Sign in

Taz Wake

@tazwake.bsky.social
4.5K followers 1.5K following 1.1K posts

DFIR & Threat Hunting Professional | SANS Course Author - FOR577 Linux IR Class | Certified SANS instructor | Incident Responder | I have no access to DMs.

PostsRepliesMedia
Taz Wake @tazwake.bsky.social · 3h
Identity Threat Hunting in Cloud Environments In the cloud there is often no host to image and no disk to acquire. The audit trail becomes the evidence, and identity becomes the thing you hunt.
halkynconsulting.co.uk
Identity Threat Hunting in Cloud Environments
In the cloud there is often no host to image and no disk to acquire. The audit trail becomes the evidence, and identity becomes the thing you hunt.
031
Taz Wake @tazwake.bsky.social · 22h
LD_PRELOAD Detection: Dynamic Linker Hijacking LD_PRELOAD lets an attacker intercept almost any library call without touching the program itself. This guide covers how the technique works, how to find it on a live host, and how to tell abuse from legitimate use.
halkynconsulting.co.uk
LD_PRELOAD Detection: Dynamic Linker Hijacking
LD_PRELOAD lets an attacker intercept almost any library call without touching the program itself. This guide covers how the technique works, how to find it on a live host, and how to tell abuse from legitimate use.
000
Taz Wake @tazwake.bsky.social · 30/09/2026
Kunai Threat Hunting Poster: Free A3 Download A free two-sided A3 poster on Kunai threat hunting: what Kunai records on a Linux host, and 14 tested jq hunts and rules you can run today.
halkynconsulting.co.uk
Kunai Threat Hunting Poster: Free A3 Download
A free two-sided A3 poster on Kunai threat hunting: what Kunai records on a Linux host, and 14 tested jq hunts and rules you can run today.
120
Taz Wake @tazwake.bsky.social · 30/09/2026
Insider Data Exfiltration: What It Looks Like Insider exfiltration uses ordinary routes: USB, personal cloud storage, webmail, print and the phone camera nobody logs.
halkynconsulting.co.uk
Insider Data Exfiltration: What It Looks Like
Insider exfiltration uses ordinary routes: USB, personal cloud storage, webmail, print and the phone camera nobody logs.
030
Taz Wake @tazwake.bsky.social · 29/09/2026
Model File Formats That Execute Code Some weight files run code the moment they load. Which formats, by what mechanism, and why scanning has become the weaker answer.
halkynconsulting.co.uk
Model File Formats That Execute Code
Some weight files run code the moment they load. Which formats, by what mechanism, and why scanning has become the weaker answer.
000
Taz Wake @tazwake.bsky.social · 29/09/2026
Threat Hunting Metrics That Convince a Board Counting hunts measures effort. Boards fund outcomes. Here is a starter set of hunting metrics that reports honestly and still earns next year's budget.
halkynconsulting.co.uk
Threat Hunting Metrics That Convince a Board
Counting hunts measures effort. Boards fund outcomes. Here is a starter set of hunting metrics that reports honestly and still earns next year's budget.
341
Taz Wake @tazwake.bsky.social · 28/09/2026
Bitwise Operations: AND, OR, XOR and Shifts AND, OR, XOR and the shift instructions manipulate individual bits, and they appear everywhere from permission checks to obfuscated malware. This post explains what each does and why analysts meet them so often.
halkynconsulting.co.uk
Bitwise Operations: AND, OR, XOR and Shifts
AND, OR, XOR and the shift instructions manipulate individual bits, and they appear everywhere from permission checks to obfuscated malware. This post explains what each does and why analysts meet them so often.
000
Taz Wake @tazwake.bsky.social · 24/09/2026
Network Threat Hunting: Beacons, DNS and TLS Encryption hides content, not behaviour. Beacon rhythm, DNS abuse and TLS metadata still expose command and control without a single decrypted byte.
halkynconsulting.co.uk
Network Threat Hunting: Beacons, DNS and TLS
Encryption hides content, not behaviour. Beacon rhythm, DNS abuse and TLS metadata still expose command and control without a single decrypted byte.
