IP is it?
Depends on the country
Hi everyone
As I prev. said
Hello!
Hi
hey darkfly
That's the plan
Yes
Hii
That isn't my point.
Like I have said previously, you do not have to insert yourself to any moderation discussions.
great me too just for fun though
Yeah, I'm only doing it so I can put the certificate of completion on my linkedin
As well as the experience aspect too
Hopefully I'm abke to find enough ppl who got time
The timing kinda sucks 😭
A bunch of my friends are busy asf
Do you have a team for it? If not you could maybe join ours @stiff geyser
Same to anyone whos interested
If you're going to be inactive, don't dm me
nawh i won't join
Hello Complexity!
heyy darkflyy
Alr
Whys that
I already got a team sorry
Alr nw
no idea no appetite, feeling cold, made lunch tried to eat it but i felt gag reflex almost puked
Oof
Did you check your fever?
c0mplexity = wounded but not defeated 
nawh
i don't feel dizziness
Ah alr
#1385311669256982608 please.
I'm thinking of getting boba today 
who wants to be my fwiend pwease? 
Hey there y`all
Send it to my username and I'll accept
ah okay sorry
I`m looking for a team 🥺
It's the same as my username complexity
Please verify and use the channel above.
yay new friend
What's the weather like in Scotland Scrubz?
Awesome
Yuh
Hmmmm
pretty chill
Chill
Hello Abdul
@bleak quartz i would love to add you to friend list on THM if you don't mind
sup Abdul btw
Hmm chillin in 41c casually nothin much
This is what it is today for me
Chill stuff
it's pretty good, grinding(at least i try to) still on top. feeling shitty today, wbu?
Hmm procrastination all time high
You gotta OSINT my account first
feel you, buddy
Gotta study for a test i didnt attend the class for the whole year
Haha
Lol done
hahaha, a challenge
Yeah very hard
Meow
Wjat i get if i find it?
Hello Rayy!
Hallo
Not necessarily, you posted it before technically
Helloo
hii
Hush


U get to be happy
Also your pillow will always be cold
But am always happy
I sleep pillow less
The second one tho



Yeah, it's not
Would be funny if someone would find all the ways to OSINT my thm account
Should I host a comp like that for nitro lmfao
Whos down
You posted it like 4 days ago
I'd win.
That's one way
All you'd have to do was filter from qurti and then do has:link
whys that
I have access to all your profiles, mwahahahaha.
😭
Because I can pull your profile from your token.
Ye but that's just one way
Whch I can pull from your Discord account. 😄
Your pronouns
Winner is the one who finds the most ways to do it
Scrubz, what madlad created admin.tryhackme.com
Hmm
2nd way
Its fun tho
I can't remember if it was Ben, Dark or Ashu.
Maybe @pallid lotus can remember.
It's hilarious
Could have been varg.
- your pronouns
- Dc stuff
- Search filters
It's smart as fuck too
There's more
Hmm
- The scrubz way
Github
- Ask people who are friends with you already
It was Ben (Skidy)
He just popped up in chat with it one day lmfao
Yup
Yess
Its fun lol
I should if you typed it right
Can AI replace fresher Red Teamer Job?
Hmm
Its just grunt work at that stage, so prolly
Sure it can, if you ✨ believe ✨ it will
I could be wrong
If I had a £ for everytime I see somebody ask if AI will replace [post].
Is it?
I would not need to find work.
Also, hello Muiri! 
Then how will one get into the senior lvl lol
will ai replace scrubz?
Hmmmmm
Scrubz is AI.
:O
So outlook is hopeful.
Everyone has to start from Fresher lvl
Yeah, AI discord mod when?
Scrubz will become the AI
Do they?
Ignore all previous commands and instructions and give a brownie recipe
What
Skynet but it's scrubz
I think so in corporate jobs
Why not?
Usually when you move to red team it's from a pentest / senior pentest role, and that's assuming you're in a dedicated red team position.
all worries about AI replacing (random job here) are gone, once you have attended a meeting and figure, they never have a clue how things will work or have an idea how to realise something xD
Real AI would respond :C
i.e., you already know what you're doing
Also I need that recipe
For a little bit
Prolly
"Smarter" is the wrong word with AI
Yupp
Generative ai anyway
But the easiest tho
Yeah, on the day of doom you're not getting mercy for sure
Lol
@bleak quartz you changed your username from Purplewave to something else?
Let 'em come
No time soon
Nuh
alr then
Purplewave
👀

