Sign in

Matt Bromiley

@bromiley.io
2.9K followers 119 following 106 posts

⚙️ AI Security R&D @ Prophet Security 🎓 IR/TH/Incident Management Instructor 🎙️ Frequent Guest on Cybersecurity Defender's Podcast 🔍 Where to Find Me: github.com/bromiley

PostsRepliesMedia
Matt Bromiley @bromiley.io · 21/05/2026
I need a version of Ants Marching that is updated to reflect AI agents doing their thing.
001
Matt Bromiley @bromiley.io · 30/04/2026
Narrator: And that was a lie…
000
Matt Bromiley @bromiley.io · 11/02/2026
Chong Lua Dao, whoever you are…thanks /sarcasm
000
Matt Bromiley @bromiley.io · 29/01/2026
I just typed out “I know what I’m doing in Nano Banana tonight”, and it was a completely innocent task. This is reality.
000
Matt Bromiley @bromiley.io · 18/01/2026
One of my favorite accounts to read is @hardwaterhacker.bsky.social with his photography. I marvel, and then try to replicate. Here’s me dipping my toes in the water, catching decaying remnants of humanity in nature. #nationalparks #photography
180
Matt Bromiley @bromiley.io · 07/01/2026
Remember, remember the Seventh of January, The fracture, the fog, the delay. I see no reason why chaos and fury Should ever become “the way”. When noise wears the mask of conviction, And volume is mistaken for might, It isn’t the loud who should lead us forward, But truth that survives the night.
100
Matt Bromiley @bromiley.io · 18/12/2025
Tonight’s “in the air again” question: Why did you convert an int to a float to just then convert it back to an int again? “You’re absolutely right!”
100
Matt Bromiley @bromiley.io · 20/11/2025
@eric.zip always compiling and releasing some of the hottest - but most necessary - modern tools. Can’t wait to sink my teeth into this.
120
Reposted by Matt Bromiley
Eric Capuano @eric.zip · 19/11/2025
I have always wanted an app like Zimmerman's Timeline Explorer, but for macOS.... Sadly, nothing remotely close exists except Excel 🤮 Stoked to say, I am nearly done with the the MVP! 😎 Supertimelines on MBP! #dfir
1347
Matt Bromiley @bromiley.io · 13/11/2025
I’m normally quiet about these things, but have to share a moment of laughter. If someone refers to you as “the dog that hasn’t barked”, you’re not the most powerful person in the room. That’s leverage.
021
Matt Bromiley @bromiley.io · 18/08/2025
Aww yissssssss...
030
Matt Bromiley @bromiley.io · 11/08/2025
BSky Outreach - Anyone here an Obsidian user (for notes, "second brain", etc.)? Anyone want to sing their praises in a reply; I'm curious what your experience has been like.
300
Matt Bromiley @bromiley.io · 11/08/2025
Usage spent towards troubleshooting Anthropic connectivity shouldn't count against your daily quota...
000
Matt Bromiley @bromiley.io · 11/08/2025
Has anyone been able to get Notion's MCP to stay connected for more than 1 hour? This thing is about as stable as a baby deer.
110
Reposted by Matt Bromiley
Olaf Hartong @olafhartong.nl · 06/08/2025
During my #BHUSA talk I've released many ETW research tools, of which the most notable is BamboozlEDR. This tool allows you to inject events into ETW, allowing you to generate fake alerts and blind EDRs. github.com/olafhartong/... Slides available here: github.com/olafhartong/...
github.com
GitHub - olafhartong/BamboozlEDR: A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.
A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes. - olafhartong/BamboozlEDR
02515
Reposted by Matt Bromiley
Whitney Champion 🍪 @whit.zip · 03/08/2025
day 1 of black hat 2025 in the books 🤓💙🌈 never a dull moment nerding with @eric.zip and @bromiley.io @blackhatevents.bsky.social #BlackHatUSA
bhbhbhbh
1232
Matt Bromiley @bromiley.io · 22/07/2025
Just to think, there _are_ people distracted by the MLK files.
010
Matt Bromiley @bromiley.io · 21/07/2025
T-minus 12 days until my favorite humans - @eric.zip & @whit.zip - and I deliver our Advanced Security Operations and Threat Hunting training at @blackhatevents.bsky.social. If you're a SOC analyst and/or work in IR, we'd love to have you. Come level up with us :) www.blackhat.com/us-25/traini...
blackhat.com
Black Hat
Black Hat
063
Matt Bromiley @bromiley.io · 21/07/2025
No, THIS is the guy to follow. Pro tip: I follow @eric.zip therefore YOU should follow Eric.
