Sign in

Josh Lemon

@joshlemon.bsky.social
58 followers 150 following 34 posts

Chief of DIFR at SoteriaSec | SANS Institute Principal Instructor | Digital Forensics & Incident Response geek.

PostsRepliesMedia
Josh Lemon @joshlemon.bsky.social · 01/03/2026
Memory Analysis for #Linux has always been a bit hit-or-miss. Trail of Bits has released a tool called #mquire that doesn't require debug symbols for the originating Kernel. #MemoryForensics #IncidentResponse #DFIR #DigitalForensics
122
Josh Lemon @joshlemon.bsky.social · 26/02/2026
How would your organisation fare in detecting IP theft via a hard drive connected to a sensitive system? "Williams used a portable external hard drive to transfer the exploits out of secure networks at Trenchant's offices in Sydney and Washington, D.C." www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker
The former head of Trenchant, a specialized U.S. defense contractor unit, was sentenced Tuesday to more than seven years in federal prison for stealing and selling zero-day exploits to a Russian broke...
000
Josh Lemon @joshlemon.bsky.social · 03/02/2026
Microsoft is moving to disable NTLM by default, with some exceptions. If implemented, this will have a significant impact on threat actors abusing credentials within a network. #SecOps #IncidentResponse #ThreatDetection #SOC 🔗 techcommunity.microsoft.com/blog/windows...
141
Josh Lemon @joshlemon.bsky.social · 15/12/2025
Got some time at the end of the year? We’ve just published the SANS Institute Detection and Response Survey results. Free Download (requires login only) 🔗 go.sans.org/detection-re... #DnR #ThreatDetection #IncidentResponse #CSIRT #SOC #CERT #Cybersecurity
100
Josh Lemon @joshlemon.bsky.social · 18/11/2025
I'm not sure how accurate this is, but The Verge is reporting that #SysMon will be integrated into Windows 11 early next year. This will be a massive win for #DFIR and #SecOps people everywhere if it's correct. www.theverge.com/news/821948/...
000
Josh Lemon @joshlemon.bsky.social · 18/09/2025
Wow, Microsoft is removing #WMIC from Windows! But they aren't removing the underlying WMI framework, so threat actors will have to use PowerShell to access WMI. 🔗 techcommunity.microsoft.com/blog/windows... #IncidentResponse #ThreatDetection #ThreatIntel #CSIRT #CERT
120
Josh Lemon @joshlemon.bsky.social · 28/08/2025
That's a bit nasty - a threat actor uses #Velociraptor as their primary C2 implant on the victim's system. You think they might also let the victim use it for responding to the compromise as well? 😂 news.sophos.com/en-us/2025/0... #DFIR #IncidentResponse #ThreatDetection #ThreatIntel
000
Josh Lemon @joshlemon.bsky.social · 19/07/2025
"I SPy" Entra ID Global Admin Escalation Technique Datadog's Security Labs identified an abuse of Office 365 Exchange Online service principal (SP) allowing escalation to Global Admin. MSRC considers it "expected misconfiguration" so don't expect a fix. 🔗 securitylabs.datadoghq.com/articles/i-s...
100
Josh Lemon @joshlemon.bsky.social · 09/07/2025
This is a timely reminder to ensure any third-parties with access to your systems follow the same cyber policies you'd expect your internal staff to follow. www.bleepingcomputer.com/news/securit... #IncidentReponse #DataBreach #CSIRT
bleepingcomputer.com
M&S confirms social engineering led to massive ransomware attack
M&S confirmed today that the retail outlet's network was initially breached in a "sophisticated impersonation attack" that ultimately led to a DragonForce ransomware attack.
200
Josh Lemon @joshlemon.bsky.social · 28/04/2025
This is an interesting write up on a slightly different #Docker #container #malware attack from the Cado Security and Darktrace teams. 🔗 www.darktrace.com/blog/obfusca...
122
Josh Lemon @joshlemon.bsky.social · 23/04/2025
Here's an update on the data breach of court documents from the NSW JusticeLink website. tl;dr - it was an individual that was able to download +9k documents over two months, it doesn't appear they were leaked anywhere publicly. www.theguardian.com/australia-ne...
theguardian.com
NSW man charged over ‘serious data breach’ that exposed thousands of sensitive court documents
More than 9,000 files downloaded from NSW JusticeLink system but authorities say no personal data compromised
000
Josh Lemon @joshlemon.bsky.social · 23/04/2025
This is a really nice write up from Sekoia with lots of #ThreatDetection details, regardless of the #EDR you're using. 🔎 Of particular note, this attack is aided with a .LNK file pulling in a .HTA via a remote location.
120
Josh Lemon @joshlemon.bsky.social · 19/04/2025
🚨 New Critical RCE in Erlang/0TP SSH (CVSS 10) - CVE-2025-32433 - Exploitable without authentication needed - Exists in Erlang's built-in SSH server - Commonly found in loT and Teleco gear - Exploit model now in Metasploit and on GitHub
100
Josh Lemon @joshlemon.bsky.social · 25/03/2025
With all the talk about the use of #Signal by government officials in the US, it's worth remembering #ThreatActors will target what they need to steal the data they want. 🔗 cloud.google.com/blog/topics/...
100
Josh Lemon @joshlemon.bsky.social · 02/03/2025
#BYOVD attacks are slowly becoming more common for threat actors to escalate privilege and kill security tools. Make sure you're #ThreatHunting for new Vulnerable Drivers! #IncidentResponse #ransomware #ThreatDetection
Image
100
Josh Lemon @joshlemon.bsky.social · 12/02/2025
Join me for SANS Institute #Perth Community Night today! 📋 Registration Thurs, 13 Feb 2025 5:30pm – 6pm 🎤 Presentation 6pm – 7pm Register Here: www.sans.org/mlp/community-night-pe… 📍The Pan Pacific Perth Hotel, 207 Adelaide Terrace, Perth WA 6000
000
Josh Lemon @joshlemon.bsky.social · 15/01/2025
I just found this amazing repository of credential stealer system info files by #MalBeacon, along with #YARA sigs for them. Useful to ID a cred stealer or going #ThreatHunting. github.com/MalBeacon/wh... #threatintel #infosec #malware #DFIR
github.com
GitHub - MalBeacon/what-is-this-stealer: A repository of credential stealer formats
A repository of credential stealer formats . Contribute to MalBeacon/what-is-this-stealer development by creating an account on GitHub.
000
Josh Lemon @joshlemon.bsky.social · 15/01/2025
The #FBI mass-removed #PlugX #malware from infected US computers. The infections were attributed to #MustangPanda (aka #TwillTyphoon). buff.ly/3PBmOpe #IncidentResponse
bleepingcomputer.com
FBI wipes Chinese PlugX malware from over 4,000 US computers
​The U.S. Department of Justice announced today that the FBI has deleted Chinese PlugX malware from over 4,200 computers in networks across the United States.
100
Josh Lemon @joshlemon.bsky.social · 14/01/2025
#Ransomware threat actors are increasingly abusing #AWS Server-Side Encryption (SSE-C) to encrypt S3 buckets. Most recently a TA known as #Codefinger is using this technique. 🕵 Monitoring S3 & encryption activity via CloudTrail & GuardDuty. www.halcyon.ai/blog/abusing... #CloudForensics #FOR509
halcyon.ai
Abusing AWS Native Services: Ransomware Encrypting S3 Buckets with SSE-C
The Halcyon RISE Team has identified a unique ransomware technique that encrypts Amazon S3 buckets with no known method to recover unless a ransom is paid...
010