Sign in

Ronnie Salomonsen

@r0ns3n.dk
107 followers 159 following 11 posts

Adversary Methods - Research & Discovery (RAD) Team @Mandiant - Now Part of @GoogleCloud. Former DFIR, Malware & Network Analyst. All tweets are my own.

PostsRepliesMedia
Reposted by Ronnie Salomonsen
gab 🇺🇦🇵🇸 @gabagool.ing · 07/04/2025
Excellent breakdown of the “Rogue RDP” TTP we’ve seen susp Russian APT UNC5837 using in their campaigns written by my colleague Rohit (@IzySec over on X)
cloud.google.com
Windows Remote Desktop Protocol: Remote to Rogue | Google Cloud Blog
A novel phishing campaign by Russia-nexus espionage actors targeting European government and military organizations.
0168
Ronnie Salomonsen @r0ns3n.dk · 07/04/2025
Windows Remote Desktop Protocol: Remote to Rogue cloud.google.com/blog/topics/...
cloud.google.com
Windows Remote Desktop Protocol: Remote to Rogue | Google Cloud Blog
A novel phishing campaign by Russia-nexus espionage actors targeting European government and military organizations.
031
Ronnie Salomonsen @r0ns3n.dk · 13/03/2025
Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers @googlecloud cloud.google.com/blog/topics/...
cloud.google.com
Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers | Google Cloud Blog
We discovered China-nexus threat actors deployed custom backdoors on Juniper Networks’ Junos OS routers.
010
Ronnie Salomonsen @r0ns3n.dk · 03/02/2025
CVE-2023-6080: A Case Study on Third-Party Installer Abuse @googlecloud cloud.google.com/blog/topics/...
cloud.google.com
CVE-2023-6080: A Case Study on Third-Party Installer Abuse | Google Cloud Blog
Mandiant exploited flaws in the Microsoft Software Installer repair action of Lakeside Software's SysTrack installer to obtain arbitrary code execution.
000
Ronnie Salomonsen @r0ns3n.dk · 29/01/2025
ScatterBrain: Unmasking the Shadow of PoisonPlug's Obfuscator @googlecloud cloud.google.com/blog/topics/...
cloud.google.com
ScatterBrain: Unmasking the Shadow of PoisonPlug's Obfuscator | Google Cloud Blog
We been tracking multiple espionage operations conducted by China-nexus actors utilizing POISONPLUG.SHADOW malware.
000
Reposted by Ronnie Salomonsen
Volatility @volatilityfoundation.org · 17/01/2025
@volatilityfoundation.org New Release: #volatility3 v2.11.0 - visit github.com/volatilityfo... for details and downloads. #memoryforensics #dfir
The latest Volatility 3 is now available at https://github.com/volatilityfoundation/volatility3/releases
045
Ronnie Salomonsen @r0ns3n.dk · 19/12/2024
New to Google Secops: Top Ten YARA-L Rules Troubleshooting Tips www.googlecloudcommunity.com/gc/Community...
googlecloudcommunity.com
New to Google Secops: Top Ten YARA-L Rules Troubleshooting Tips
I’ve been asked a few times in the past month for tips that I use to troubleshoot YARA-L rules. As I thought about it, I realized this covers a lot of ground because when building detection logic, we ...
020
Ronnie Salomonsen @r0ns3n.dk · 14/12/2024
XRefer: The Gemini-Assisted Binary Navigator @googlecloud cloud.google.com/blog/topics/...
cloud.google.com
XRefer: The Gemini-Assisted Binary Navigator | Google Cloud Blog
A Gemini-powered tool to reduce response and triage time when faced with increasingly large and complex malware.
021
Ronnie Salomonsen @r0ns3n.dk · 05/12/2024
cloud.google.com/blog/topics/...
000
Ronnie Salomonsen @r0ns3n.dk · 04/12/2024
cloud.google.com/blog/topics/...
010
Ronnie Salomonsen @r0ns3n.dk · 04/12/2024
virustotal.github.io/yara-x/blog/...
000
Reposted by Ronnie Salomonsen
Allison Nixon @nixonnixoff.bsky.social · 02/12/2024
yay this feature is built into bluesky yay
3577
Reposted by Ronnie Salomonsen
Russel Van Tuyl @russelvantuyl.bsky.social · 17/11/2024
Nice write up from Mandiant on some practical use cases for leveraging AI to help red team operations. What are some other use cases ya’ll are thinking of? cloud.google.com/blog/topics/...
cloud.google.com
AI Enhancing Your Adversarial Emulation | Google Cloud Blog
Learn how Mandiant Red Team is using Gemini and LLMs for adversarial emulation and defense.
121
Reposted by Ronnie Salomonsen
Russell Lowery @russell-lowery.bsky.social · 19/11/2024
The bad guys are moving faster. Mandiant analyzed 138 vulnerabilities. 97 of them were exploited before patches were available. #cyber cloud.google.com/blog/topics/...
cloud.google.com
How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends | Google Cloud Blog
Mandiant analyzed 138 vulnerabilities that were disclosed in 2023 and that we tracked as exploited in the wild.
001
Reposted by Ronnie Salomonsen
Will T @bushidotoken.net · 18/11/2024
Looking for more people to follow on BlueSky? Find the @curatedintel.bsky.social folks here: go.bsky.app/Kfp62Uh
32817
Reposted by Ronnie Salomonsen
techy @techy.detectionengineering.net · 18/11/2024
I made a Detection Engineering starter pack, will be adding more as more folks jump over to bluesky! go.bsky.app/HenXJUR
812455
Reposted by Ronnie Salomonsen
PIVOTcon @pivotcon.bsky.social · 19/11/2024
#PIVOTcon25 registration is now OPEN 🤟📥📥📥 pivotcon.org #CTI #ThreatResearch #ThreatIntel Please read carefully the whole 🧵 for the rules about invite -> registration (1/5)
media.tenor.com
two men are standing next to each other with the words " we open it up " on the screen
ALT: two men are standing next to each other with the words " we open it up " on the screen
24222
Ronnie Salomonsen @r0ns3n.dk · 19/11/2024
cloud.google.com/blog/topics/...
cloud.google.com
Empowering Gemini for Malware Analysis with Code Interpreter and Google Threat Intelligence | Google Cloud Blog
When used for malware analysis, Gemini now has capabilities to address obfuscation, and obtain insights on IOCs.
010
Reposted by Ronnie Salomonsen
Austin Larsen @handle.invalid · 18/11/2024
#UNC5537 proved to be one of the most consequential threat actors of 2024 when they launched a campaign in April 2024 that systematically compromised misconfigured SaaS instances across over a hundred organizations. cloud.google.com/blog/topics/...
cloud.google.com
UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion | Google Cloud Blog
A campaign targeting Snowflake customer database instances with the intent of data theft and extortion.
121
Ronnie Salomonsen @r0ns3n.dk · 18/11/2024
Hello World
130