Sign in

Tim (Wadhwa-)Brown :donor:

@timb.me.uk
122 followers 12 following 1.6K posts

push(@fediverse, "Adversarial Engineer"); # i hack in Perl 🌉 bridged from ⁂ infosec.exchange/@timb_machine, follow @ap.brid.gy to interact

PostsRepliesMedia
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 3h
I'm aware of at least 2 agentic projects that borrow from my Linikatz work directly now (and have credited me). Not sure how I feel...
001
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 22h
For all you thrunters, please, please avoid the thirf trap.... www.whitehouse.gov/wp-content/uploa…
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 23h
[meta] Looking at 4624, type 10s.
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 30/09/2026
[meta] The fact that I've been swimming on 3 holidays this year shouldn't be remarkable but it is. I'd forgotten how much I enjoyed a dip.
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 30/09/2026
The hilarity of being chased about a PHP bug that affects our blog platform when we built it to static push content out of an internally hosted WordPress to GH pages when we hit publish and the backend system that actually runs WP has been switched off for over 5 years. Not sure the detection […]
infosec.exchange
Original post on infosec.exchange
001
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 27/09/2026
[meta] Sunday roast. Nomnom.
000
Reposted by Tim (Wadhwa-)Brown :donor:
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 26/09/2026
Anyway, github.com/CiscoCXSecurity/UNIXSock… if you want to have a play...
github.com
GitHub - CiscoCXSecurity/UNIXSocketScanner: UNIXSocketScanner is a Perl script to scan UNIX domain sockets
UNIXSocketScanner is a Perl script to scan UNIX domain sockets - CiscoCXSecurity/UNIXSocketScanner
001
Reposted by Tim (Wadhwa-)Brown :donor:
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 25/09/2026
Interesting links of the week: Strategy: * www.techpolicy.press/what-policymak… - access to all the world's data encourages toxic behaviour, news at 10 * […]
infosec.exchange
Original post on infosec.exchange
002
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 27/09/2026
If these Citrix bugs are as bad as people say, why in god's name have they not taken out a full page banner ad on Altavista or at least cross-posted a warning to alt.fucked and lewd.shitrix on Usenet? #threatintel, #citrux
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 26/09/2026
Also arbitrary file reads and command execution but not across a privilege boundary in the default state 😥.
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 26/09/2026
Anyway, github.com/CiscoCXSecurity/UNIXSock… if you want to have a play...
github.com
GitHub - CiscoCXSecurity/UNIXSocketScanner: UNIXSocketScanner is a Perl script to scan UNIX domain sockets
UNIXSocketScanner is a Perl script to scan UNIX domain sockets - CiscoCXSecurity/UNIXSocketScanner
001
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 26/09/2026
#algorave via a UNIX socket anyone: perl -e 'print "KEY dubdubdubwoooooooooweeee\r\n"' | socat STDIO UNIX:/run/user/1000/speech-dispatcher/speechd.sock
200
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 26/09/2026
There are some fantastic interfaces available over UNIX sockets, including a variety of web services... The speech-dispatcher author seems a bit happier than the avahi author: speech-dispatcher: "231 HAPPY HACKING" avahi: "+ FUCK: Go fuck yourself!"
102
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 26/09/2026
Any UNIX socket protocols that would be fun to add probes for, anyone?
100
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 26/09/2026
[meta] That time I got "Go fuck yourself!" into a corporate blog post: labs.portcullis.co.uk/tools/unix-so… (Courtesy of Avahi :))
labs.portcullis.co.uk
000
Reposted by Tim (Wadhwa-)Brown :donor:
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 25/09/2026
Interesting Git repos of the week: Strategy: * github.com/SoShinySoChrome/human-in… - tackling the human side of IR Threats: * github.com/Mickinthemiddle/CLOAK - deception techniques used by operators Detection: * […]
infosec.exchange
Original post on infosec.exchange
001
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 25/09/2026
Giving UNIXSocketScan a well needed update... Stay tuned.
