Ronnie Salomonsen
@r0ns3n.dk
90 followers 160 following 11 posts
Adversary Methods - Research & Discovery (RAD) Team @Mandiant - Now Part of @GoogleCloud. Former DFIR, Malware & Network Analyst. All tweets are my own.
Posts Media Videos Starter Packs
Reposted by Ronnie Salomonsen
gabagool.ing
Excellent breakdown of the “Rogue RDP” TTP we’ve seen susp Russian APT UNC5837 using in their campaigns written by my colleague Rohit (@IzySec over on X)
Windows Remote Desktop Protocol: Remote to Rogue | Google Cloud Blog
A novel phishing campaign by Russia-nexus espionage actors targeting European government and military organizations.
cloud.google.com
Reposted by Ronnie Salomonsen
volatilityfoundation.org
@volatilityfoundation.org New Release: #volatility3 v2.11.0 - visit github.com/volatilityfo... for details and downloads.

#memoryforensics #dfir
The latest Volatility 3 is now available at https://github.com/volatilityfoundation/volatility3/releases
Reposted by Ronnie Salomonsen
nixonnixoff.bsky.social
yay this feature is built into bluesky yay
Reposted by Ronnie Salomonsen
Reposted by Ronnie Salomonsen
bushidotoken.net
Looking for more people to follow on BlueSky? Find the @curatedintel.bsky.social folks here: go.bsky.app/Kfp62Uh
Reposted by Ronnie Salomonsen
techy.detectionengineering.net
I made a Detection Engineering starter pack, will be adding more as more folks jump over to bluesky! go.bsky.app/HenXJUR
Reposted by Ronnie Salomonsen
pivotcon.bsky.social
#PIVOTcon25 registration is now OPEN 🤟📥📥📥
pivotcon.org
#CTI #ThreatResearch #ThreatIntel
Please read carefully the whole 🧵 for the rules about invite -> registration (1/5)
two men are standing next to each other with the words " we open it up " on the screen
ALT: two men are standing next to each other with the words " we open it up " on the screen
media.tenor.com
Reposted by Ronnie Salomonsen
austinlarsen.me
#UNC5537 proved to be one of the most consequential threat actors of 2024 when they launched a campaign in April 2024 that systematically compromised misconfigured SaaS instances across over a hundred organizations.

cloud.google.com/blog/topics/...
UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion | Google Cloud Blog
A campaign targeting Snowflake customer database instances with the intent of data theft and extortion.
cloud.google.com