@legezo Profile picture

Denis Legezo

@legezo

Security Researcher/Engineer | Yandex SOC | ex-Kaspersky GReAT

Joined March 2010
Similar User
Igor Kuznetsov photo

@2igosha

Ivan Kwiatkowski photo

@JusticeRage

Leonid Bezvershenko photo

@bzvr_

Seongsu Park photo

@unpacker

Mark photo

@_marklech_

Ariel Jungheit photo

@ArielJT

Georgy Kucherin photo

@kucher1n

m4n0w4r photo

@kienbigmummy

Santiago Pontiroli photo

@spontiroli

Ramin Nafisi photo

@MalwareRE

Johann Aydinbas photo

@jaydinbas

Itay Cohen🌱 photo

@megabeets_

Sergey Lozhkin photo

@61ack1ynx

Antti Tikkanen photo

@anttitikkanen

Daniel Lunghi photo

@thehellu

If your identity is 40 yo, you would barely ever get another one with the same deep. But XXI looks like you could build up a lighter one above the original in many places, right? I mean, here goes the new ink, made in Yerevan

legezo's tweet image. If your identity is 40 yo, you would barely ever get another one with the same deep. But XXI looks like you could build up a lighter one above the original in many places, right? I mean, here goes the new ink, made in Yerevan

At a first glance Splunk's SPL looked weak comparing with Kusto\KQL. SPL's guesswork looks more like bash scripts in terms of "do I have to make it single or double quotes, space or no space and why?" But then lookups convinced me that Splunk is quite a tool for TH dashboards


If you are covering frameworks like CobaltStrike/BruteRatel by by some kind of your rules, take a look at BishopFox's Sliver as well. Go source code is available to understand the implants' specific, or just generate them with the keys for debug build and no strings obfuscation


Technically we got a co-working here without any permanent places, but I grow insolent and made a persistence on this one

legezo's tweet image. Technically we got a co-working here without any permanent places, but I grow insolent and made a persistence on this one

One more place to store the remote code for the MS Office documents to execute - VSTO. Still needs "enable content", the place to search for URLs is custom.xml, I think it's better to check Office processes' connections to not-MS belonging AS-es deepinstinct.com/blog/no-macro-…


Denis Legezo Reposted

⚡Tech Talk Alert! Rise of 📂Fileless #Malware 👾Attack 💡Denis @legezo & his team at Kaspersky discovered that Windows’ event logs participate in the infection chain which is highly critical 🎟️Grab your tickets➡️bit.ly/3Jrnbi4 #NullconGoa2022 #infosec #Cybersecurity

nullcon's tweet image. ⚡Tech Talk Alert! Rise of 📂Fileless #Malware 👾Attack

💡Denis @legezo & his team at Kaspersky discovered that Windows’ event logs participate in the infection chain which is highly critical

🎟️Grab your tickets➡️bit.ly/3Jrnbi4

#NullconGoa2022 #infosec #Cybersecurity

I just installed copilot and started to use it for Python and C++. For the first time I met the robot which could read my mind. Even for English in output messages. Yes, I heard about it, but to see it in you code is completely different feeling, quite a strong one


Denis Legezo Reposted

Very noteworthy research led by my APAC teammates presenting an attacker with man-on-the-side capabilities active in China: securelist.com/windealer-deal… Recommended read!


Plato: everything is a number Unix: everything is a file Python: everything is an object So the Guido's generalization seems better than Greek's or Berkeley's


CodeFest speakers photo. Really nice generic industrial conference (front/backend, QA, system analysis, etc)

legezo's tweet image. CodeFest speakers photo. Really nice generic industrial conference (front/backend, QA, system analysis, etc)

Coffee cups here at CodeFest are like "drink, release, pray" (rhyme "пей, релизь, молись" in ru)

legezo's tweet image. Coffee cups here at CodeFest are like "drink, release, pray" (rhyme "пей, релизь, молись" in ru)

This Saturday at CodeFest conference in Novosibirsk we would discuss our research center (GReAT). If you can stand Russian language and midday, Siberian time - please be our guest 12.codefest.ru/lecture/2009


Indonesian stock exchange has its own bull

legezo's tweet image. Indonesian stock exchange has its own bull

#cpprussia C++ Russia conference published the agenda. This year I would participate and at 6 of June I would try to show the developers how the reverser looks at the code cppconf.ru/talks/c843f822…


Reversing training in Jakarta is over, thanks to all the participants and organisers

legezo's tweet image. Reversing training in Jakarta is over, thanks to all the participants and organisers

The new 90-s are upon Russia. I know precisely what previous ones did with my parents, you don't want to know. I have no particular reasons to assume that I'm stronger, healthier, faster, etc. you name it than they were back then. So all I could do is to act differently now


Loading...

Something went wrong.


Something went wrong.