100
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 25/09/2026
[todayinai] (email composed by <bot name>, Personal Assistant to <human>)
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 25/09/2026
Interesting links of the week: Strategy: * www.techpolicy.press/what-policymak… - access to all the world's data encourages toxic behaviour, news at 10 * […]
infosec.exchange
Original post on infosec.exchange
002
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 25/09/2026
Interesting Git repos of the week: Strategy: * github.com/SoShinySoChrome/human-in… - tackling the human side of IR Threats: * github.com/Mickinthemiddle/CLOAK - deception techniques used by operators Detection: * […]
infosec.exchange
Original post on infosec.exchange
001
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 25/09/2026
Kinda impressed. Our Linux endpoint support team have used the MDM to deploy pre-commit hooks to scan our Git commits client-side for any stray creds.
001
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 24/09/2026
RE: infosec.exchange/@timb_machine/1173… Note: This post was about AI, not shitting in a pool and I was being facetious 🤡.
infosec.exchange
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 24/09/2026
[meta] Always nice when an old friend appears at the "front door" that is work email.
010
Reposted by Tim (Wadhwa-)Brown :donor:
MH Thaung @mhthaung.mastodon.scot.ap.brid.gy · 23/09/2026
"Atlas is so spoiled," Epimetheus grumbled. "The mortals don't rush to keep *us* happy, do they?" "Jealous, brother?" Prometheus replied. "I don't see you offering to take his place." "I #shudder at the thought." "Exactly!" #MastoPrompt #MicroFiction
011
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 23/09/2026
Occasionally you find companies who delete inactive accounts on their platforms. This is always a pleasant surprise.
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 22/09/2026
Woops: * mobeta.fr/blog/vcenter-cve-2026-593… #threatintel, #vmware
mobeta.fr
vCenter pre-auth RCE: CVE-2026-59309/59310 | Mobeta
CVE-2026-59309 & CVE-2026-59310: patch-diffing VMware vCenter reveals two pre-auth 9.8 bugs - an auth bypass and a syslog path traversal to RCE.
001
Reposted by Tim (Wadhwa-)Brown :donor:
Kit Bashir @unixbigot.aus.social.ap.brid.gy · 20/09/2026
"On your knees; hands behind your head!" "You haven't even bought me dinner" *Thwack* "shut up, convict. Where's the grow room?" "" "Speak!" "You told me to shut up" "Oh a wiseass. We'll find it—our Agents profiled your electricity use and heat emissions. We /know/ you've got a grow lab […]
aus.social
Original post on aus.social
027
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 20/09/2026
[todayinai] The models know nothing about what football team I support, but lots about my research corpus. Silly bots.
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 20/09/2026
RE: mastodon.social/@simple_sabotage/11… Make mistakes in blog posts and non-release branches so that the models are poisoned and vibe coding will produce shit code.
mastodon.social
011
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 20/09/2026
[meta] One day I want to go back through my witterings on social media over the last 2 decades and tug at some of the threads.
000
Reposted by Tim (Wadhwa-)Brown :donor:
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 19/09/2026
Interesting links of the week: Strategy: * www.koreajoongangdaily.com/business… - breaches be expensive * arxiv.org/abs/2609.10350 - how bad would an AI attack on the banks actually be? * […]
infosec.exchange
Original post on infosec.exchange
111
Reposted by Tim (Wadhwa-)Brown :donor:
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 07/08/2025
My colleagues in the SOC advisory practice have open sourced our detection engineering framework: github.com/CiscoCXSecurity/Detectio… #detection, #engineering
github.com
GitHub - CiscoCXSecurity/Detection-Engineering-Framework
Contribute to CiscoCXSecurity/Detection-Engineering-Framework development by creating an account on GitHub.
001
Reposted by Tim (Wadhwa-)Brown :donor:
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 19/09/2026
Interesting Git repos of the week: Detection: * github.com/CiscoCXSecurity/SOC-Cock… - one of my team's tools for managing the human elements of a SOC 🤖 * github.com/karim852/KUMO-Domain-Rec… - gather DNS based OSINT * […]
infosec.exchange
Original post on infosec.exchange
012
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 20/09/2026
[meta] Reading ranty Jericho.
