Sav @InfoSecSav
Intelligence Capability Development consultant @Mandiant, studying the intersection of intelligence, risk, and business operations. Virginia, USA Joined November 2020-
Tweets4K
-
Followers565
-
Following833
-
Likes762
@greglesnewich I had strep and flu at the same time and the doc looked at me with a level of pity I will never forget. Good luck, Greg.
So…anyone seen details on this?
On Mythos, from @MarkWarner in this morning's Senate Banking hearing: "the head of the NSA and Cyber Command came and said this tool broke into almost all of our classified systems, not in weeks, but in hours"; I had not seen that mentioned elsewhere?
I’m hiring a sr principal threat researcher. When big things happen on the internet, you’ll lead the threat research to hunt across our vast telemetry & write the threat briefs. Senior role w/ strong comms & collab experience. jobs.paloaltonetworks.com/en/job/santa-c…
Sometimes I put this on the projector and just shout “QUADBOX” at my wife until she is forced to acknowledge.
Packers fans are everywhere
A 77-year-old Ukrainian grandmother fleeing the war was spotted by a drone while walking alone under fire. They sent a UGV to rescue her. To avoid frightening her, the ground robot was covered with a blanket bearing the message: "Grandma, get on."
@ImposeCost Generally I advocate for yes, but the reality is some degree of collaboration varying with consumer maturity/familiarity. CTI is accountable for collections IRL, so no buck passing. Only wholly applies if the consumer is providing consistent feedback, though. Generally speaking.
@ImposeCost Every end consumer has two very robust requirements: “tell me everything I need to know for my job” and “tell me everything I don’t need to know but could get me fired anyways.” Everything else is on us.
The Department of Justice, through U.S. Attorney Jeanine Ferris Pirro and Assistant Attorney General A. Tysen Duva of the Criminal Division, together with its partners, today announced a series of coordinated actions by the Scam Center Strike Force against Southeast Asian criminal organizations operating scam centers that have defrauded Americans of billions of dollars. Read More Here: justice.gov/usao-dc/pr/sca… @USAttyPirro @FBI @SecretService @USTreasury @StateDept
Had an interview with a “crypto” recruiter. We talked for about 40 minutes, and then they asked me to look at some code. Their first instruction was to clone the repo. I didn’t. They seemed surprised, so I told them I wanted a moment to check whether it was safe first. I ran a quick analysis with Claude. Turns out the code had a backdoor. It would copy my environment variables and send them to a remote server. The recruiter went speechless and ended the call pretty quickly. Be careful who you talk to. Scammers are real.
A special place in hell for the people indicted here.
Seeing western-based ransomware negotiators & incident responders deploying ransomware at victims & playing both sides of negotiation is sickening 🤮 21st century version of the 1990’s movie Backdraft justice.gov/opa/pr/florida…
The @SLEUTHCON CFP closes next week. Don’t waste valuable time doing your taxes. Submit! Submit! Submit!
We want to hear from YOU 🫵 Got something you think would make a great talk at SLEUTHCON this year? Full-talk speakers get a $500 honorarium, ALL speakers get the best swag! Don't wait - submissions close April 17th at 11:59 (ET)! Learn more about our CFP and submit yours today
It’s nice to fantasize about a comprehensive integration into CI/CD pipelines to the point where we all get to hold hands and sip daiquiris on the beach, but you are still a river of fire and brimstone away from that level of tool and patch adoption.
If your response to a highly competent, but imperfect and resource sensitive, vulnerability hunting tool is to conclude this favours *defence*, you and your networks are ngmi. One does not bug hunt their way to a defendable network. AI does not change that.
@ZackKorman Bold leadership in these trying times. Not good leadership, but bold.
If there are any Delve customers left on @ZackKorman’s list, this should be some sort of blunt force instrument. A brand new “How cooked are we?” metric.
I'll refrain from commenting. But if the founders would like to talk... I've seen this show before.
Really can’t believe @smithsonian took Hail Mary off the IMAX for Super Mario.
The FLARE team now freely distributes its quality reverse engineering and malware analysis educational content at github.com/mandiant/flare…. Launched with: - Malware Analysis Crash Course - Go Reversing Reference - Intro to TTD
Our blog on the Axios NPM supply chain attacks. We are attributing the incident to a suspected North Korean threat actor we track as UNC1069. That actor is financially motivated and DPRK historically leveraged supply chain attacks to target crypto. cloud.google.com/blog/topics/th…
We are still looking at the axios supply chain compromise, but we’ve attributed it to UNC1069, a suspected DPRK actor, who we covered in a blog this February. They are financially-motivated and historically DPRK uses these incidents to target crypto. cloud.google.com/blog/topics/th…
Shoutout to the Badgers captain dropping an F bomb on live TV.
