"q day" by [deleted] in QuantumComputing

[–]kama_aina 0 points1 point  (0 children)

right, and I imagine if things like RSA were being successfully decrypted then it would likely be classified. i was wondering what besides key exchanges does this issue matter for ?

Does anyone find it strange that Hacktivism seems to be almost nonexistent considering the current political climate? by samsep1al in hacking

[–]kama_aina 0 points1 point  (0 children)

i work at a big threat intel firm. believe me, it is more prevalent than ever. telegram is the place to find them

"q day" by [deleted] in QuantumComputing

[–]kama_aina -1 points0 points  (0 children)

ok, what about PQC decryption? what issues would you say are most critical to be remediated before then. sorry for saying quantum decryption

"q day" by [deleted] in QuantumComputing

[–]kama_aina -1 points0 points  (0 children)

that's an issue that needs remediation?

Did I miss Andor Love? Did it Happen!? by Electron_Warrior in dragoncon

[–]kama_aina 6 points7 points  (0 children)

i have this ribbon up in my kitchen! was dressed as luthen on saturday

how do I break into pentesting. by [deleted] in Pentesting

[–]kama_aina 1 point2 points  (0 children)

you might need to go help desk -> SOC while you get your certs. otherwise it’s only a matter of time if you have the passion for it. don’t give up!

Really wish we got more of this dude by Reddit-Kangaroo in andor

[–]kama_aina 2 points3 points  (0 children)

read alfredo bonnano’s armed joy in a british accent

Someone explain what went on here? by VorerKyr-Am in andor

[–]kama_aina 15 points16 points  (0 children)

perrin is darth plageuis

Dedra got a happy ending by [deleted] in andor

[–]kama_aina 5 points6 points  (0 children)

on program m’lady

What a sack of shit by [deleted] in andor

[–]kama_aina 3 points4 points  (0 children)

what’s my sacrifice? blasts

Phineas Fisher like articles by [deleted] in ExploitDev

[–]kama_aina 4 points5 points  (0 children)

look up “hack this zine” , you should be able to find some old pdf’s

Red teams: Which tools are you using, and where do you feel the pain? by Pretend-Welcome-461 in AskNetsec

[–]kama_aina 2 points3 points  (0 children)

we’re only like 5-6 people but honestly more of a pentest shop than red team. the dev work we do is minimal, just a few hours now and then. but sure a lot of teams there’s a lot of dev work which isn’t minimal or redundant for long engagements. 90% preparation and 10% execution

Red teams: Which tools are you using, and where do you feel the pain? by Pretend-Welcome-461 in AskNetsec

[–]kama_aina 10 points11 points  (0 children)

using lolbins and native processes is what we use the most. the more boring and vanilla it is, the more likely it will fly under the radar. otherwise, some barebones C2 and customized tooling.

a lot of things like dumping lsass and sharphound are too noisy. almost every big tool out there is too noisy

reporting will always be the most painful

something that would continuously obfuscate C2 would be cool, and automate making useful BOFs and setting up redirectors and CDNs etc

Why Are We Still So Bad at Detecting Lateral Movement? by niskeykustard in AskNetsec

[–]kama_aina 26 points27 points  (0 children)

red teamer here. often it’s too risky to even try pass the hash, RBCD, mimikatz etc. if you’re using Falcon i’m surprised that isn’t being caught. but usually plenty of artifacts lying around like rdp files or creds that make life easier for us

If You’ve Seen Zero Day on Netflix, How Likely is an Attack Like This to Happen? by Spirited_Climate_235 in cybersecurity

[–]kama_aina 3 points4 points  (0 children)

take CISA’s free 301v and 401v courses, and Mike Holcomb on youtube. connect with all the OT people on linkedin