#DFIR and research.

Sydney, Australia
Joined August 2010
Matthew Green ๐ŸŒป retweeted
Printing Just A Little Bit Iโ€™d say we are roughly at the 2 minute mark โ€ฆ
107
497
74
1,678
97,539
๐Ÿฆ– A quick blog post to share velociraptor-skills: AI skills for DFIR with Velociraptor. Includes the repo link and a walkthrough of installation and lab use. ๐Ÿ”— labs.infoguard.ch/posts/ai_aโ€ฆ
3
9
37
1,946
Matthew Green ๐ŸŒป retweeted
I found an exposed directory through Hunt io containing a Russian-language CLAUDE.md that looks like an operational playbook for AI-assisted exploitation. The workflow: Find leaked credentials -> enumerate the target stack -> test LFI/RCE/SQLi/IDOR/business logic -> avoid rate limits -> establish access -> move on. It specifically tells the operator not to waste time brute-forcing passwords before finding something critical. Alongside it are scripts for SharePoint key extraction, TeamCity, SonicWall SMA 1000, BeyondTrust, SmarterMail and LoadMaster. .bash_history also shows repeated OpenCode use across multiple targets. Do we think this is a pentest or a real threat actor? ๐Ÿ˜‚ I think the latter lol Pay attention to how closely this matches the boring reality of a lot of intrusion activity... Known vulns. Exposed management interfaces. Leaked credentials. Secrets. Weak auth. Misconfigurations. Automation to enumerate and exploit faster. That is what defenders should be hunting continuously. We spend a lot of time talking about advanced sandbox evasion, novel malware and APT tradecraft because it makes better headlines. Meanwhile, a huge amount of real-world access still starts with very basic stuff that someone bothered to look for. AI just makes that workflow faster and easier to scale. Also, ssh-authorized_keys and files named ssh-jagarzon are in the screenshot. APT Jagarzon confirmed? ๐Ÿ˜‚ Absolutely not lol
9
73
2
367
23,288
๐Ÿ’š NVIDIA launches its Open Agent Safety Platform, an open reference design for running AI agents more safely. An agent ๐Ÿค– can ask for more access, but it should not approve its own request. ๐—›๐—ผ๐˜„ ๐—ข๐—ฝ๐—ฒ๐—ป๐—ฆ๐—ต๐—ฒ๐—น๐—น ๐—ฝ๐˜‚๐˜๐˜€ ๐˜๐—ต๐—ถ๐˜€ ๐—ถ๐—ป๐˜๐—ผ ๐—ฝ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐—ฐ๐—ฒ OpenShell separates the agentโ€™s work from permission decisions: โ€ข ๐—š๐—ฎ๐˜๐—ฒ๐˜„๐—ฎ๐˜†: Manages sandboxes, workspaces, policies, and providers. It controls policy changes and how network access proposals are approved. โ€ข ๐—ฆ๐—ฎ๐—ป๐—ฑ๐—ฏ๐—ผ๐˜…: Runs the agent and child processes under kernel controls for files and privileges. It identifies programs making outbound requests and passes those requests to the supervisor, with no direct external route. โ€ข ๐—ฆ๐˜‚๐—ฝ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐˜€๐—ผ๐—ฟ: Runs outside the agent workload, checks outbound requests against policy, and adds managed credentials only when authorized, without exposing them to the agent. โ€ข ๐—ฃ๐—ผ๐—น๐—ถ๐—ฐ๐˜† ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ฒ๐—ฟ: Flags risky access in proposed network rules. Its standalone check compares a candidate policy with an operatorโ€™s boundary and shows an example if modeled permissions exceed it. ๐—ช๐—ต๐—ฎ๐˜ ๐—ฐ๐—ฎ๐—ป ๐˜๐—ต๐—ฒ ๐—ฟ๐˜‚๐—ป๐˜๐—ถ๐—บ๐—ฒ ๐—ฐ๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น? For configured endpoints, OpenShell can inspect REST methods and paths, GraphQL operations and fields, and MCP methods and tool names. With enforcement enabled, it can allow a read and block a write to the same service, even through a shell, generated code, or child process. A blocked request can explain why. ๐—ช๐—ต๐—ฎ๐˜ ๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ๐—ฑ ๐—ถ๐—ป ๐Ÿฌ.