Sign in

Toby Lewis

@tobaslouis.co.uk
629 followers 1K following 72 posts

Global Head of Threat Analysis at @Darktrace.com All things Cyber Security Ops, Threat Hunting, Threat Intel and Incident Mgmt.

PostsRepliesMedia
Toby Lewis @tobaslouis.co.uk · 28/12/2025
If I did one of those Ancestry DNA tests right now, a significantly high proportion would come back as Stilton Cheese
020
Toby Lewis @tobaslouis.co.uk · 01/05/2025
Details of the cyber attack at Harrods (as they are with Co-op & M&S) are still low and we shouldn’t rule out that the three incidents impacting the retailers are simply coincidence. .... 1/2
news.sky.com
Luxury store Harrods is latest retail victim of cyber attackers
Harrods has "restricted internet access" after an attempt to gain access to its systems left some customers struggling to pay for purchases, Sky News can reveal.
151
Toby Lewis @tobaslouis.co.uk · 07/04/2025
Why is @microsoft.com "Teams" plural, when "Word" is not? Surely a singular Team feels more homely... maybe. Conversely, a singular "Word", feels like about as much effort as I put in my school coursework.
010
Toby Lewis @tobaslouis.co.uk · 01/04/2025
Do phishing simulations on April Fools' Day still count? 🤷‍♂️
030
Toby Lewis @tobaslouis.co.uk · 03/03/2025
Cooking top tip: quarter-pounders are not the same size as quarter-kilo’ers #ImadeBigBurgers
010
Toby Lewis @tobaslouis.co.uk · 29/01/2025
New blog post from @darktrace.com, looking at the detection of an Insider Threat in a SaaS application, with the customer supported by our amazing Analyst SOC
darktrace.com
Bytesize Security: Insider Threats in Google Workspace | Darktrace Blog
Insider threats pose significant risks due to access to internal systems. Darktrace detected a former employee attempting to steal data from the customer’s Google Workspace platform. Learn about this ...
020
Toby Lewis @tobaslouis.co.uk · 20/01/2025
In my first Executive Order, I will be renaming France as "Cheese-land" #GulfOfMexico
020
Toby Lewis @tobaslouis.co.uk · 16/01/2025
A cautionary tale: not everything suspicious is malicious. (although, I'd argue everything malicious was indeed suspicious at one point)
notalwaysright.com
So, Is Someone Getting Fired, Or…?
Two weeks before Christmas, exactly that happened. It was pandemonium in security. Someone apparently tried really hard to break into our high-sec company by sending out a "gift certificate" to every ...
110
Toby Lewis @tobaslouis.co.uk · 10/01/2025
A new blog post from analysts at @darktrace.com: The use of phishing kits as part of an AitM attack, increasing an attackers ability and proficiency in stealing legitimate credentials. ... and then simply just logging on.
darktrace.com
Detecting and mitigating adversary-in-the-middle phishing attacks with Darktrace Services | Darktrace Blog
Threat actors often use advanced phishing toolkits and Adversary-in-the-Middle (AitM) attacks in Business Email Compromise (BEC) campaigns, Discover how Darktrace detected and mitigated a sophisticate...
030
Toby Lewis @tobaslouis.co.uk · 07/01/2025
Ok Brain Trust: Prove me wrong. There is no application of cyber attack, where the intended outcome can't be achieved by non-cyber means.
300
Toby Lewis @tobaslouis.co.uk · 05/01/2025
A dog walk on the beach
030
Toby Lewis @tobaslouis.co.uk · 02/01/2025
One of my 2025 resolutions is to write more, including reinvigorating my cyber security focussed blog, which took a bit of a hiatus in the latter half of 2024. I've got a few ideas lined up already, but what would you like to see me write about?
tobylewis.substack.com
Common Sense Security | Toby Lewis | Substack
Removing the FUD from Cyber Security. Click to read Common Sense Security, by Toby Lewis, a Substack publication. Launched 2 years ago.