150
Taz Wake @tazwake.bsky.social · 23/09/2026
Reading the Linux Process Tree During Triage A flat process list tells you what is running. The tree tells you what started it. This guide covers reading Linux process lineage, exposing renamed processes and recovering a deleted binary through /proc.
halkynconsulting.co.uk
Reading the Linux Process Tree During Triage
A flat process list tells you what is running. The tree tells you what started it. This guide covers reading Linux process lineage, exposing renamed processes and recovering a deleted binary through /proc.
022
Taz Wake @tazwake.bsky.social · 23/09/2026
Reading Prompt History as Evidence An employee's AI prompt history is a record of what they asked for, including the requests they thought better of. It needs handling with care.
halkynconsulting.co.uk
Reading Prompt History as Evidence
An employee's AI prompt history is a record of what they asked for, including the requests they thought better of. It needs handling with care.
020
Taz Wake @tazwake.bsky.social · 22/09/2026
Threat Hunting Workflow and Governance Enthusiasm produces a few good hunts. A workflow produces them every month, and keeps producing them after the enthusiast leaves.
halkynconsulting.co.uk
Threat Hunting Workflow and Governance
Enthusiasm produces a few good hunts. A workflow produces them every month, and keeps producing them after the enthusiast leaves.
020
Taz Wake @tazwake.bsky.social · 21/09/2026
Arithmetic Instructions and CPU Flags Every add and subtract quietly updates the CPU flags, and every conditional branch reads them. This post explains the arithmetic instructions and the four flags that drive program decisions.
halkynconsulting.co.uk
Arithmetic Instructions and CPU Flags
Every add and subtract quietly updates the CPU flags, and every conditional branch reads them. This post explains the arithmetic instructions and the four flags that drive program decisions.
010
Taz Wake @tazwake.bsky.social · 18/09/2026
Rolling Your Own IOC Scanner A hunt you can only run by hand does not scale. Here is how to turn your findings into a repeatable IOC scanner, with a free tool and a YARA rule pack.
halkynconsulting.co.uk
Rolling Your Own IOC Scanner
A hunt you can only run by hand does not scale. Here is how to turn your findings into a repeatable IOC scanner, with a free tool and a YARA rule pack.
021
Taz Wake @tazwake.bsky.social · 18/09/2026
Shadow AI Discovery: Finding Inference Endpoints Unapproved inference servers are easy to find once you know what to look for. The defaults matter more than the port numbers.
halkynconsulting.co.uk
Shadow AI Discovery: Finding Inference Endpoints
Unapproved inference servers are easy to find once you know what to look for. The defaults matter more than the port numbers.
010
Taz Wake @tazwake.bsky.social · 17/09/2026
Intelligence-Driven Threat Hunting in Practice Buying a feed is not intelligence-driven hunting. Here is how to turn a threat report into behaviours worth hunting, and why indicators alone age badly.
halkynconsulting.co.uk
Intelligence-Driven Threat Hunting in Practice
Buying a feed is not intelligence-driven hunting. Here is how to turn a threat report into behaviours worth hunting, and why indicators alone age badly.
010
Taz Wake @tazwake.bsky.social · 16/09/2026
eBPF Runtime Security Tools: A Responder’s View Falco, Tracee, Tetragon, Sysdig and Jibril all promise kernel-level visibility. This guide compares them from a responder's perspective and covers how to find out what is already running on a compromised host.
halkynconsulting.co.uk
eBPF Runtime Security Tools: A Responder’s View
Falco, Tracee, Tetragon, Sysdig and Jibril all promise kernel-level visibility. This guide compares them from a responder's perspective and covers how to find out what is already running on a compromised host.