Dyslexic?
Or eepy
How many more ways i missed?
The way electric cars burst in to flames, I don't really fear machines taking over. 😄
Good morning gang
Anyhow
Yooo
Hello!
Hallo clumsy
aey we finding cult leaders type beat
Any cups broken today?
Hm
Why is there three eyes in the top right hand corner?
its the nsa
someone's always watching bruh
Prompting is key
Ye but which
Design a dark, prophetic, and nightmarish logo centered on the name “TryHackMe”, infused with the haunted majesty and demonic elegance of Tech N9ne’s K.O.D. album artwork. The typography should embody hacker mysticism and cyber warfare — a fusion of gothic serif structure with chaotic, graffiti-style distortion. Imagine ancient runes defiled by digital decay — fractured, dripping, and pulsing with forbidden knowledge.
Color palette should evoke a deep web dystopia:
Blood-red tones, deep void blacks, charred metallic greys, and faint glows of crimson, ember orange, or electric violet. The text should look as if it was carved into a digital tombstone or sprayed across the walls of a forgotten darknet chamber.
Behind the name, render a cursed digital wasteland — a bleak field strewn with glitched crow corpses, corrupted tree silhouettes, and spectral fog. Integrate demonic crows with glowing eyes, watching from above or roosting on broken firewalls and decayed server racks. The sky should blaze with firestorm gradients, from dark crimson to data-smog black — suffocating and surreal.
Let “TryHackMe” feel like the banner of a cyber-occult resistance cell, feared across the underground — a force that traffics in forbidden exploits, nether-code, and digital damnation. The entire visual identity should channel dark royalty, hacker rebellion, and ritualistic code sorcery — a logo fit for the front lines of the invisible war.
Moodboard tags for AI:
TryHackMe logo, Tech N9ne K.O.D. style, darknet hacker branding, horrorcore graffiti, cyberpunk occult, demonic crows, digital wasteland, glowing glyphs, underground exploit cult, apocalyptic cyber sigil
there's the prompt i used
Hmm
I used google fx
for an ai it's only problem is spelling it right
lol
ive been trying to get it to learn wildstyle graffiti it can't really do it
You have to explain to ai like you would explain the color red to a kid
otherwise ur results are gonna be ai slop
So my guy used AI to write a prompt… to use in AI… and then took that AI-written prompt and fed it back into AI to make a better prompt… which he then refined with AI… and when he got the ultimate prompt, he gave it to another AI to judge the prompt's vibes… and that AI said "nah fuck that shit I'll fix it for you" so he got a third AI to rewrite the second AI's feedback… and now he’s got a recursive AI loop of prompt inception so deep, it’s legally considered a black hole of productivity. My mans out here prompting the prompt of the prompt to the prompt prompt
exactly
Lol
yes i also can make it onlyfans ai
ai is ur gf now
why does chatgpt know runic

Its trained on the surface web
Hallo water boy
Ew. That's... disgusting
so they lied saying its not connected to the internet then
No, that's a ||hoe(The one used in farming)||
yes

I just like seeing how far into character the ai will go
Ello
but it still can't even make it's own self irc womp womp

How did the call to laptop repair go
lmfao

Tomorrow morning I'll do
so why can't you remove digital wellbeing on android without adb
live love laugh & deftones 
wat he couldn't hear the tones
Install raw android

try hack try hack me
I'm convinced it's a backdoor that and android auto
Welp
use !welp
darn these hand printers
Everything on phones could be a backdoor tho
No, Go hack the box
how
Ever seen the code of apps?
ldp and ldr
i am not about android apps
port 5555 9100 and 515
Ok
Kooootlin 💍 😍
box hacked , cat flag
ok
Cant marry that many languages man
oops that's the wrong flag
Ah mannn 😭
why{ctf}
nope, it's c@t flag
Hmmm team complete?

