Sign in

Jorge Orchilles

@jorgeorchilles.bsky.social
755 followers 46 following 3.8K posts

SANS Principal Instructor & Author #SEC565 | #RedTeam | #PurpleTeam | #PenTest | #C2Matrix Creator | ATT&CK & Atomic Red Team Contributor | Published Author

PostsRepliesMedia
Jorge Orchilles @jorgeorchilles.bsky.social · 18/04/2025
Save the date and register for the official release of the 2025 Verizon Data Breach Investigations Report hashtag#DBIR aka THE REPORT on April 23: www.brighttalk.com/webcast/1509...
brighttalk.com
2025 Data Breach Investigations Report Key Findings
The Verizon Data Breach Investigations Report (DBIR) is the authoritative source of cybersecurity breach information. This annual report provides an unparalleled, data-driven analysis of real-world cy...
000
Jorge Orchilles @jorgeorchilles.bsky.social · 07/04/2025
At VulnCon this week, if you are here, say hi. Already got a ton of value from this conference: did an SBOM workshop, a couple VEX talks from folks leading that effort in Cisco and Nvidia, and of course AI. Looking forward for the next few days!
000
Jorge Orchilles @jorgeorchilles.bsky.social · 06/03/2025
Formula 1 is back! If you played last year, you can rejoin without a passcode. If you would like to play, set up a team at fantasygp.com and DM me for the code to join #InfoSecF1
000
Reposted by Jorge Orchilles
Jake Williams @malwarejake.bsky.social · 29/01/2025
Threat intelligence is about more than just regurgitating indicators you found in someone else's reports. If this is your idea of "threat intelligence" then AI is 100% coming for your job.
4403
Reposted by Jorge Orchilles
The DFIR Report @thedfirreport.bsky.social · 27/01/2025
🌟New report out today!🌟 Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware Analysis & reporting completed by @r3nzsec, @MyDFIR & @MittenSec. Audio: Available on Spotify, Apple, YouTube and more! thedfirreport.com/2025/01/27/c...
thedfirreport.com
Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware
Key Takeaways This intrusion began with the download and execution of a Cobalt Strike beacon that impersonated a Windows Media Configuration Utility. The threat actor used Rclone to exfiltrate data…
12410
Reposted by Jorge Orchilles
hasherezade.bsky.social @hasherezade.bsky.social · 26/01/2025
In case if you wonder what broke #ProcessHollowing on Windows 11 24H2, I have something for you: hshrzd.wordpress.com/2025/01/27/p...
hshrzd.wordpress.com
Process Hollowing on Windows 11 24H2
Process Hollowing (a.k.a. RunPE) is probably the oldest, and the most popular process impersonation technique (it allows to run a malicious executable under the cover of a benign process). It is us…
05838
Reposted by Jorge Orchilles
Olaf Hartong @olafhartong.nl · 30/12/2024
FalconHound 1.4.2 is out! * Added Managed identity authentication for Azure based inputs (KeyVaults, MDE, Sentinel, GraphAPI) * Added report command line option and actions * Added HTML output option Grab it here > github.com/FalconForceT...
github.com
Releases · FalconForceTeam/FalconHound
FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log ag...
01810
Reposted by Jorge Orchilles
Gerald Auger, PhD @geraldaugerphd.bsky.social · 16/12/2024
Wicked pumped for our community to have won the SANS Difference Makers award 2024 "Podcast of the Year" Community, Cyber, Coffee, and Carl
172
Reposted by Jorge Orchilles
Matt Johansen @mattjay.com · 13/12/2024
The Paranoids @ Yahoo was one of the oldest, largest, and highest reputation internal security teams in the industry. A lot of good talent was built and trained there. This is a shame.