043
Taz Wake @tazwake.bsky.social · 16/09/2026
Access Logs and Intent in Insider Cases The same access, at the same hour, by the same person is either routine or the whole case. What separates them is context, not telemetry.
halkynconsulting.co.uk
Access Logs and Intent in Insider Cases
The same access, at the same hour, by the same person is either routine or the whole case. What separates them is context, not telemetry.
000
Taz Wake @tazwake.bsky.social · 15/09/2026
What a Threat Hunting Capability Really Costs The tooling is rarely the expensive part. Data retention and protected analyst time are where a hunting budget actually goes.
halkynconsulting.co.uk
What a Threat Hunting Capability Really Costs
The tooling is rarely the expensive part. Data retention and protected analyst time are where a hunting budget actually goes.
021
Taz Wake @tazwake.bsky.social · 14/09/2026
My horse had to be put down today. He was 25 years old and over the last few months was struggling to eat. This is him in better times.
Horse.
240
Taz Wake @tazwake.bsky.social · 14/09/2026
Reading Control Flow in Disassembly Assembly has no if statements or while loops, only compares and jumps. This post shows how the familiar high-level structures are built from those parts, and how to recognise each pattern in disassembly.
halkynconsulting.co.uk
Reading Control Flow in Disassembly
Assembly has no if statements or while loops, only compares and jumps. This post shows how the familiar high-level structures are built from those parts, and how to recognise each pattern in disassembly.
011
Taz Wake @tazwake.bsky.social · 11/09/2026
Finding Hidden Processes and Ports on Linux Advanced attackers make the host lie to your tools. Here is how to catch the lie on Linux by cross-checking independent views, with two free tools.
halkynconsulting.co.uk
Finding Hidden Processes and Ports on Linux
Advanced attackers make the host lie to your tools. Here is how to catch the lie on Linux by cross-checking independent views, with two free tools.
052
Taz Wake @tazwake.bsky.social · 11/09/2026
LLM Evidence on Linux: The Artefact Map The artefact map for a local AI deployment: model storage, caches, configuration, conversation records and the credentials sitting alongside them.
halkynconsulting.co.uk
LLM Evidence on Linux: The Artefact Map
The artefact map for a local AI deployment: model storage, caches, configuration, conversation records and the credentials sitting alongside them.
010
Taz Wake @tazwake.bsky.social · 10/09/2026
Hunting Visibility: Knowing What You Can See Every hunt is limited by what your telemetry can see. Mapping that honestly is duller than hunting, and it changes the results more than any tool will.
halkynconsulting.co.uk
Hunting Visibility: Knowing What You Can See
Every hunt is limited by what your telemetry can see. Mapping that honestly is duller than hunting, and it changes the results more than any tool will.
010
Reposted by Taz Wake
Alex von Tunzelmann @alexvont.bsky.social · 10/09/2026
If you feel like donating to the RNLI, here’s a link. I just have. Their minimum donation is £2: I think it might be nice for them to receive a lot of donations this week, even if they’re mostly very modest. Just so they know a lot of people out here appreciate their work. rnli.org/support-us/g...
rnli.org
Donate to the RNLI and help save lives at sea
Your donations really make a difference. We depend on your generosity to educate people to stay safe and prevent tragedies on and offshore. Donate here.
4920921251
Taz Wake @tazwake.bsky.social · 09/09/2026
Linux Host Telemetry: Sysmon and Kunai A default Linux server records nothing about process creation. This guide covers Sysmon for Linux and Kunai, how to confirm what your build actually captures, and how to keep the volume manageable.
halkynconsulting.co.uk
Linux Host Telemetry: Sysmon and Kunai
A default Linux server records nothing about process creation. This guide covers Sysmon for Linux and Kunai, how to confirm what your build actually captures, and how to keep the volume manageable.
