I am retiring this social media account. Find me as @hal_pomeranz@infosec.exchange

Orlando, FL
Joined November 2008
Filter
Exclude
Time range
-
Near
If your vendors have usernames/passwords on your systems "for support", then your attackers have usernames/passwords "for abuse". #sec101
3
Not going to use a tool that would help you make your case because it's not on some arbitrary list of "approved" forensics tools? Really?
3
Ok, somebody please explain the meaning of "< this" comment after a RT. I'm totally not "with it", I know, so please educate me!
5
Reminder for my fellow DoD Cyber Crime Conf presenters: slides are due Friday. Spent several hours tonight working on mine...
1
@ericjhuber No. That explains it. Can't we all just get along?
@ericjhuber OK, I missed something. Do you have a link?
Replying to @littlemac042
@littlemac042 @brad_garnett @Patories @KDPryor @kylemaxwell @4n6woman I only bust out the hex editor when Sleuthkit doesn't work.
Replying to @elpie
@elpie I am so sorry that you all are going through this. That's no way to leave the world.
@ericjhuber Still don't understand why any of us need to be screened.
1
Replying to @jgarcia62
@jgarcia62 Forensic artifacts from a #KenSMASH incident.
Could be the APT (Airport Persistent Threat) twitpic.com/77o9xb
1
@ericjhuber Fed LE show their creds and bypass TSA.
If POTUS, Congress, and Law Enforcement had to put up with the same TSA BS as normal travelers, the TSA would be dismantled in a week...
1
TSA checking IDs and boarding passes again as we're boarding the aircraft. What exactly is the point of this ridiculous security theatre?
4
@ericjhuber Thou shalt not covet thy neighbor's CSS.
RT @mikko: This is why you do not want to link to the original CSS if you steal somebody's website design: inspr.in/BMUM [LOLz!]
Road trip weeks 12&13 (of 14): VACATION! Meeting Laura at <undisclosed location>. We haven't slept in the same bed in two months.
RT @lennyzeltser: Reminder to self: Write every email with the assumption that it will end up being shared with everyone in the company.
1
Replying to @tuxcomp
@tuxcomp Also some sample AIDE config files under deer-run.com/~hal/aide/
1
Replying to @tuxcomp
@tuxcomp Look on deer-run.com/~hal/ for my old "Detecting Break-ins" talk. There's some AIDE info there as I recall.