Helping organizations respond to cyber incidents in the cloud |
🆘 24/7 support https://t.co/zfF62gimvm |
📚 Academy https://t.co/GH0u8tmjXJinvictus-ir.com ☁️Joined May 2021
The second part in our Kubernetes Incident Response series is live on Google Kubernetes Engine (GKE).
invictus-ir.com/news/incident-…
🔹 Standard vs. Autopilot Forensics: Why choosing Autopilot means you lose node-level access and how to adjust your IR plan accordingly.
🔹 The Logging Gap: Admin Activity logs are on by default, but Data Access logs (the ones that show secret enumeration and unauthorized execs) are not. If you don't enable them now, that evidence is gone forever.
🔹 Containment without Contamination: How to use NetworkPolicies to quarantine a compromised pod without tipping off the attacker or destroying volatile evidence.
🔹 Querying Cloud Logging: Practical examples of how to hunt for kubectl exec abuse within GCP.
#stayInvictus#CloudIncidentResponse#k8s
Most security leaders discover their cloud Incident Response (IR) gaps at 2:00 AM in the middle of an active breach.
The hard reality? Cloud incidents fail differently. The playbooks, containment moves, and muscle memory built for on-premises environments often don't apply when an attacker bypasses the perimeter entirely.
If your team had to contain a cloud breach today, could they confidently answer these three questions?
1. Where does the evidence land? If your logs only live inside the individual compromised accounts, assume they are already suspect or deleted.
2. Who can authorize immediate collection? If your access permissions or approval paths have to be improvised under pressure, your time-to-truth drops to zero.
3. What is your evidence posture? Optimizing for fast business recovery pulls in a completely different direction than preserving data for litigation.
We put together The Cloud IR Readiness Guide to serve as a practical pressure test for your visibility, access, and authority to act in those critical first hours. This isn’t a vendor pitch or a rigid compliance checklist, it’s a list of five critical readiness gaps based on real-world cloud breach responses. Stop guessing where your visibility ends.
Download the full guide here to audit your environment before an incident forces the question:
eu1.hubs.ly/H0vxzkQ0#CloudSecurity#IncidentResponse#CyberSecurity#CloudIR#InfoSec#InvictusSpirit
Is your organization truly ready for a cloud breach?
Most teams discover their cloud incident response (IR) gaps at 2:00 AM in the middle of a live incident. In the cloud, the "old rules" don't apply, the clock starts when an attacker gets a token, not a shell.
We are excited to share the Cloud IR Readiness Guide, a practical manual designed to help security leaders pressure-test their environments before the crisis hits.
The 5 Gaps That Determine Containment:
1. Log Integrity: It’s not just about having logs; it’s about whether they are immutable and independent enough to reconstruct an attacker’s tracks after they’ve tried to cover them.
2.Identity as the Perimeter: Traditional IP-based containment is dead. You need a full inventory of human and service identities to revoke sessions fast.
3. The Collection Plan: Collection speed is dictated by access. Do you know where your evidence will land and who is authorized to "pull everything" from a tenant?.
4. Cloud-Native Tabletops: If your last exercise was a standard ransomware drill, you’re using the wrong muscles. You need to test for OAuth phishing and metadata service abuse.
5. Pre-Staged Partnerships: The worst time to negotiate an MSA or grant admin access to a stranger is during an active breach.
Stop relying on "compliance checklists" and start building actual technical authority to act in the first critical hours. Download the full guide below to see where your organization stands on the readiness scale. eu1.hubs.ly/H0vjnXM0
Get a Professional Perspective. Invictus is offering a Free 15-Minute Technical Readiness Assessment. We will help you understand if your organization is prepared to recover from an incident or where you may be currently vulnerable.
eu1.hubs.ly/H0vjpTB0#CloudIR#InvictusIR#InfoSec#CyberSecurity#CloudSecurity#IncidentResponse
We’ve received quite a few messages over the past few days about Get-UAL being broken. It turns out Microsoft made an update that impacted the script, but this has now been fixed in our latest release.
𝘜𝘱𝘥𝘢𝘵𝘦-𝘔𝘰𝘥𝘶𝘭𝘦 -𝘕𝘢𝘮𝘦 𝘔𝘪𝘤𝘳𝘰𝘴𝘰𝘧𝘵-𝘌𝘹𝘵𝘳𝘢𝘤𝘵𝘰𝘳-𝘚𝘶𝘪𝘵𝘦
While we were at it, we also added some additional features and improvements. Check out the release notes for all the details.
github.com/invictus-ir/Mi…#stayInvictus#CloudIncidentResponse#MicrosoftExtractorSuite
Defeating the Atlas Lion Threat 🦁
Most threat actors want your data. Atlas Lion (Storm-0539) wants your balance sheet specifically, your gift card portals.
We have been tracking the evolution of this Moroccan-based group. They aren't just sending simple phishing links; they are high-jacking "trust chains" by:
🔹 Enrolling their own Virtual Machines (VMs) directly into your cloud domain.