1236
Reposted by Jorge Orchilles
Jake Williams @malwarejake.bsky.social · 04/12/2024
If they find the perpetrator, I can't imagine how they manage to avoid jury nullification. It's not just patients. Change Healthcare (part of United) turned the lives of so many provider upside down and most will never be made whole. nypost.com/2024/12/04/u...
nypost.com
Exclusive | UnitedHealthcare CEO Brian Thompson fatally shot outside Hilton hotel in Midtown in possible targeted attack: sources
The CEO of UnitedHealth was fatally shot in the chest Wednesday morning outside the Hilton hotel in Midtown in what police say was a targeted attack.
2162
Reposted by Jorge Orchilles
Christopher Peacock @securepeacock.bsky.social · 04/12/2024
Purple Team metrics can be tough and conflated with BAS testing so here’s a few, but feel free to add your own in the comments. 1. Engagements with SOC per year/quarter. 2. Intel leads tested. 3. Custom tests to verify detection logic. 4. Request for testing completed %
1113
Jorge Orchilles @jorgeorchilles.bsky.social · 26/11/2024
Excellent write up from the folks @volexity.com www.volexity.com/blog/2024/11...
volexity.com
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...
020
Reposted by Jorge Orchilles
Jake Williams @malwarejake.bsky.social · 22/11/2024
You won't always win. That's okay. The goal is to win as many as you can and learn as much as you can from the ones you lose.
0312
Jorge Orchilles @jorgeorchilles.bsky.social · 22/11/2024
Hi friends! Just switched over. Please connect so I can follow you back!
020
Jorge Orchilles @jorgeorchilles.bsky.social · 27/10/2024
This was before lights out. I took the pic and called it. #F1 #MexicoGP
000
Jorge Orchilles @jorgeorchilles.bsky.social · 04/09/2024
I first met @bsdaemon when I was randomly put on the BRA (Brasil) team at Hack Cup too many years ago (we went on to win and get free tickets to INFILTRATE). I had no idea who he was other than just a kind, fun dude that played soccer. Here is his profile:...
100
Jorge Orchilles @jorgeorchilles.bsky.social · 09/05/2024
C2 via Microsoft Windows print functionality? Yes please: diverto.hr/en/blog/2024-05-03-MS-Wi… Thanks for @c2_matrix shout out
diverto.hr
Abusing MS Windows printing for C2 communication
Diverto is an information security company. We provide co...
000
Jorge Orchilles @jorgeorchilles.bsky.social · 22/04/2024
We need to reset expectations. LLMs are not "discovering" novel attacks or 0days. They are lowering the barrier for entry for all types of hackers. Embrace it, let it help you. Criminals already are: thehackernews.com/2024/04/microsoft…
thehackernews.com
Microsoft Warns: North Korean Hackers Turn to AI-Fueled C...
North Korea's state-linked hackers are enhancing their op...
000
Jorge Orchilles @jorgeorchilles.bsky.social · 06/04/2024
Spotted @BSidesTampa Learning some more Azure stuff with @SecurePeacock and a nice little demo @mrgretzky may recognize the tool
000
Jorge Orchilles @jorgeorchilles.bsky.social · 24/03/2024
I should have stayed up for this race! My fantasy team did terrible but how about Ferrari!!!!! #InfoSecF1
000
Jorge Orchilles @jorgeorchilles.bsky.social · 21/03/2024
Spent the last year @Verizon running the offensive security team (more accurately called Readiness and Proactive Security) One of the innovative things I got to do was build an AI Red Team with @teschulz We will share lessons learned and how to get...
100
Jorge Orchilles @jorgeorchilles.bsky.social · 20/03/2024
Anyone have an extra ticket for Wicys? I have a direct report that has booked flight and hotel but now needs a ticket. This will be her first time attending, please RT for reach.