Andrew Thompson @ImposeCost
41K Followers 2K Following Posts are attributable to me—not my employer. Leadership, Security, and Intelligence. Former Infantry, HUMINT, Counterintelligence, and Cyberspace Operations.
John Hultquist @JohnHultquist
30K Followers 1K Following Chief Analyst, Google Threat Intelligence Group. @CYBERWARCON and @SLEUTHCON founder. Johns Hopkins professor. Army vet.
John @Big_Bad_W0lf_
2K Followers 677 Following Bad guys and Breaches with #AdvancedPractices 🦅 @Mandiant / @Google | tweets are my own
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Tyler McLellan @tylabs
3K Followers 588 Following Intrusion aficionado. @Google/@Mandiant GTIG Advanced Practices
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
💻 Sherrod @sherrod_im
37K Followers 7K Following Difficult mystery girl connected to the divine forces of the universe.
Gigs @ Shmoo @Gigs_Security
2K Followers 715 Following not aspiring to be humble▪️ #AdvancedPractices🦅 ▪️Thoughts are my own ▪️She|Her|Gigs
Jared Wilson @JWilsonSecurity
2K Followers 1K Following Mandiant Research and Discovery, Father, Husband, Trail Runner, Co-Founder CyberFriendsCircle
InfoSecProf @_John_Doyle
2K Followers 963 Following Cyber threat intelligence | Palo Alto Unit 42 | SANS FOR578 instructor | Arcane Trickster | Ex-Mandiant | Ex-CIA | Posts represent my personal views
Allan “Ransomware S... @uuallan
17K Followers 6K Following Back The Press Guardian & The Clock:1942 https://t.co/liXLX2DeQ8
Dan Perez @MrDanPerez
5K Followers 1K Following Technical Lead, 🇨🇳 Mission @Google GTIG. Specializing in tracking and attribution of China-Nexus Threats, and making life difficult for them.
Steve YARA Synapse Mi... @stvemillertime
18K Followers 1K Following AI threat intelligence @google writing & sharing on adversary tradecraft, malware, threat detection, AI-nexus intel and all things #yara
Cris Brafman Kittner @criskittner
2K Followers 1K Following Cyber geek at @FireEye, @Mandiant, @GoogleCloud, now @Proofpoint. Interplanetary enthusiast. History geek. Opinions my own.
Andrew Northern 𓅓 @ex_raritas
5K Followers 1K Following 🔮 Principal Researcher at Censys ARC 🔮 | formerly Proofpoint | Knowledge Piñata 🪅 | Attack Chain Connoisseur | Aspiring Stoic
🇨🇦PJ⌨🏋🏻... @PJ47596176
2K Followers 3K Following 🇨🇦whisky; cyber; natsec; Greater Toronto; innovation; girl dad.🌻.
Jamie Collier @TheCollierJam
3K Followers 1K Following Cyber threat connoisseur @Google/ @Mandiant. Associate Fellow @RUSI_org.
Ryan Tomcik @heferyzan
1K Followers 1K Following DE/TH @GoogleCloud @Mandiant Threat Defense | Google in the streets, Mandiant in the tweets | Thruntito ergo sum
cl4ire18 @clairetwinklei
1 Followers 353 Following i’m a lot to handle but luckily i come with an instruction manual (my best friend)
James Ibrahim @JamesIb54140322
52 Followers 4K Following
MikeWavada @WavadaMike
336 Followers 5K Following Cyber specialist specializing in Imposter Syndrome. Former USMC. Currently with Prestige Worldwide. Likes Nickelback.
Ryan "Chaps" Chapman @rj_chap
8K Followers 3K Following Threat Hunter. DFIR & Malware Analyst. @sansforensics Author (FOR528) & Instructor (FOR610). Husband & father. Retro gamer too! Comments = own.