021
Reposted by Taz Wake
Ilikecaketoo (UK) @ilikecaketoo.bsky.social · 09/09/2026
Disgraceful that the RNLI have to say this today, but here we are 😞. If you would like to donate👇🏻. rnli.org/support-us/g... #RNLI #RNLISavesLives
621934871
Taz Wake @tazwake.bsky.social · 09/09/2026
Insider Investigation Authorisation Comes First Who authorises an insider investigation, what they must consider first, and what happens to the evidence when the step gets skipped.
halkynconsulting.co.uk
Insider Investigation Authorisation Comes First
Who authorises an insider investigation, what they must consider first, and what happens to the evidence when the step gets skipped.
010
Taz Wake @tazwake.bsky.social · 08/09/2026
Staffing a Threat Hunting Team: Build or Buy Hunting is a skill set, not a headcount. Here is how to decide between building a team, buying the capability, or running a credible hybrid.
halkynconsulting.co.uk
Staffing a Threat Hunting Team: Build or Buy
Hunting is a skill set, not a headcount. Here is how to decide between building a team, buying the capability, or running a credible hybrid.
041
Reposted by Taz Wake
Luca Trenta @lucatrenta.bsky.social · 07/09/2026
Turns out that if you are an old lady with a banner supporting Palestine, the government arrests you on charges of terrorism. If you are a masked white male thug bringing a national port to a standstill, the government does absolutely nothing, and the media covers it like some lads on a day out.
11340701383
Taz Wake @tazwake.bsky.social · 07/09/2026
Function Calls and Stack Frames Explained Beneath every function call sits a precise machine-level contract: where arguments go, where the return value comes back, and how the stack keeps it all straight. This post explains that contract.
halkynconsulting.co.uk
Function Calls and Stack Frames Explained
Beneath every function call sits a precise machine-level contract: where arguments go, where the return value comes back, and how the stack keeps it all straight. This post explains that contract.
000
Reposted by Taz Wake
Marie Vibbert @reasie.bsky.social · 06/09/2026
My fellow US Americans, I know most of our country lacks proper transportation infrastructure, but please, by all that is holy to you, ALLOW THE PASSENGERS TO EXIT before boarding the train. Thnx.
2657150
Taz Wake @tazwake.bsky.social · 04/09/2026
Building a Quick Linux Host Timeline Individual findings are dots. A host timeline is the line through them. Here is a lightweight way to order an intrusion on Linux, and spot faked timestamps.
halkynconsulting.co.uk
Building a Quick Linux Host Timeline
Individual findings are dots. A host timeline is the line through them. Here is a lightweight way to order an intrusion on Linux, and spot faked timestamps.
000
Taz Wake @tazwake.bsky.social · 04/09/2026
Autopsy Plugins for Linux Evidence Autopsy is a great forensic suite but there aren't a lot of good plugins for Linux evidence. We have tried to change this by creating some autopsy plugins directly aimed at things we find during Linux casework.
halkynconsulting.co.uk
Autopsy Plugins for Linux Evidence
Autopsy is a great forensic suite but there aren't a lot of good plugins for Linux evidence. We have tried to change this by creating some autopsy plugins directly aimed at things we find during Linux casework.
042
Taz Wake @tazwake.bsky.social · 04/09/2026
Investigating Self-Hosted LLM Systems on Linux Self-hosted AI is now ordinary enterprise infrastructure. Investigating a compromised deployment turns out to be a Linux problem.
halkynconsulting.co.uk
Investigating Self-Hosted LLM Systems on Linux
Self-hosted AI is now ordinary enterprise infrastructure. Investigating a compromised deployment turns out to be a Linux problem.
050
Taz Wake @tazwake.bsky.social · 03/09/2026
Writing a Threat Hunting Hypothesis That Works Most hunts fail before anyone queries anything, because the hypothesis was never testable. Here is how to write one that scopes the ground and reaches a conclusion.
halkynconsulting.co.uk
Writing a Threat Hunting Hypothesis That Works
Most hunts fail before anyone queries anything, because the hypothesis was never testable. Here is how to write one that scopes the ground and reaches a conclusion.