🔹 Abusing MFA registration to bypass traditional security perimeters.
🔹 Leveraging legitimate platforms like Akamai and Linode to hide in plain sight.
Our latest research on this cloud threat actor is live:
invictus-ir.com/news/atlas-lio…#stayInvictus#CloudIncidentResponse#AtlasLion
📷 The SaaS Hardening Checklist:
- Kill "Shadow Consent" – Disable user consent and implement an Admin Consent Workflow. No unvetted app should touch your data.
- Audit Permissions – Understand Delegated vs. Application-level access to ensure the principle of least privilege.
- Restrict App Access – Require explicit user assignment on first-party apps to block attackers from exploiting "trusted" tools.
- Enforce Hygiene – Build application cleanup into your standard off-boarding process.
Read the full breakdown: invictus-ir.com/news/the-silen…#StayInvictus#SaaS#CloudIncidentResponse#EntraID
Update:
Fingerprinting the HTTP response headers, we identified a unique ETag: W/"16-zUIWjx30dNMOrJoqA1R8JWYnVAw" which is shared between the primary Axios C2 and 23.254.167[.]216; both servers are also hosted on Hostwinds LLC (AS 54290).
This specific IP and ETag fingerprint provide a high-confidence link to the "JustJoin" landing pages. As documented by researchers at Hunt.io, this infrastructure is associated with DPRK-nexus activity. This overlap further supports that the Axios incident is likely linked to a DPRK-nexus 🇰🇵 threat actor.
🚨Axios Attack Infrastructure Update🚨
New C2 pivots reveal a coordinated staging effort. The malicious payload was published by nrwise@proton[.]me a separate account from the ifstap proton address used in the maintainer hijack.
Analysis shows a newly identified and highly likely C2 callnrwise[.]com on the same infrastructure used in the #Axios attack, sharing clear naming similarities with the attacker's Proton account.
#npm#SupplyChainAttack
🚀 Introducing 𝐀𝐥𝐥-𝐈𝐧 access for Cloud Labs
Most cloud security training happens in a vacuum. Real-world attacks don't.
We are incredibly excited to announce the launch of our All-in level for Cloud Labs. Here is what makes this scenario unique:
🌐 Cross-Cloud Attacks: You will trace sophisticated threats that pivot across different cloud environments, mimicking the true complexity of modern, multi-layered breaches.
🛠️ Live Environment Access: You get real, hands-on access to investigate active threat scenarios directly within live Google Workspace and Google Cloud environments.
It is time to test your cloud incident response skills for real!
#stayInvictus#CloudIncidentResponse#CloudLabs
6K Followers 3K FollowingHunt & Response Senior Manager @HuntressLabs || "Competition is the law of the jungle, but cooperation is the law of civilisation” - Kropotkin
492 Followers 4K FollowingSecurity Researcher
-Random Incoherent Ramblings & Idiosyncrasies-
Trying To Add Words To Remaining ~54 Characters,
And Here Comes The Smelly ~~Brain Farts~~
42K Followers 9K FollowingInformation security - #SIEM, #DFIR, #EDR formerly at Gartner! Now @GoogleCloud Office of the #CISO; host of @CloudSecPodcast https://t.co/VpKtfz8nXG
680 Followers 161 FollowingFinancial freedom through options trading so I can retire before my back starts making weird noises. Basically my trading journal. Not trading advice.
58K Followers 1K FollowingONE autonomous platform to prevent, detect, respond, and hunt. Do more, save time, secure your enterprise: https://t.co/N75g1HAnCs 🐱💻
111K Followers 104 FollowingThe world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
22K Followers 599 FollowingDigital forensics and incident response. Ex-AFOSI, Mandiant, and CrowdStrike. SANS Institute Fellow and co-author of #FOR500 and #FOR508 courses.
69K Followers 871 FollowingThreat intelligence platform - Data from Deep Web, Dark Web, Open Web || For data API integration : [email protected] Democratizing Cyber Security.
18K Followers 646 FollowingHacker, trainer, and guitarist | Black Hills InfoSec #RedTeam | @BreakForge Training | Produces music to hack to at @N0BANDW1DTH
9K Followers 1K FollowingBelgian Information Security Conference | #BruCON0x12 (18th edition) Spring Training 22-24 April 2026 | Training 21-23 Sept - Conference 24-25 Sept 2026
7K Followers 383 Following💼 Director of Security
📬 @CloudSecList
📚 https://t.co/TrQKzxfnYg
💬 I write about security strategy, technical leadership, and cloud security.
3K Followers 301 FollowingMacOS Intrusion Analyst, APT Smiter , Haole. Author of OS X Incident Response Scripting and Analysis
Owner of https://t.co/oApHpiRaQ0
193K Followers 412 FollowingSANS is the most trusted and by far the largest source for information & cyber security training, certification and research in the world.