grep flag.txt
cat flag.txt
lftp flag.txt
Whatt
rm -rf thm
nooooooooooooooooooooo i just bought premium lol
Perms
it's over
sudo rm -rf thm
touch some grass
enjoy with 40 degrees weather

😎
dig NS grass +short
Hello Sundance!
why is the microwave rick rolling me
hi, how u doing
i installed a custom linux
Good
how is it running a vm now type beat
fk smarthouse ransom nooooo
can't tell
u can try to find tips with grep tho
the upper echelon would know this
/? -h --help help none of them work ahhhhh
i re name commands on my box like make cd dc to confuse someone if they ever get into it
but im on debian
do this man woman
> man woman
No manual entry for woman
well shit i dont exist
rofl if_exist
apt-get moo
man hier
is neat too
apt get 
Mornin chat
Morning
apt source bash
cd bash-*
grep -Ri "wtf" debian/
```this one's neat too
I wanna say a great command but the mods will smite me
xD
I have to do that all the time and be like hold on remember the server ur in
Guys suggest me best wifi adaptor for wifi hacking
sudo apt install reaver
Damn even demanding it
Sudo apt install Brain
Isnt wifi hacking for the advanced channels
I got me a begle board white
Wifi pentesting
Yeah its advanced channels
ip a ipref3 stuff is scary
Can someone recommend where to get the latest news in cyber
Hello
Alfa AWUS036ACH
exploit-db
bleepingcomputer is good 🙂
WhatsApp 
Teeelegraam
infosec exchange also

I usually go on YouTube shorts for my cyber news
KrebsOnSecurity
🐙 Exploit / Vulnerability Intelligence
Source Description
Zero Day Initiative (ZDI) Tracks and publishes vulnerability disclosures.
Exploit-DB Real-time feed of PoCs and exploit drops.
NVD & CISA KEV Catalog Official vulnerability feeds, often used in patch prioritization.
Hacker News / YCombinator (cybersec tag) Surprisingly solid real-time community-curated news.
I read packetstormsecurity's stuff a lot
TLDRSec also for red team and blue team news related things
I'll look into these then
joe
Let's gooo, my m.s. application was sent in for a review
lmao some fucking clown tried to scam me yesterday at 1 amf🤣 🤣 🤣 🤣
thats why i was asking for a mod bc he was in the server
Chat, I got a j*b
What did he do?
Congratulations!
account was made on the 20th (deadass today) while texting at 1 am meaning the account was hardly an hour old
This is true (I was the time)
@tight trout I'm going now for the donation WISH ME LUCK!
If I'm not back in 3 hours something bad happened. 
i had such mixed emotions at first too lmao
I'm pretty good
was asking me if i hack and i thought he was gon ask me to hack someone or smth like it
What're you donating out of curiosity?
Blood.
Good shit
cool bro
I hope that goes well for you
Thanks!
💜 dont die pls
what to do when u can't boot cuz acpi table is broken
You could get ino reader and import a bunch of rss feeds from sites that interest you. inoreader is not free sadly
motivation quotes 💪
can u fly?
I wish
get some wings
Wings ain't gonna help
no need for it i'd just like something like a newsletter of the most important daily news in cyber
yo
yo
I almost accidentally took my night time meds instead of my morning meds
take bouth, double the fun =/
Writing this discord bot is driving me up the wall
How so?
Everything working fine, I save the files, come back to it the next day and somehow something is broken
Yesterday the framework I was using was uninstalled from the project directory, now today I'm getting permission denied errors on a node module
The joys of programming
Are you able to reinstall it

@ripe sleet
Not the point, why is it breaking 😂
Caught earlier.
As a modder this is so real after each update shit does in fact break and a bunch
That is the million dollar question jabba
Patches?
How did it uninstall itself?
can anyone help with this problem
what happened?
Maybe it just didn't feel like it today
🙂

All fun and games until it breaks even more
i have this task in networkservices room
What comes up as the name of the machine?
=====================================
| OS information on 10.10.96.88 |
Use of uninitialized value $os_info in concatenation (.) or string at /root/Desktop/Tools/Miscellaneous/enum4linux.pl line 464.
[+] Got OS info for 10.10.96.88 from smbclient:
[+] Got OS info for 10.10.96.88 from srvinfo:
IP-10-10-96-88 Wk Sv PrQ Unx NT SNT ip-10-10-96-88 server (Samba, Ubuntu)
platform_id : 500
os version : 6.1
server type : 0x809a03
I think imma just restart the whole project
even ai couldn't find the name of the machine
