@dcode Profile picture

Derek Ditch

@dcode

Founder of @rocknsm. I ❤️ all things @elastic so much that I now build things there.

Similar User
Andrew Pease photo

@andythevariable

Elastic Security Labs photo

@elasticseclabs

Jessica David photo

@quixentric

DefSecSentinel photo

@DefSecSentinel

Joe Desimone photo

@dez_

James photo

@jamesspi

Devon Kerr photo

@_devonkerr_

Gabriel Landau photo

@GabrielLandau

Keith photo

@kwm

Teneisia Brown photo

@Txsh876

Daniel Stepanic photo

@DanielStepanic

David French photo

@threatpunter

Mark Parsons photo

@markpars0ns

w0rk3r photo

@_w0rk3r

Justin Ibarra photo

@br0k3ns0und

I made it until Dec 17th with copious amounts of Christmas music listening. #whamageddon whamageddon.com


If you attended or watched my talk this morning at #mWISE 2022, the talk repo URL is fixed. PDF copy of slides and related links to repo here: ela.st/mwise-2022 Sorry 'bout that.


We're up in 2 hours in track 1. Here's our presentation repo and the actual project repo. ela.st/sans-dfir-2022 ela.st/malware-exquac…

Really excited for @dcode and Jessica David’s talk on “Cracking the Beacon: Automating the extraction of implant configurations” at the @sansforensics con. sans.org/cyber-security…



Hey @linkedin! I'm tired of you selling my information so I can get cold called at 9am for a job title I had 5 years ago. My phone number was only listed as a security item, not contact info. This violates my personal privacy policy, so I'm scrubbing the info. Knock it off.


I should tweet more 🤔


Derek Ditch Reposted

Here's a tool that was written by @dcode and @DanielStepanic that automates the collection of #cobaltstrike beacons from #Elastic, pulls the configuration out, and writes it all back into Elasticsearch. elastic.github.io/security-resea…


Derek Ditch Reposted

Elastic's MacOS Endpoint Agent with the Malware Protections feature enabled and MacOS Prebuilt Detection Rules enabled in Kibana detected the new MacOS malware Dazzlespy (welivesecurity.com/2022/01/25/wat…) out of the box. (These capabilities are free and open source for you to use.)

Tweet Image 1

I'm interested in moving my money to a US-based bank with 2FA that doesn't suck. Namely I'm looking for TOTP. I'm looking at you @USAA @CapitalOne @Chase @WellsFargo @Citi @PNCBank credit unions and others. Any ideas?


I'm sorry, this is absurd @FoxBusiness green energy caused this? In reality, all TX energy producers and ERCOT failed to retrofit freeze protections because it's expensive. I'm ordering more @tesla panels and powerwalls fxn.ws/2ZrX3NW #FoxBusiness


Derek Ditch Reposted

We are moving our Apache 2.0-licensed source code in Elasticsearch & Kibana to be dual licensed under SSPL & the Elastic License, giving users the choice of which license to apply. Read more → go.es.io/39AnJAL">go.es.io/39AnJAL FAQs → go.es.io/3oInry8 go.es.io/39AnJAL">go.es.io/39AnJAL


I know @Schwarzenegger was born in Austria, but he's a hell of an American. Above all, I think the political divisiveness, intolerance of each others ideas, and unwillingness to compromise at all is what destroys us. It's not too late to move on, together.

My message to my fellow Americans and friends around the world following this week's attack on the Capitol.



Derek Ditch Reposted

On this #Thanksgiving Day, we have so much to be grateful for — our community of customers, partners, users, #Elasticians, family, and friends. Happy Thanksgiving!

Tweet Image 1

Loading...

Something went wrong.


Something went wrong.