InfoSecSherpa 🏔️ @InfoSecSherpa
51K Followers 4K Following Your Guide Up a Mountain of Information! #Librarian 📚 ➡️ #InfoSec 🤖 #Philly 💚🏡 Nil satis nisi optimum ⚽ #Toffees
Tony (@[email protected]... @amdz23
255 Followers 2K Following @Android Security @Google | Security Researcher | Bureaucracy Hacker | Team Builder | Ex: @USArmy, @US_CYBERCOM, @NSAGov
Michael Kelley @mikewkelley
29 Followers 54 Following Security Research Engineer @TalosSecurity, USAF Veteran
范托姆👹 @Muzaooo2025
18 Followers 363 Following
Timothy Dunn @TimDunn94183193
128 Followers 893 Following Threat Researcher, Security+, CEH, Speaker, Practicing Curmudgeon. Opinions are my own ...
Romario Antunes Hornb... @RHornburg
4 Followers 266 Following
Paulo Bernardo @BR00224993
6 Followers 1K Following
Sa9lo @S49L0
0 Followers 2K Following
0xDoge @mov0xDoge
111 Followers 980 Following Cybersecurity and CS at GT | 21 | he/him Been on the internet for too long
Ellie Loralee @ELoralee60942
2 Followers 168 Following
IntelCorgi @IntelCorgi
730 Followers 1K Following cyber threat intelligence, OSINT, and corgi hair. Thoughts are my own, RT/Like != Endorsement. (He/Him)
Agnani Sanjay @sagnani
32 Followers 3K Following
Nick Vidal @nikolaipozdnii
93 Followers 806 Following Sr CTI Analyst @secalliance | @warstudies alum | Russia watcher & strategic culture evangelist | 🇺🇸 in 🇬🇧
kasper @kasper_rt
485 Followers 283 Following cofounder - embroidery. i (prefer to) yell at silicon to do cyber security stuff
1aN0rmus @TekDefense
4K Followers 1K Following CTO at @permisosecurity Alum: @Mandiant, https://t.co/kqlvYwe86k, USMC
Vijay Bolina @vijaybolina
4K Followers 7K Following I build and lead deeply technical teams solving some of the hardest problems in the world. Current: @PrometheusInc, Prev CISO @GoogleDeepMind, @Mandiant, USG.
Tom_Giw @GiwTom_
1 Followers 56 Following
Disco Elyzard @disco_elyzard
33 Followers 1K Following
The Adam Parsons Proj... @AdamParsonz
1K Followers 943 Following Father of 2 mini-mes. Former helpdesk. 'Talented individual' - MT, 'Notable patience' - SW, 'You were right, and it made it better' - @SwiftOnSecurity
Zack Korman @ZackKorman
13K Followers 2K Following Cofounder @ Embroidery. Building AI cybersecurity stuff.
BSides Pyongyang @BSidesPyongyang
1K Followers 706 Following 🇰🇵 #BSidesPyongyang2026 : Nov 18 2026 (Missile Industry Day) @ Lazarus HQ Pyongyang & Live Stream | 31st anniversary 🎂 https://t.co/gb9sDPJC8X
Tyler Butler @tbutler0x90
408 Followers 1K Following @GeorgetownSFS studying the intersection of cyber security and statecraft | Independent vulnerability researcher
The North Korean Comp... @dprkcert
4K Followers 1K Following Defend Tomorrow, Secure Today! A Computer Emergency Response Team (CERT) for the Democratic People's Republic of Korea #EnjoyPropaganda
Dávid Kosť @dk_samper
421 Followers 3K Following Everything SOC | All opinions are mine and not necessarily those of my employer, whoever that might be.
guiduck🦆 @guiducky
109 Followers 1K Following | A snow chasing, cyber defender ❄️🛡️ | “If you look for the light, you can often find it. But if you look for the dark that is all you will ever see.” ― Iroh
Marcus Edmondson @ShowMeTheIOCs
460 Followers 1K Following Sr. Incident Response Consultant @Google Public Sector - Views are my own and not affiliated with my employer.
Isabella @Faouzi75017
446 Followers 643 Following "Every day is a new beginning. Take the first step."
Sean Levesque @seanlevesque
182 Followers 1K Following Mostly here to retweet. Also I have kids and I like my job so my actual opinions are conveyed through memes and sarcasm
Spencer Walden @__Masq__
776 Followers 4K Following Principal Cyber Threat Analyst @Centene #cti #ctf #blueteam #dfir #malware #netsec #infosec
throatylava @decompilebug
213 Followers 598 Following Infosec and RE stuff sometimes,talking nonsense the rest.
Jake Knowlton @j2k3k
1K Followers 2K Following cyber things @mandiant . natsec. prior USAF. opinions are my own. I’m back.
Letem Avit 🇬🇧�... @LetemAvit
624 Followers 5K Following If you can keep your head when all about you are losing theirs, perhaps you’ve misunderstood the situation...
Petrus Vasenius @PetrusVasenius
397 Followers 937 Following Cloud Security leader 🛡️☁️ | Retweets/Likes ≠ Endorsements | #CyberSecurity #SecOps
Beaudin Storniolo @S3901xom
8 Followers 552 Following
Andrew Thompson @ImposeCost
41K Followers 2K Following Posts are attributable to me—not my employer. Leadership, Security, and Intelligence. Former Infantry, HUMINT, Counterintelligence, and Cyberspace Operations.