๐Ÿญ.๐Ÿฌ? OpenShell already had sandboxing and API policies. This milestone separates the supervisor from the workload across supported runtimes and authenticates their channel for each sandbox. It verifies the network boundary before launch and freezes the workload if the supervisor disconnects. Policies reject unknown fields, and a standalone checker tests proposed permissions against an operatorโ€™s boundary. ๐—Ÿ๐—ผ๐—ด๐˜€ ๐—ผ๐—ฟ ๐—ถ๐˜ ๐—ฑ๐—ถ๐—ฑ๐—ป'๐˜ ๐—ต๐—ฎ๐—ฝ๐—ฝ๐—ฒ๐—ป OpenShell already emits OCSF events for observed process, network, and API activity, including policy decisions. This predates 0.1.0. Operators can enable full JSON export and ship the records to a SIEM or data lake. Since a sandbox may last only one task, collecting events while it runs preserves evidence for investigation. ๐—ช๐—ต๐—ฒ๐—ฟ๐—ฒ ๐—ฆ๐—ฒ๐—ป๐˜๐—ฟ๐˜† ๐—ฎ๐—ป๐—ฑ ๐—•๐—น๐˜‚๐—ฒ๐—™๐—ถ๐—ฒ๐—น๐—ฑ ๐Ÿฐ ๐—ณ๐—ถ๐˜ BlueField 4 is a data processing unit (DPU), a separate processor for networking and security. In the Vera Rubin POD reference design, it sits on the nodeโ€™s path to the model. Sentry uses DOCA, the framework for programming BlueField, for independent monitoring, identity governance, and enforcement. This optional layer fits AI factories with BlueField infrastructure. OpenShell also runs on supported local, cloud, and Kubernetes systems without it. The result: operator-controlled access, enforced at runtime, with policy decisions logged for investigation.
Today, with over 100 industry partners, we introduced the NVIDIA Open Agent Safety Platform, bringing together OpenShell and Sentry. Artificial intelligence is extraordinary technology that will advance discovery, productivity, security, health, and prosperity for generations to come. But its full promise can only be realized when people have confidence that AI is being built to be safe and deployed with wisdom and responsibility. This is bigger than a single product. It's the beginning of an open ecosystem to build the trust layer for safe agent systems. Together, we are building the foundation of the AI economy. Trust and innovation are not in conflict. Safety is how trust is earned. We must build not only the most capable AI, but the most trusted AI, so that this extraordinary technology can realize its enormous promise for the world. nvda.ws/4hcoq7m
14
3
9
2,267
Matthew Green ๐ŸŒป retweeted
I asked dozens of ransomware groups one important question, do they like cats, here are the results ๐Ÿงต๐Ÿ‘‡
74
241
46
1,617
178,693
Matthew Green ๐ŸŒป retweeted
I think that all of the focus on exploit specific detection is a losing strategy in general. Post-exploitation detection is more resilient and if you're strong there, you will catch intrusions regardless of the CVE number. The overwhelming majority of in the wild zero day exploitation I have encountered in my life has been identified by detecting post-exploitation behavior.