000
Jorge Orchilles @jorgeorchilles.bsky.social · 11/03/2024
2nd race of the 2024 season in the books with @SecurePeacock taking P1. @paulpols and I sharing the podium with him. Paul manages to hold on to the lead but a long way to go with 22 more races this season! #InfoSecF1
000
Jorge Orchilles @jorgeorchilles.bsky.social · 06/03/2024
The AI Red Team @Verizon is growing! Join me and @teschulz as we continue building one of the best AI Red Team in the industry: verizon.wd5.myworkdayjobs.com/veriz…
verizon.wd5.myworkdayjobs.com
Verizon Updated Candidate Home | Verizon Careers
000
Jorge Orchilles @jorgeorchilles.bsky.social · 02/03/2024
First #InfoSecF1 results are in! Congrats to @paulpols and @MarcOverIP for P1 and P2
000
Jorge Orchilles @jorgeorchilles.bsky.social · 26/02/2024
Who is ready for #InfosecF1 fantasy league?? Sign up at fantasygp.com and dm me for the access code
000
Jorge Orchilles @jorgeorchilles.bsky.social · 23/02/2024
Blink twice if you aren’t a deepfake
000
Jorge Orchilles @jorgeorchilles.bsky.social · 19/01/2024
AI/ML vulnerabilities aren't as ground breaking as you may think... protectai.com/threat-research/janua…
protectai.com
Protect AI's January 2024 Vulnerability Report
At Protect AI we are taking a proactive approach to ident...
000
Jorge Orchilles @jorgeorchilles.bsky.social · 18/01/2024
15 years of being off and on this platform. Do you remember when you joined X? I do! #MyXAnniversary
000
Jorge Orchilles @jorgeorchilles.bsky.social · 10/01/2024
CVSS is for individual vulns, combine these two and you have a 10 that is actively exploited in the wild, no patch, but there is a workaround: CVE-2023-46805 (Authentication Bypass) & CVE-2024-21887 (Command Injection) for Ivanti Connect Secure and Ivanti Policy Secure Gateways
000
Jorge Orchilles @jorgeorchilles.bsky.social · 07/12/2023
Red + Blue + Llama = Purple Llama about.fb.com/news/2023/12/purple-ll…
about.fb.com
Introducing Purple Llama for Safe and Responsible AI Deve...
Purple Llama will bring together tools and evaluations to...
000
Jorge Orchilles @jorgeorchilles.bsky.social · 30/11/2023
Lazy web, is there a common syntax/method to share threat modeling information? I feel output is often a report with diagrams created in various tools and the tools are all spitting out proprietary artifacts.
000
Jorge Orchilles @jorgeorchilles.bsky.social · 30/11/2023
Just heard on a webinar that #purpleteam is hard and expensive. Do you agree?
000
Jorge Orchilles @jorgeorchilles.bsky.social · 29/11/2023
Ask your favorite GenAI to repeat the same word forever. That is the exploit. Fits in a tweet: not-just-memorization.github.io/ext…
not-just-memorization.github.io
Extracting Training Data from ChatGPT
000
Jorge Orchilles @jorgeorchilles.bsky.social · 29/11/2023
Does your AI Red Teaming include safety and fairness testing? Waiting for the NIST definition but the joint release of "Guidelines for secure AI system development" does not include it. See page 15: www.ncsc.gov.uk/files/Guidelines-fo…
000
Jorge Orchilles @jorgeorchilles.bsky.social · 29/11/2023
Super easy plan to run a #PurpleTeam Exercise from @Sam0x90 I like the spreadsheet it comes with for tracking results: github.com/Sam0x90/CTI/tree/main/Ad…
github.com
CTI/Adversary Emulation Plans/2022_Top35_Mitre at main · ...
Repo containing various intel-based resources such as thr...
000
Jorge Orchilles @jorgeorchilles.bsky.social · 17/11/2023
I am actually up and ready to watch the first practice in Las Vegas! #InfoSecF1
100
Jorge Orchilles @jorgeorchilles.bsky.social · 01/11/2023
Our Red Team Operations and Adversary Emulation course now has a certification: GIAC Red Team Professional (GRTP) Take the course and pass the test to get the cert: www.sans.org/cyber-security-courses… #redteam #adversaryemulation...
sans.org
SEC565: Red Team Operations and Adversary Emulation for S...