John Hultquist @JohnHultquist
30K Followers 1K Following Chief Analyst, Google Threat Intelligence Group. @CYBERWARCON and @SLEUTHCON founder. Johns Hopkins professor. Army vet.
Gabby Roncone 🇺�... @gabby_roncone
4K Followers 1K Following hunting russian apt cyber ops @Mandiant @GoogleCloud. views expressed here are mine, not my employer’s. she/her.
John @Big_Bad_W0lf_
2K Followers 677 Following Bad guys and Breaches with #AdvancedPractices 🦅 @Mandiant / @Google | tweets are my own
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Mandiant (part of Goo... @Mandiant
129K Followers 4K Following We’re determined to make organizations secure against cyber threats and confident in their readiness.
vx-underground @vxunderground
439K Followers 359 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Tyler McLellan @tylabs
3K Followers 588 Following Intrusion aficionado. @Google/@Mandiant GTIG Advanced Practices
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
💻 Sherrod @sherrod_im
37K Followers 7K Following Difficult mystery girl connected to the divine forces of the universe.
Gigs @ Shmoo @Gigs_Security
2K Followers 715 Following not aspiring to be humble▪️ #AdvancedPractices🦅 ▪️Thoughts are my own ▪️She|Her|Gigs
Jared Wilson @JWilsonSecurity
2K Followers 1K Following Mandiant Research and Discovery, Father, Husband, Trail Runner, Co-Founder CyberFriendsCircle
InfoSecProf @_John_Doyle
2K Followers 963 Following Cyber threat intelligence | Palo Alto Unit 42 | SANS FOR578 instructor | Arcane Trickster | Ex-Mandiant | Ex-CIA | Posts represent my personal views
Allan “Ransomware S... @uuallan
17K Followers 6K Following Back The Press Guardian & The Clock:1942 https://t.co/liXLX2DeQ8
visi stark @invisig0th
5K Followers 680 Following Founder @vtxproject Father of the #APT1 Report @mandiant / @fireeye Inventor of synapse, vivisect, UNCs, imphash, ... DEFCON CTF Champion, Founder of Kenshoto
Dan Perez @MrDanPerez
5K Followers 1K Following Technical Lead, 🇨🇳 Mission @Google GTIG. Specializing in tracking and attribution of China-Nexus Threats, and making life difficult for them.
SwiftOnSecurity @SwiftOnSecurity
410K Followers 9K Following computer security person. former helpdesk.
Steve YARA Synapse Mi... @stvemillertime
18K Followers 1K Following AI threat intelligence @google writing & sharing on adversary tradecraft, malware, threat detection, AI-nexus intel and all things #yara
Tenobrus (→vibecamp... @tenobrus
33K Followers 3K Following this endless blue sky is driving me insane
Joe @JoePostingg
20K Followers 746 Following I mostly post about running, computers, and politics. https://t.co/OUpl9sa9PQ
reason @reason
294K Followers 382 Following Reason is the monthly magazine and website of “free minds and free markets” published by @ReasonFdn.
PoPville @PoPville
201K Followers 47 Following Chronicling the happenings in Washington D.C.’s neighborhoods since 2006. Founder: Dan Silverman [email protected]
Aleksandar Milenkoski @milenkowski
2K Followers 589 Following Cyber Threat Intelligence & AI Innovation | PhD | European Commission Marie Curie Research Fellow 2011-2014 | Personal Profile
Mike Manrod @CroodSolutions
2K Followers 2K Following CISO and faculty by day, adversary emulation/tools by night, bad jokes and memes all the time.
🎭 @deepfates
62K Followers 6K Following deepfates is an open-source AI project, developer, and publication focused on AI agent frameworks, large language models, and autonomous multi-agent systems.
Yarden Shafir @yarden_shafir
25K Followers 319 Following A circus artist with a visual studio license
TLPBLACK @wearetlpblack
330 Followers 168 Following Research collective turned into cyber threat intelligence business. Industry veterans, looking to redefine the future of cybersecurity. https://t.co/6xRbNyM4To
Theo - t3.gg @theo
345K Followers 4K Following Full time CEO @t3dotchat. Part time YouTuber, investor, and developer
Lukasz Olejnik @lukOlejnik
31K Followers 266 Following Security & Privacy. Data Protection. Research & Development. Engineering. Analyst. Policy. W3C. Consultant. Author. [email protected] Ph.D, LL.M. @warstudies
Patrick McKenzie @patio11
196K Followers 808 Following I work for the Internet and am an advisor to @stripe. These are my personal opinions unless otherwise noted.