5
16
76
4,188
Matthew Green ๐ŸŒป retweeted
If you have a Citrix Netscaler device, act now โ€ฆ itโ€™s serious
NCSC brengt een security-advisory uit over Citrix NetScaler ADC en NetScaler Gateway. De kans en schade van deze kwetsbaarheid beoordelen wij als high/high. Wij adviseren u de security-advisory op te volgen. advisories.ncsc.nl/2026/ncscโ€ฆ #CyberSecurity
4
26
2
109
52,140
Matthew Green ๐ŸŒป retweeted
My blog post on the Iran-backed APT group MuddyWater is out. MuddyWater uses tools from TAG-150, a Malware-as-a-Service platform run by Russian-speaking cybercriminals. In this campaign, an MSI package is distributed through Amadey, installs the Deno-based DinDoor agent and runs it in memory. The agent collects browser passwords, cookies and crypto wallet data, and the final stage of the chain connects to a CastleRAT C2 server. medium.com/@Root0ne/muddywatโ€ฆ
6
41
4
197
24,427
Matthew Green ๐ŸŒป retweeted
๐Ÿงต New misalignment disclosures! 1. A model published a GitHub token in a public repo while trying to cheat on a math task. It used GitHub Actions to run code outside its restricted environment and retrieve another teamโ€™s submission logs. When GitHub blocked its attempt to add a workflow, it modified a script that an existing workflow would run instead. It embedded the token in pieces to avoid secret scanning. The model violated the system prompt and two explicit user instructions to solve the problem itself.
28
51
27
551
98,959
Matthew Green ๐ŸŒป retweeted
Periodic reminder: Good security architecture minimizes the number of bugs and CVEs you have to care about.
9
45
10
233
17,973
Matthew Green ๐ŸŒป retweeted
ScreenConnect is 74.5% of the abused remote-access tools @HuntressLabs sees. So I detonated two real samples and hunted both on Defender and Elastic. Full hunt notes and every query in the Article.
2
33
128
18,105
Matthew Green ๐ŸŒป retweeted
Remember the guy who hacked his gym using AI, Andrew Bird? Well, I did a little OSINT, and it turns out he is the Conference Co-Director of Effective Altruism Global since 2015. Isn't it interesting that every major "AI" hack has been made by people directly connected to Effective Altruism?
NEW: A Melbourne man asked his AI assistant OpenClaw to book a gym class. It found a exploit in the gym website, got around booking restrictions and kicked someone off the waiting list to move him up a spot It's the first known Australian case of AI agents autonomously hacking!
74
365
60
2,560
174,059
Matthew Green ๐ŸŒป retweeted
I put my @UnpromptedAU slides up at justdionysus.github.io/slideโ€ฆ โ€” a bit of reflection on exploit development in the age of AI. My TL;DR is keep pushing to understand complex things, be honest with your own understanding, and use AI as a power tool to increase pace and depth.
4
68
5
240
32,469
Matthew Green ๐ŸŒป retweeted
๐Ÿšจ FIRST REPORTED AUTONOMOUS AI C2 MALWARE IMPLANT DISCOVERED Cisco Talos has disclosed CLOSEDQUORUM, what researchers believe is the first publicly documented Windows malware implant that delegates tactical command-and-control decisions directly to multiple commercial AI models. โ€ข The malware can query DeepSeek, Qwen, Mistral and Google Gemini โ€ข Models independently vote on what the malware should do next โ€ข The winning decision is automatically executed without continued human operator commands โ€ข Capabilities include LSASS credential dumping, browser-password theft and crypto-wallet collection โ€ข It supports process injection, persistence, ETW telemetry suppression and sandbox-evasion techniques โ€ข Stolen information can be encrypted and exfiltrated through Discord webhooks โ€ข Instead of relying solely on traditional attacker-controlled C2 logic, the implant uses legitimate LLM-provider endpoints as part of its decision architecture โ€ข Talos linked development artifacts to an individual associated with criminal-forum carding activity dating back to 2025 โš ๏ธ Important: Talos has NOT confirmed deployment of CLOSEDQUORUM in the wild. The publicly analyzed build contains placeholder API keys and a dummy webhook, so this should currently be treated as emerging offensive tooling rather than an active malware campaign. โš ๏ธ Analyst Note: The architectural shift is significant: AI is no longer simply helping an attacker write malware โ€” the models themselves are being placed inside the malware's operational decision loop. Original Cisco Talos research: blog.talosintelligence.com/tโ€ฆ #AI #Malware #C2 #ThreatIntel #CyberSecurity #AgenticAI #DDW #DarkWeb
4
14
8
70
25,630
Matthew Green ๐ŸŒป retweeted