000
Toby Lewis @tobaslouis.co.uk · 31/12/2024
Interesting OpSec aspect with regards to the BeyondTrust compromise. (H/T to @GossiTheDog.cyberplace.social.ap.brid.gy for first spotting this) Having a search for some of the IOCs from the BeyondTrust blog, reveals that they appear in a file uploaded to VirusTotal on the 19th December
Screenshot from VirusTotal showing file uploaded on 19th December
120
Toby Lewis @tobaslouis.co.uk · 30/12/2024
US Treasury announce network breach by “Chinese Actors” via cybersecurity vendor BeyondTrust. BeyondTrust specialise in Privileged Access Management. In other words, they have the power to access or generate one-time-use Admin credentials for their customer networks.
bbc.com
US Treasury says it was hacked by China in 'major incident'
A Chinese state-sponsored hacker broke into the US Treasury Department's systems in what is being called a "major incident".
173
Toby Lewis @tobaslouis.co.uk · 17/12/2024
New blog post by analysts from @darktrace.com: Detecting the exploitation of internet-facing File Transfer Servers, exploiting CVE-2024-50623
darktrace.com
Cleo File Transfer Vulnerability: Patch Pitfalls and Darktrace’s Detection of Post-Exploitation Activities | Darktrace Blog
File transfer applications are prime targets for ransomware groups due to their critical role in business operations. Recent vulnerabilities in Cleo's MFT software, namely CVE-2024-50623 and CVE-2024-...
020
Toby Lewis @tobaslouis.co.uk · 10/12/2024
New blog post by analysts from @darktrace.com - a review of recent exploit campaigns against Palo Alto firewalls which are then used as a launch point into customer networks.
darktrace.com
Darktrace’s view on Operation Lunar Peek: Exploitation of Palo Alto firewall devices (CVE 2024-2012 and 2024-9474) | Darktrace Blog
Darktrace’s Threat Research team investigated a major campaign exploiting vulnerabilities in Palo Alto firewall devices (CVE 2024-2012 and 2024-9474). Learn about the spike in post-exploitation activi...
010
Toby Lewis @tobaslouis.co.uk · 05/12/2024
New blog post by analysts @darktrace.bsky.social - detecting the use of AiTM Phishing Kits, including MFA bypass, by attackers.
darktrace.com
A snake in the net: Defending against AiTM phishing threats and Mamba 2FA | Darktrace Blog
Phishing-as-a-Service (PhaaS) platforms have lowered entry barriers for cybercriminals, leading to sophisticated AiTM phishing attacks. Darktrace's AI-driven solutions, including Darktrace / EMAIL, ef...
010
Toby Lewis @tobaslouis.co.uk · 04/12/2024
I can only read this in the voice of the guy who reads out the Football results.
A cinema listing showing Gladiator 2, Paddington 3
020
Toby Lewis @tobaslouis.co.uk · 01/12/2024
‘Tis the season to… … be constantly picking up dropped pine needles off the floor
010
Reposted by Toby Lewis
TruBluFan @trublufan.bsky.social · 30/11/2024
021
Toby Lewis @tobaslouis.co.uk · 30/11/2024
England Women’s Football is more fun to watch than the men’s game
020
Toby Lewis @tobaslouis.co.uk · 30/11/2024
OSINT challenge - Easy Edition #lionesses
Wembley Stadium - I did say this was easy.
010
Toby Lewis @tobaslouis.co.uk · 27/11/2024
New blog post by analysts at @darktrace.bsky.social - detecting SaaS account compromise including the use of multiple VPN access points by threat actors.
darktrace.com
Behind the veil: Darktrace's detection of VPN exploitation in SaaS environments | Darktrace Blog
A recent phishing attack compromised an internal email account, but Darktrace’s advanced AI quickly intervened. By identifying unusual activity across email and SaaS environments, Darktrace uncovered ...