Carina Eikaas @carinaeikaas
401 Followers 203 Following VP Data & AI at Pistachio. Making AI do cybersecurity things.
kasper @kasper_rt
485 Followers 283 Following cofounder - embroidery. i (prefer to) yell at silicon to do cyber security stuff
Joshua Saxe @joshua_saxe
3K Followers 1K Following Now: cofounder @ Abundant Security. Before: AI+cybersecurity at Meta. Way before: labor / community organizing, classical/jazz piano, hacking scene
HIGH PLANES Drifter @the_engi_nerd
16K Followers 925 Following Engineer. Dangerously sane. Creator of the phrase “vibes-based analysis”. In my Chinese Deterrence Era. https://t.co/6gkiD7lLGu
Scott Alexander @slatestarcodex
165K Followers 38 Following I have a place where I say complicated things about philosophy and science. That place is my blog. This is where I make terrible puns.
The Adam Parsons Proj... @AdamParsonz
1K Followers 943 Following Father of 2 mini-mes. Former helpdesk. 'Talented individual' - MT, 'Notable patience' - SW, 'You were right, and it made it better' - @SwiftOnSecurity
RealClearPolitics @RCPolitics
249K Followers 3K Following RealClearPolitics (RCP): an independent, non-partisan media outlet providing reliable news, analysis, and commentary
RealClearScience @RCScience
17K Followers 2K Following RCS is your portal to clear, relevant, and evidence-based science news and opinion. We strive to bring you the best of #scicomm. Editor: @SteRoPo
RealClearDefense @RCDefense
62K Followers 5K Following RealClearDefense - Your source for the latest on Defense, National Security, Strategy, and Military Commentary and Analysis.
Zack Korman @ZackKorman
13K Followers 2K Following Cofounder @ Embroidery. Building AI cybersecurity stuff.
dunadan @udunadan
1K Followers 87 Following An open-eyed man falling into the well of weird warring state machines. I talk about reverse engineering, vulnerability research and exploit development.
KeepTheShuttle @KeepTheShuttle
496 Followers 80 Following The Space Shuttle Discovery belongs at the Smithsonian, and we're going to fight to keep her there.
Matthew Pines @matthew_pines
56K Followers 6K Following CEO / co-founder solving physics @ https://t.co/5ryaTzDcuG | physics & philosophy @ JHU, public policy @ LSE | ignis scientiae, illumina mundum
Jake Knowlton @j2k3k
1K Followers 2K Following cyber things @mandiant . natsec. prior USAF. opinions are my own. I’m back.
Adam Goss @gossy_84
2K Followers 249 Following I help businesses and individuals enhance their cyber threat intelligence processes, develop their skills, and make CTI actionable.
Chris King @raikiasec
2K Followers 328 Following Mandiant (Google Cloud) Red Team Director. My views and comments are my own and do not reflect my employer's view
Senator Saddam Azlan ... @SalimForVA
3K Followers 498 Following Official account of Virginia State Senator for District 37, Bangladeshi-American.
Pierogi @ScammerPayback
120K Followers 164 Following Come join us as we go on the adventure of giving visibility into scammers and how they operate. [email protected] (Business ONLY, no investigations)
IFP @IFP
22K Followers 50 Following A think tank for accelerating scientific, technological, and industrial progress. Follow our team: https://t.co/CC0MxWfh3X
Cannibal 🎃 @Cannibal
9K Followers 832 Following Ex medical infosec. Red team. Threat hunter. Patient safety. Locksport. Metal work. Rapid prototyping. 3D Printing. I break things.
Samuel Groß @5aelo
25K Followers 524 Following Working on Project Zero, Big Sleep, and V8 Security. Personal account. Also @[email protected] and https://t.co/aVitnPjBie
Bernardo Quintero @bquintero
25K Followers 269 Following Founder of @virustotal 📖 INFECTED: https://t.co/RRguFlNWKR 📖 INFECTADO: https://t.co/WZ5C2U5ymR
Amanda Goodall @thejobchick
44K Followers 52 Following Execution-risk intelligence for capital allocation decisions. Workforce. Infrastructure. Sequencing. Capital flows. https://t.co/CyNSYFHIZd
Make It Hackin @MakeItHackin
5K Followers 607 Following Maker, Hacker, Engineer. TikTok/YouTube/Snapchat/Instagram and other links below:


