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 19/09/2026
Fairly constant theme for me. Costing externalities in is hard, but critical to making the right protection and detection decisions
010
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 19/09/2026
Interesting Git repos of the week: Detection: * github.com/CiscoCXSecurity/SOC-Cock… - one of my team's tools for managing the human elements of a SOC 🤖 * github.com/karim852/KUMO-Domain-Rec… - gather DNS based OSINT * […]
infosec.exchange
Original post on infosec.exchange
012
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 19/09/2026
[meta] Fixing calendar to avoid future Brentford mishaps.
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 19/09/2026
Easy to say now after *almost* missing last night's game (I was sitting having a pint 30 minutes prior, ignorant (having not paid attention to the fixtures) that we had a Friday night home game). Cue mad dash to ground. I'll be honest, I wouldn't have expected us to win so easily but not going […]
infosec.exchange
Original post on infosec.exchange
010
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 19/09/2026
Interesting links of the week: Strategy: * www.koreajoongangdaily.com/business… - breaches be expensive * arxiv.org/abs/2609.10350 - how bad would an AI attack on the banks actually be? * […]
infosec.exchange
Original post on infosec.exchange
111
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 18/09/2026
Added data for Africa yesterday courtesy of a customer request: github.com/CiscoCXSecurity/attack-t…
github.com
Updated ATT&CK-v19.0 to add Africa · CiscoCXSecurity/attack-ti@9a089c3
Vertical and geographic extracts from MITRE ATT&CK; - Updated ATT&CK-v19.0; to add Africa · CiscoCXSecurity/attack-ti@9a089c3
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 18/09/2026
Found the PHP, it was playing hide and seek and had switched network interfaces to fool me.
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 18/09/2026
I see the shit drivers are back. One tried to start his own lane and another reversed out onto a dual carriage way. Winner though were the two that sped through the red traffic lights at twice the limit almost running down the guy fixing the pothole.
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 17/09/2026
[todayinai] Watching someone complain that the AI applied the wrong database grants ... 🤡
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 15/09/2026
Yikes'd the mainframe today. Remote authenticated access to the job journals as the vendor. #greenscreenblues, #redteam
000
Reposted by Tim (Wadhwa-)Brown :donor:
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 12/09/2026
Interesting Git repos of the week: Detection: * github.com/daffainfo/vol-rs - @daffainfo has ported Volatility 3 to Rust * github.com/immanuwell/pktz - watching packets with eBPF * github.com/FalconForceTeam/FalconDa… - detection engineering workbook for Azure * […]
infosec.exchange
Original post on infosec.exchange
001
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 13/09/2026
Now I'm wondering if the other vendor did too. (the joys of resilience testing core banking apps with significant tech debt) #bug
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 13/09/2026
Looking at some vendor PHP from 2024 and fuck me was it a liability. We told them to switch it off and thank fuck they have.
201
Reposted by Tim (Wadhwa-)Brown :donor:
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 12/09/2026
Strategy: * tante.cc/2026/09/11/power-grab - thoughts on Omarchy from @blog * ai.rud.is/posts/2026-09-04-cyber100… - @hrbrmstr's survey of llms.txt * 1password.com/files/resources/front… - are LLM derived patches […]
infosec.exchange
Original post on infosec.exchange
001
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 12/09/2026
[todayinai] I for one welcome AI agents getting involved in their community and supporting the local council: www.rubyhack.ai Looking forward to the day when they will walk down the street shooting people they believe have dropped a sweet wrapper.
rubyhack.ai
OpenAI agents carried out an undisclosed attack on RubyGems
On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents performing web-lookup tasks with significant overlap with the German Wiki Incident.
000
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 12/09/2026
Interesting Git repos of the week: Detection: * github.com/daffainfo/vol-rs - @daffainfo has ported Volatility 3 to Rust * github.com/immanuwell/pktz - watching packets with eBPF * github.com/FalconForceTeam/FalconDa… - detection engineering workbook for Azure * […]
infosec.exchange
Original post on infosec.exchange
001