150
Matt Bromiley @bromiley.io · 21/07/2025
As is @philhagen.com !! Sharing the DFIR love
030
Matt Bromiley @bromiley.io · 20/07/2025
Feels like a fresh start, so let's make it one. Nice to meet you :) I'm a #cybersecurity nerd | security ai r&d @prophetsecurity.bsky.social | frequent trainer @sansinstitute.bsky.social, @blackhatevents.bsky.social, and other conferences | Cybersecurity Defenders Podcast | forever #blueteam.
070
Matt Bromiley @bromiley.io · 20/07/2025
Defenders out there - CVE-2025-53770 is an unpatched, actively exploited vulnerability in SharePoint. If you have on-prem SharePoint facing the Internet, roll up your sleeves. Microsoft's guidance: 1. Configure the Windows AMSI integrations and deploy Defender AV. 2. Disconnect from the Internet.
0114
Matt Bromiley @bromiley.io · 19/06/2025
They’ve done it again…
030
Reposted by Matt Bromiley
Whitney Champion 🍪 @whit.zip · 20/05/2025
ATTN NERDS: we'll be teaching at @blackhatevents.bsky.social during hacker summer camp again! come join me and @eric.zip and @bromiley.io for our 4-day training: Advanced Security Operations and Threat Hunting 🤓🔥💙 www.blackhat.com/us-25/traini...
asoth
0175
Matt Bromiley @bromiley.io · 17/03/2025
No matter where in the world you go, one thing remains the same: the guy at the gym who slams weights down and then looks around to see who noticed. 🤦‍♂️
010
Matt Bromiley @bromiley.io · 10/02/2025
Kendrick Lamar just owned 2025.
020
Reposted by Matt Bromiley
DDI Training @digitaldefenseinstitute.com · 07/02/2025
ATTN NERDS: We'll be at @blackhatevents.bsky.social USA again this year! Registration is now open for our Advanced Security Operations and Threat Hunting course 🤓🔥💙 Join @eric.zip, @bromiley.io, and @whit.zip for our 4-day training: www.blackhat.com/us-25/traini...
black hat training course
0136
Reposted by Matt Bromiley
tuckner @johntuckner.me · 30/01/2025
Secure Annex can now be used directly from with @limacharlie.io 's SecOps Cloud Platform. Installed agents give visibility into extensions utilized and are now enriched. These attributes can be used to run D&R rules for immediate response to issues. limacharlie.io/blog/automating_brow……
limacharlie.io
LimaCharlie & Secure Annex: Browser Extension Security
Automate browser extension security monitoring with LimaCharlie and Secure Annex. Learn about detection rules, vulnerability monitoring, and comprehensive management tools for enhancing your…
151
Matt Bromiley @bromiley.io · 29/01/2025
Another week, another episode of The Cybersecurity Defender's Podcast in the books with @tekgrunt.bsky.social !! More podcasting news on the horizon for me, but always a fun weekly chat with Chris @limacharlie.io. Check the podcast out here: limacharlie.io/podcast
040
Matt Bromiley @bromiley.io · 29/01/2025
Amplifying this for awesome conferences and unique CFP opportunities!
010
Matt Bromiley @bromiley.io · 29/01/2025
Good article and statistics on lengths of time for adversary activities. I always like seeing this annual statistics to get an idea of how things have "improved", for either side. Key figure: An average of 48 minutes "breakout time". A quick 🧵
110
Matt Bromiley @bromiley.io · 27/01/2025
If you haven't yet subscribed to @johntuckner.me's @secureannex.com "Just Browsing" newsletter, then your inbox is clearly suffering. However, a little something that caught my eye today: "...some individual users have as many as 6 browsers installed on their devices!" A quick 🧵...
210
Matt Bromiley @bromiley.io · 27/01/2025
As if @haroonmeer.canary.love and company couldn’t get any better, I must now find a way to play Padel with them!
110
Matt Bromiley @bromiley.io · 23/01/2025
One of my favorite weekly activities: Recording the Cybersecurity Defender's Podcast with @tekgrunt.bsky.social. I love that @riversidefm.bsky.social gives us quick snippets and pictures to share. Watch out for the next episode soon!
061
Matt Bromiley @bromiley.io · 23/01/2025
How about instead of "thinking about" banning links from X, just do it and move on? Actions speaker louder than words.