Learn Red Team operations and adversary emulation for sec...
100
Jorge Orchilles @jorgeorchilles.bsky.social · 30/10/2023
NIST is now showing the Curl vulnerability CVE-2023-38546 as a LOW (CVSSv3 of 3.7): nvd.nist.gov/vuln/detail/CVE-2023-3… Wondering how many of you had this as a critical because you only use CVSS Base scores and not environmental ;)
nvd.nist.gov
NVD - CVE-2023-38546
000
Jorge Orchilles @jorgeorchilles.bsky.social · 30/10/2023
Have you tested RMMs in your environment? Do you only allow and try to prevent/detect all the others? That is the C2 of choice in 2023. Here is yet another example and excellent report from @TheDFIRReport...
100
Jorge Orchilles @jorgeorchilles.bsky.social · 12/10/2023
Call to action! Read the Purple Team Exercise Framework, plan an exercise in Q4, and use this scenario from @MITREattack CTID: github.com/center-for-threat-inform… It is all...
github.com
adversary_emulation_library/ocean_lotus/Emulation_Plan/Oc...
An open library of adversary emulation plans designed to ...
100
Jorge Orchilles @jorgeorchilles.bsky.social · 21/09/2023
Cisco to acquire Splunk for $28B newsroom.cisco.com/c/r/newsroom/en/…
newsroom.cisco.com
Cisco Intends to Acquire Splunk
The combination of these two innovative leaders makes the...
010
Jorge Orchilles @jorgeorchilles.bsky.social · 21/09/2023
Ghostwriter v4 is out for those using free and open source reporting frameworks for #redteam posts.specterops.io/ghostwriter-v4-…
posts.specterops.io
Ghostwriter v4: 2FA, RBAC, and Logging, Oh My!
Ghostwriter v4 is officially here! Technically, it’s been...
000
Jorge Orchilles @jorgeorchilles.bsky.social · 13/09/2023
Haven't played with CALDERA in a while but going to check out the newest version and then try the OT plugin: github.com/mitre/caldera-ot Anyone check this out yet?
github.com
GitHub - mitre/caldera-ot: MITRE Caldera™ for OT Plugins ...
MITRE Caldera™ for OT Plugins & Capabilities. Contribute ...
000
Jorge Orchilles @jorgeorchilles.bsky.social · 23/08/2023
If you use WinRAR, upgrade to 6.23 now. Reading the release notes shows 2 vulns were fixed: CVE-2023-40477 and CVE-2023-38831 The later has been exploited since April according to Group-IB: www.group-ib.com/blog/cve-2023-3883… Release notes:...
group-ib.com
Cybersecurity Services, Solutions & Products. Global Prov...
Leading provider of cybersecurity solutions: Threat Intel...
100
Jorge Orchilles @jorgeorchilles.bsky.social · 08/08/2023
Almost there!!!
000
Jorge Orchilles @jorgeorchilles.bsky.social · 03/08/2023
Dedicated Purple Team role at Meta: www.metacareers.com/v2/jobs/9690864…
metacareers.com
Error
Meta's mission is to build the future of human connection...
000
Jorge Orchilles @jorgeorchilles.bsky.social · 20/07/2023
RIP www.dignitymemorial.com/obituaries/…
dignitymemorial.com
Attention Required! | Cloudflare
000
Jorge Orchilles @jorgeorchilles.bsky.social · 13/07/2023
Building a #redteam? Go #purpleteam first. I like the new graphic @brysonbort scythe.io/library/building-an-inter…
000
Jorge Orchilles @jorgeorchilles.bsky.social · 11/07/2023
Big patch Tuesday today www.bleepingcomputer.com/news/micro…
000