010
Taz Wake @tazwake.bsky.social · 03/09/2026
Why CPTED Works: Designing for the Offender’s Decision Crime is a calculation. Here is why CPTED works - by shaping the offender's decision, raising effort and risk while lowering the reward.
halkynconsulting.co.uk
Why CPTED Works: Designing for the Offender’s Decision
Crime is a calculation. Here is why CPTED works - by shaping the offender's decision, raising effort and risk while lowering the reward.
011
Reposted by Taz Wake
Randall Munroe @xkcd.com · 02/09/2026
Trade xkcd.com/3290/
Comic. [Person standing holding hammer above raised knee.] PERSON: Listen up, leg. I’ve been sending you rich, oxygenated blood for years, while you send me worthless used-up blood with no oxygen. Time to teach you a lesson about not ripping me off! [caption] Tariffs
56113622488
Taz Wake @tazwake.bsky.social · 02/09/2026
SSH Forensics: What an Intrusion Leaves Behind SSH is how most Linux intrusions travel between hosts. This guide covers the artefacts it leaves behind, from appended authorised keys and hashed known_hosts entries to configuration changes used for persistence.
halkynconsulting.co.uk
SSH Forensics: What an Intrusion Leaves Behind
SSH is how most Linux intrusions travel between hosts. This guide covers the artefacts it leaves behind, from appended authorised keys and hashed known_hosts entries to configuration changes used for persistence.
020
Taz Wake @tazwake.bsky.social · 02/09/2026
Insider Threat Investigation: Evidence and Process What separates an insider investigation from an intrusion investigation, and why the authorisation chain matters more than the toolkit.
halkynconsulting.co.uk
Insider Threat Investigation: Evidence and Process
What separates an insider investigation from an intrusion investigation, and why the authorisation chain matters more than the toolkit.
010
Taz Wake @tazwake.bsky.social · 02/09/2026
If you are interested in posts like this, you could do me a huge favour and visit the blog at www.halkynconsulting.co.uk/a/ and subscribe to the posts. The team write 1-3 posts a day, so you won't get spammed, and we dont use your details for anything else (we don't even see them). Thank you!
000
Taz Wake @tazwake.bsky.social · 01/09/2026
Building a Threat Hunting Business Case Hunting is easy to justify to security people and hard to justify to a finance director. Here is how to build a case that survives the second conversation.
halkynconsulting.co.uk
Building a Threat Hunting Business Case
Hunting is easy to justify to security people and hard to justify to a finance director. Here is how to build a case that survives the second conversation.
011
Taz Wake @tazwake.bsky.social · 01/09/2026
Ten Low-Cost Crime Reduction Measures That Work Effective crime reduction is usually a stack of small, cheap habits rather than one big purchase. Ten measures - most costing pounds, not thousands - that measurably cut risk within a month.
halkynconsulting.co.uk
Ten Low-Cost Crime Reduction Measures That Work
Effective crime reduction is usually a stack of small, cheap habits rather than one big purchase. Ten measures - most costing pounds, not thousands - that measurably cut risk within a month.
020
Taz Wake @tazwake.bsky.social · 31/08/2026
DFIR tip: `/proc/PID/fd` maps a process's open descriptors to files, pipes, sockets and anonymous objects. `ls -l /proc/PID/fd` is only a live snapshot: descriptors can close or be reused during collection.
040
Taz Wake @tazwake.bsky.social · 31/08/2026
How the Stack Works in Assembly Language The stack is where programs keep return addresses, local variables and saved registers. Understanding push, pop and stack growth explains both everyday debugging and a whole class of attacks.
halkynconsulting.co.uk
How the Stack Works in Assembly Language
The stack is where programs keep return addresses, local variables and saved registers. Understanding push, pop and stack growth explains both everyday debugging and a whole class of attacks.
031