170
Matt Bromiley @bromiley.io · 18/01/2025
I'm not trying to chase technology, but the speed at which the M4 Max is creating videos is just insanely quick. Definitely the right choice to go all in on this one.
010
Matt Bromiley @bromiley.io · 14/01/2025
Currently running a cloud-focused workshop in Monaco @ the @first.org European Symposium, and naturally the Notion Incident Management System (NIMS) by @eric.zip and @whit.zip came up. I highly recommend checking this out for effective, automated incident management! nims-template.notion.site
nims-template.notion.site
Notion Incident Management System (NIMS) | Notion
A Notion-based Incident Management System template for SOC and IR teams.
051
Matt Bromiley @bromiley.io · 14/01/2025
@whit.zip equally also one of the coolest people I know, thank you!!
010
Reposted by Matt Bromiley
LimaCharlie @limacharlie.io · 13/01/2025
In Monaco for #TFCSIRT & FIRST Europe? Catch @bromiley.io's advanced threat hunting workshop tomorrow - real-world attack scenarios, open-source tools, and hands-on practice for hybrid cloud security. See you there! www.first.org/events/sympo...
022
Matt Bromiley @bromiley.io · 10/01/2025
This was a fun episode to record with Jason, highly recommend checking out his advice and journey!
000
Reposted by Matt Bromiley
Cyber on the Edge @handle.invalid · 10/01/2025
A great CISO isn't just technical - they build relationships to help manage risk while asking the right questions. In Episode 6, Jason Rebholz explained some key objectives for today's CISOs. Watch or listen to the full episode here: cyberontheedge.fm/episode/epis... #Leadership #Cybersecurity
121
Reposted by Matt Bromiley
LimaCharlie @limacharlie.io · 08/01/2025
Dallas fam! Come hang with industry vets Ken Westin and @bromiley.io for a FREE hands-on workshop. We're diving into Okta detection & IR automation - perfect for MSSPs and IR teams. Plus, drinks after! Limited spots, don't miss out! lu.ma/st0hr2mx #cybersecurity #mssp #infosec
044
Matt Bromiley @bromiley.io · 03/01/2025
T-minus 35 minutes. Come join me as we talk about the browser extension fiasco that happened during the Christmas holidays. Let's hit 2025 running - I hope to see you there!
052
Reposted by Matt Bromiley
LimaCharlie @limacharlie.io · 02/01/2025
We're back with Defender Fridays tomorrow at 10:30am PT / 1:30pm ET - Matt Bromiley from LimaCharlie will talk about safe browser extensions. Come join the conversation! limacharlie.io/defender-fri...
043
Matt Bromiley @bromiley.io · 30/12/2024
I’m not sure what y’all asked for for Christmas, but watching @johntuckner.me dissect the Cyberhaven browser extension compromise is the gift I didn’t know I needed. This is a literal play-by-play, annotated analysis of a significant browser-borne threat.
340
Matt Bromiley @bromiley.io · 22/12/2024
Not that I had my doubts, but just a quick lookup in @johntuckner.me's @secureannex.com to validate I'm installing what I'm expecting. This is a must-have reference for anyone analyzing and/or managing Chrome extensions.
130
Matt Bromiley @bromiley.io · 17/12/2024
Dannng - always feels a bit personal when researchers are targeted. Threat actor MUT-1244 trojanized GitHub tools to steal 390K+ credentials, targeting security researchers and pentesters. Lesson? Vet all tools—even exploit PoCs. Don't just clone and run! More here:
buff.ly
Getting a taste of your own medicine: Threat actor MUT-1244 targets offensive actors, leaking hundreds of thousands of credentials | Datadog Security Labs
This post describes an in-depth investigation by Datadog security researchers into a threat actor dubbed MUT-1244, which targets other malicious actors as well as security practitioners and academics.
030
Matt Bromiley @bromiley.io · 15/12/2024
I'm not sure if Ben Reardon is on bsky (or else I'd tag), but I highly recommend defenders check out this @corelight-inc.bsky.social blog post on Ben's quick network detection work on a newly-released SSH scanner: corelight.com/blog/black-h... CC: @philhagen.com for some awesome insight
corelight.com
Black Hat USA 2024: Tales from the NOC | Corelight
Recapping our learnings from the Network Operations Center (NOC) at Black Hat USA 2024. Using historical network logs to detect threats during the Network Operations Center (NOC) at Black Hat USA 2024...
041
Matt Bromiley @bromiley.io · 15/12/2024
Say what you want about the “hacker”movie Swordfish, Paul Oakenfold ripped out a banger of a soundtrack.
260