Sign in

Christopher Peacock

@securepeacock.bsky.social
1.2K followers 127 following 32 posts

I find weird things on networks. #PurpleTeam | Ex Raytheon MSSP, SCYTHE, & GD | Taught at BlackHat & DEFCON | #100DaysofSigma | Keep exploring, keep learning, and stay curious.

PostsRepliesMedia
Christopher Peacock @securepeacock.bsky.social · 29/01/2026
I’m gonna need a copy of coalfire’s contract template since it’s battle tested and held up in court 😆 arstechnica.com/security/202...
arstechnica.com
County pays $600,000 to pentesters it arrested for assessing courthouse security
Settlement comes more than 6 years after Gary DeMercurio and Justin Wynn's ordeal began.
020
Christopher Peacock @securepeacock.bsky.social · 05/01/2026
AI can help build C2s and payloads, but often this seems to be the case.
010
Reposted by Christopher Peacock
CyberRaiju @jaiminton.com · 24/06/2025
New Octowave Loader sample is leading to Amatera Stealer deployment over the past week. 0 VT detections on any component of the malware loader. Proofpoint rules detect the outbound C2 traffic. My Yara rule detects the installer.
264
Christopher Peacock @securepeacock.bsky.social · 05/04/2025
This seems like a project to watch 👀
120
Christopher Peacock @securepeacock.bsky.social · 26/03/2025
How to properly evaluate a CVE score: 1. Is Gossi freaking out? 2. Is Florian freaking out? 3. Does SANS have an emergency webcast? 4. Are all your red team friends losing their minds over how crazy easy it is to give them awesome access.
073
Christopher Peacock @securepeacock.bsky.social · 11/03/2025
I can’t make this up. I bought an expired MSSP domain, and set up mail forwarding for all emails. I’ve tried to unsubscribe from getting an ISAC’s TLP Amber emails but they wont stating I must, “email from an email associated with the ISAC account receiving these emails.” 🤦‍♂️
110
Christopher Peacock @securepeacock.bsky.social · 23/02/2025
I checked out the #ZeroDay series on Netflix and I think this depiction of events would take too many coordinated attacks. The Russian targeting of Ukraine with Blackenergy and Industroyer is more realistic to what happens. The scenes I saw more resemble an EMP attack.
010
Christopher Peacock @securepeacock.bsky.social · 22/02/2025
Stock up toilet paper now! 😂 www.scmp.com/news/china/s...
scmp.com
Chinese team finds coronavirus that could infect humans via same route as Covid
Research was led by Shi Zhengli, a virologist known as the ‘batwoman’, who is best known for her work on coronaviruses at a lab in Wuhan.
010
Christopher Peacock @securepeacock.bsky.social · 14/02/2025
This is why I think TTP count is a terrible metric. You either detect the procedure adversaries use or you don’t, this count of 4 for whoami /all is meaningless in most cases.
130
Christopher Peacock @securepeacock.bsky.social · 10/02/2025
Before rushing to secure GenAI, make sure your DevSecOps and AppSec foundations are solid. GenAI is just another piece of the application stack. Security fundamentals are crucial. To help understand it, GenAI vulnerabilities are a lot like SQL vulnerabilities.
000
Christopher Peacock @securepeacock.bsky.social · 06/02/2025
Interesting talk today by @wietzebeukema.nl. Make sure you follow him and check out his GitHub too.
030
Christopher Peacock @securepeacock.bsky.social · 06/02/2025
Today at WWHF Wietze is dropping Invoke-ArgFuscator 👀 t.co/b4Agg3nveJ
t.co
https://github.com/wietze/Invoke-ArgFuscator
130
Christopher Peacock @securepeacock.bsky.social · 31/01/2025
🚨 Last day to submit a CFP ‼️ Get yours in ASAP. Last year saw nearly 2,000 registrations. This is one of the best B-Sides in the world. Oh and did I mention you can visit beautiful Florida beaches during your trip in May? events.bsidestampa.net/BSidesTampa2...
events.bsidestampa.net
BSides Tampa 2025
TAMPA BAY'S PREMIER IT SECURITY CONFERENCE. BY THE COMMUNITY. FOR THE COMMUNITY. 40+ Speakers | 7 Tracks | 1000+ Participants
032
Christopher Peacock @securepeacock.bsky.social · 30/01/2025
Who’s going to WWHF Denver?
120
Christopher Peacock @securepeacock.bsky.social · 30/01/2025
Heard this on a podcast and it really resonated with me.
010
Christopher Peacock @securepeacock.bsky.social · 29/01/2025
Contrary to popular belief, piping IOCs to your SIEM does not mean you’re making CTI actionable.
media.tenor.com
bart simpson is looking at a cake that says at least you tried
ALT: bart simpson is looking at a cake that says at least you tried
010
Christopher Peacock @securepeacock.bsky.social · 02/01/2025
One of the best career tips I can share is to care about the people you work with. Not everyone will be receptive, but those who are can become invaluable connections in your career journey—and in life.
030
Christopher Peacock @securepeacock.bsky.social · 17/12/2024
One piece of advice to give new SOC analysts is to have humor. Working alerts in a SOC is a high stress environment and the grind never stops, so find ways to laugh and enjoy who you work with.
030
Christopher Peacock @securepeacock.bsky.social · 17/12/2024
Just a friendly reminder that you can hunt in datasets that are outside your organization.
021
Christopher Peacock @securepeacock.bsky.social · 04/12/2024
Purple Team metrics can be tough and conflated with BAS testing so here’s a few, but feel free to add your own in the comments. 1. Engagements with SOC per year/quarter. 2. Intel leads tested. 3. Custom tests to verify detection logic. 4. Request for testing completed %
1113
Christopher Peacock @securepeacock.bsky.social · 03/12/2024
One of the quickest GenAI use cases you can do in your SOAR is to auto enrich command lines associated with an alert by adding an explanation of what the command is doing. This boost productivity and situational awareness of the analysts.
050
Christopher Peacock @securepeacock.bsky.social · 22/11/2024
This is approaching gross negligence, leaving a public facing back door open 🤯 : “gained initial access through a web shell left from a third party’s previous security assessment” www.cisa.gov/news-events/...
cisa.gov
Enhancing Cyber Resilience: Insights from CISA Red Team Assessment of a US Critical Infrastructure Sector Organization | CISA
031
Christopher Peacock @securepeacock.bsky.social · 13/11/2024
Three fundamental questions you should ask before purchasing a SOC another enterprise tool are: 1. Does it reduce risk by uncovering previously undetected activities? 2. Does it enhance productivity? 3. If the answers to both of the above are no, then where is the potential return on investment?
000
Christopher Peacock @securepeacock.bsky.social · 05/11/2024
Three tips to grow a career in cyber: Keep exploring, keep learning, and stay curious.
011
Christopher Peacock @securepeacock.bsky.social · 20/11/2023
This is brilliant, everyone always asks for IOCs. So how do you get people to focus on behaviors? Add them to the IOC section! www.cisa.gov/sites/defaul...
020
Christopher Peacock @securepeacock.bsky.social · 07/11/2023
How often do you hunt for rare user agents?
020