Live data from Hacker News

Viewing profile — flexorium

flexorium

HN member
Joined
Fri, Sep 01, 2017, 12:30 AM UTC
HN karma
2
Public activity
12 items

About flexorium

[ my public key: https://keybase.io/flexorium; my proof: https://keybase.io/flexorium/sigs/nPUOrpsaReGBeVuz9LuQvs8aOjAqdVMFrAIsRTbFTJQ ]

Recent public activity

  1. comment
    Comment #47829744

    We appreciate this information you share in the open

  2. comment
    Comment #47829742

    Nice! very useful

  3. comment
    Comment #47804706

    That’s definitely part of the solution to limit the risk, but it does not eliminate it. That’s exactly something the tool demonstrates very well. If you can exploit , you can gentl…

  4. comment
    Comment #47780811

    Thanks! I got tired of talking about it to defenders. I wanted to talk to Red Teamers too and SOC / detection engineering people. I wanted to build a tool that someone can just hav…

  5. comment
    Comment #47780740

    Absolutely not. The same TTPs apply almost 1-to-1 for Insider Threat scenarios. We've built the Deciduous Attack Trees (shout out to Kelly) for insider threats last year. It overla…

  6. comment
    Comment #47780625

    OP here, mini AMA. Two years ago today, our small research team open sourced poutine, a SAST scanner for CI/CD pipelines (very similar to zizmor, but written in Go and customizable…

  7. story
    Show HN: SmokedMeat, like Metasploit, but for CI/CD (open-source)

    A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

  8. comment
    Comment #44159684

    We're pretty excited to finally talk about this new TTP.

  9. comment
    Comment #43856590

    I’m somewhat surprised to see that they use a KVM to switch between back and forth between a JWICS and SIPRNET. I would imagine it’s a special KVM as it’s essentially bridging the …

  10. comment
    Comment #39719300

    In the audit log of the organization you can see an event, but by that time you have lost visibility into what the attacker really executed. So a malicious tag payload (stage 1) wi…

  11. comment
    Comment #39718418

    When people think about Supply Chain security, they generally think of SBOM and vulnerabilities in your direct and transitive dependencies. But most people are completely blind of …

  12. story