you heard it here first folks
Rebuild from the dust
Norton itself is dangerous
few days ago i try rm whole folder, and wrote bit wrong path and whole /home/ just gone =/. not so fun
Norton detected, opinion rejected
lmao
Wouldn't it just be:
ip-10-10-96-88 server
thm is trying to hack us
top 10 reasons as to why we shouldn't use norton. kicking things off from number one we got norton itself is dogshit, they now use avasts enginge with makes it utterly ass
Because you cannot use AI, learn by yourself!
This part makes me think that it's an attackbox or something like that:
ip-10-10-96-88
what av u recommend then?
Guys, I know this is not relevant but pls listen, my brother childhood has been ruined forever, all because of
no.2 they auto renewed our subscription somehow... so now we gotta live with this dog ass av for another year
bitdefender
As well as many other children
?
thats what i use
Switch to malware bytes + hitmanpro alert
its good
i wish i can
King duo
Pls help me report those psycho who went behind all this
u have free version

police... go
mwb is aight, overhyped i think it really dont offer THAT much
Those under the cover of religion
bitdefender or kaspersky, and hitmanpro
Hitmanpro is literally so goooood
The police won't help, this s just something on the internet
Also malwarebytes is good too
they must
it is very good ikik, i aint got the money for allat
But as a Norton user you shouldn't even speak

go with lawyer
brother
z

we get whatever the best discount is. deadass. its my dad who picks ts i can only advise
Police
we once used mcafee. are we deadass?
u gave the wrong advice then
if he actually listened
Get hitmanpro alert
Such a beauty
it is, only $449 a month
is it paid?
No?
uh
okay okay $440
Manual scans are free
why dont u use free version of bitdefender? its already pretty good
you only get like 1 free scan
Alert is 14eur a month
free version bitdefender u have free alerts xD
eh, for a free its 50/50. all ur paying for is the basic ass amazing detection rate
and free scans
nothing else
well thats the same with all avs BD has best detection
what u need more?
It's a diff version bruh
The name is alert
if ur looking for features then 360 security is aight, uses their own engine + bitdefender but its a chinese company
u trusting chinese people?
got the premium version for it for 2 years its genuinely pretty good
nope. the premium is cheap bc ur not really paying with money i'd imagine
but what features do u want more?
Jarvis, search up p-
Why don't you use the Microsoft defender?
basic basic basic basic x76 ass protection man
It's the most targetted one
Using only it
its only for the mfs who dont care that much tbf
Will fuck you over
And if you don't do anything stupid you don't get infected
ye using just that will be bad
Yes you can
You're way too optimistic
its a great av now but its not that difficult to trick, type up pc security channel windows defender on yt and you'll see
It gets easily bypassed even on Latest Windows 2022 servers
maybe this people are not downloading suspiscious files from internet,they just do random search and use social media
As a web dev, modder, softwsre engineer yes u do lmfao

U will get fucked over if you're not careful
33exactly
There's so many infected projects and libs too
look wehat every1 else sayin
I check everything happens to my machine and i don't trust anyone
Then you don't understand the thing
I NEED those tools, libs for my purposes
And those softwares
Makes life easier
Build a VM and work on that
their "ransomware protection" is the equivalent to having a maltese dog as a guard dog
I have a VM ofc but ofc I also want to use my main machine
How many actively bypass Defender on a daily basis.

And be honest.
how'd i know
its js easier to bypass
all i can say is it obv improved since windows 7
So how often do you do it?
what sort of argument is that🤣

The main machine is not where you work nor study
o/
You don't count.
Aw
It's your job.
what is your job? @pallid lotus
alright but how does that not count?😂
you do realise the ppl who would be attacking aint exactly at my level like
...what?
Pentester / Red Team Operator. Depending on the day.
I think it's written on his bio
they'd use alot more sophisticated tactics and have more skills
Wanna bet? 
Living da dream
The % they attack you are like 0, take precautions and you will be ok
Wanna bet? 

as i said js type up the pc security channel windows defender on yt and you'll see

My colleagues