"They then inspected the documents they collected prior to exfiltrating them over to Mega storage servers using the Rclone application." Read the full report: buff.ly/9SUamWk #DFIR #ThreatIntel
8
36
3,608
Matthew Green ๐ŸŒป retweeted
Good piece from the NCSC on agentic defence The difficult part starts when the agent is allowed to actually change things in production. Scope, criticality, confidence and recoverability suddenly matter a lot more than โ€œcan the model understand the attack?โ€ Worth a read ncsc.gov.uk/blogs/one-does-nโ€ฆ
5
52
6
242
18,136
Matthew Green ๐ŸŒป retweeted
Si haces Threat Intelligence o ciberseguridad defensiva, tienes que guardar esto ahora mismo. Crearon CLOAK, un framework al estilo MITRE ATT&CK pero enfocado 100% en las tรกcticas de ocultaciรณn y evasiรณn de los cibercriminales. ๐Ÿ” ยฟQuรฉ incluye? โ€ข 1,387 TTPs documentados. โ€ข Capas tรฉcnicas, comportamentales y fรญsicas. โ€ข 100% Open source y actualizado este 2026. Entender cรณmo se esconden los atacantes es la รบnica forma de encontrarlos antes de que sea tarde. Te dejo la plataforma interactiva y los detalles abajo en los comentarios ๐Ÿ›ก๏ธ๐Ÿ‘‡
19
232
4
1,327
56,623
Matthew Green ๐ŸŒป retweeted
All of the coolest Jev projects I could find on X today ๐Ÿงต
114
253
46
4,447
505,130
Matthew Green ๐ŸŒป retweeted
here's how JEV works, simplified I've been experimenting with it for the last hour, and it's EXTREMELY good at making decisions with the right references and context you give it the information, your questions, and the type of answer each question needs: > a choice from options you provide > a score on a scale you define > a probability that something is true the models we're used to often give us long written answers, with explanations and reasoning jev returns structured answers your app can use directly, instead of generating those explanations information + your questions + allowed answers โ†’ answers your app can use you define what happens next, based on those answers that could mean sending information to the right place, checking an AI agent's work, or flagging something for human review because jev doesn't generate prose, it doesn't invent facts or sources inside a written explanation (hallucinations) clear questions and useful context matter, including references that explain what it should check I'm seeing so many cool use cases across X, and I can see people adding this to all kinds of existing apps if you haven't started building with it yet, try it on one decision your app already makes
the new jev model is insane.. it can check your AI's work and make decisions inside software for $0.042 per million input tokens, with free output here are the first things you should use jev for: 1. second brain 2. content workflow 3. post analysis 4. SEO article review typesafe reports up to 193.6ร— faster results and 444.6ร— lower costs than the LLMs in its workflow tests you give jev information and specific questions. it returns choices, scores or probabilities that your software uses to decide what happens next 1. second brain when a document, message or meeting note enters your second brain, give jev the content and your categories identify what it is, classify the topic and check for duplicates against existing notes your software checks required fields, saves the content with its source and verifies that it was saved correctly works well with the karpathy LLM wiki framework 2. content workflow give jev your draft, and then reference your anti slop rules and voice DNA file (which defines how you write) it will check for generic phrasing, repeated points and differences from your voice. use previous content and its results to estimate performance potential then send results to the writing agent for revision, compare the performance estimates with results after publishing 3. post analysis jev can compare a draft with previous posts and their results to estimate how well it could perform with your audience evaluate the hook, topic and format against defined criterias. and compare those scores with the performance after it goes live 4. SEO article review give jev your article / page draft, a target keyword and the articles currently ranking for that keyword (in the top 10 SERP) compare how well they answer the query, cover the topic and provide useful information. use that comparison to estimate your article's ranking potential then your LLMs can revise weak sections before publishing, and compare the estimate with actual rankings so many more usecases, we will see many new upgrades to previous concepts and workflows weยดve read about now
28
123
4
1,095
154,742