030
Toby Lewis @tobaslouis.co.uk · 24/11/2024
Nuances become lost when arguments are oversimplified. In this case, both attribution and motivation are reduced into its simplest form. With attribution, it’s worth considering we’re talking about threats from multiple groups originating, or in support of, Russia’s objectives.
www-bbc-co-uk.cdn.ampproject.org
Russia ready to wage cyber war on UK, minister to say - BBC News
Pat McFadden will tell a Nato conference that Russia could try to attack British businesses and power grids.
110
Toby Lewis @tobaslouis.co.uk · 24/11/2024
Only those of a certain age/persuasion will know what this means: FCKGW-RHQQ2-YXRKT-8TG6W-2B7Q8
050
Reposted by Toby Lewis
Adam Sharp @adamcsharp.bsky.social · 22/11/2024
A list of the most popular names for the daughters of drummers: 3. Anna One 2. Anna Two 1. Anna One Two Three Four
2363780
Toby Lewis @tobaslouis.co.uk · 19/11/2024
Sure, a snowy back garden sounds like fun, but for any dog owners out there, you now have your own dog 💩 minefield. One step and it could be catastrophe.
011
Toby Lewis @tobaslouis.co.uk · 19/11/2024
As we're in this rapid growth of @bsky.app, not only are we going to see accnts impersonating high profile individuals, but critically, impersonating high reputation news sources. All it would take is some imaginative "Breaking News" to hit public confidence. Can the real BBC News please stand up?
Screengrab of search results in Bluesky for the handle "bbcnews". It shows a list of accounts all of which could be the real BBC news, but it's unclear.
053
Toby Lewis @tobaslouis.co.uk · 18/11/2024
With reports of "fake" bsky accnts impersonating UK MPs, its important to note that accnt verification (akin to the pre-Musk Twitter "Blue tick") is left to the user, not @bsky.app. This is done using a method similar to how email spoofing is mitigated, with a special DNS record:
bsky.social
How to set your domain as your handle - Bluesky
Using a domain as your handle helps with account identity, verification, and portability. Here's how to set your domain as your handle.
023
Reposted by Toby Lewis
RNIB @rnib.bsky.social · 14/11/2024
New to @bsky.app? We’ve got some etiquette just for you! Turn on the little feature that reminds you to post alt text with your images. Alt text allows blind and partially sighted people to understand what's in your images using screen readers. Without alt text, it just says "image".
Screen shot of "Accessibility Settings" with two main categories: "Alt text" and "Media." Under Alt text, there are two toggle options labelled "Require alt text before posting," which is switched on. “Display larger alt text badges" Under Media, there’s an option labelled "Disable autoplay for videos and GIFs," which is switched on.
18403298
Toby Lewis @tobaslouis.co.uk · 17/11/2024
…Also shows if your account has been blocked by anyone. I’ve been on this app for less than a week and I’ve already been blocked by someone?!
000
Toby Lewis @tobaslouis.co.uk · 17/11/2024
A friend asked if I had any pre-prepared content on phishing. I was feeling particularly lazy, so got ChatGPT to give it a go. I actually quite like the simplicity of its response.
What is Phishing? Phishing is when a bad person tries to trick you into giving them your secret stuff, like passwords or credit card numbers. They pretend to be someone you trust!
050
Toby Lewis @tobaslouis.co.uk · 16/11/2024
Is it…. Not speeding?
Clickbait article with headline “Driver reveals trick to avoid speeding fines”
031
Toby Lewis @tobaslouis.co.uk · 15/11/2024
#whoami - Global Head of Threat Analysis at Darktrace: Cyber Security, AI in Cyber Security, Threat Landscape - Ex-NCSC & UK Government: Current affairs, Geopolitics & Nat. Security - Other things: Diversity and Inclusivity, Compassionate Leadership, Social Mobility, Mentoring & Coaching
020
Toby Lewis @tobaslouis.co.uk · 14/11/2024
Hello World
2110