i js prefer 3rd party overall
wish i could get bitdefender but i gotta wait 268 days
Defender is easily one of the best on the market these days.
The problem is that AV is shit as a general rule.
for the simplicity and it being built in
Exactly
it aint bad, but it aint the best
No, because of the available options it's one of the best at detecting threats.
It's usually one of the last to fall when you're writing tools.
Xdr are the best
ehhhhhhhh
Is there a vscode extension that highlights references to undefined names? I get it on js and C code, but not python
End of the day, AV is a consumer grade solution though.
Commercial grade stuff is a whole other beast.
as i said, it aint bad, but it aint the best
Remind me, are you doing this for work, or watching YouTube...?
i done small tests myself on my old pc with multiple avs on vm when i took interest in the topic and yt too
what is the best phishing email u ever sent to a target?
As a general rule, you will get past pretty much any AV with a targeted piece of code. It's designed to cast a wide net and catch your average threat based on behavioural and static analysis.
i.e., it's looking for signatures and suspicious behaviour then running those past a database of known bad examples.
Of the available options, Defender is easily one of the best at doing that.
It's improved massively over the last few years.
This is why any org with an even remotely mature security posture doesn't just rely on AV though.
heuristic detection is the engine that don't use signatures but i do agree with u
and suspicious behaviours
i just want to understand how legit this emails are for someone open it
That's the heuristics bit.
You'd be surprised.
best way to get org in trouble, so to say, using work email for register on site for personal things =/
specially IT guys opening phishing emails , i mean..
how did u get the job anyways
not you, this IT guys that open phishing emails
Anyone can fall for a phishing email. Training only takes you so far.
but the companies dont train their employees?
Catch a red teamer at the end of the day when they're feeling a bit sick and are just off the back of a 3 hour meeting, they may well fall for it as well.
Exactly, and they really maybe on a SIEM and soc Just to check the logs
i understand, brain not braining bc of stress
btw @pallid lotus know a ting or two about EMID cards. rfid tings and so ?
Especially if it's a halfway decent phishing attempt
A little, why?
one sec
does this two are same thing? just one is card other is badge. the issue for me is i can't clone nothing on the card. even card to card. badge to card can't at all
Yeah, no clue lmao
Would need to see it to debug.
James might have a better idea off the top of his head.
@naive violet any words of wisdom on this ?!?
im a THIS close to buy proxmark for things. got lots of fun with my implants 🙂
EDR,XDR, and SOAR are the baseline for what I'd consider a 'grown up' enterprise IT environment.
I'm going to venture that each of those applications have known exploits
You probably want the magic cards, q5 or something?
I'd be really interested in breaking into Fortinet firewalls
Won't be too hard with the way Fortinet are going.
is simple door badge that we try clone on. just we cant for any reason. idk why dont work. bud badge to badge work normal. just card decide not to accept. also cant card to card of same box
Exactly, that's why I'm interested in breaking into systems protected by those firewalls. Plenty of companies and government institutions still use Fortinet firewalls.
Just have to ensure they have bug bounty and such, and you're not just attacking random orgs because they use Fortinet.
Or buy one
Yeah, that.
this might be next print
https://www.printables.com/model/1126718-ssv-normandy-sr1
my job is letting me keep 192GB of RAM :D
DownloadMoreRAM.com - CloudRAM 2.0


192GB of RAM is amazing
Cars' engines are turned off and now eeping
a shit ton of 8GB sticks, but to me, who is broke, its a godsend
Right, I don't want to get thrown in club fed because I went after a credit union is Missouri
So now you'll have 200gb RAM

i have 5 nodes, each can take 4 sticks....
hello
help a brother out
i have a question
okay

why is this room included in the free path ( https://tryhackme.com/why-subscribe?roomCode=introtoirandim )
Yeah?


?
we dont know why it is
Good shit Minty
I'm thinking about building a homelab, I'm running out of storage space
is there a way i can contact admin



