Matt Bromiley
bromiley.io
Matt Bromiley
@bromiley.io
⚙️ AI Security R&D @ Prophet Security
🎓 IR/TH/Incident Management Instructor
🎙️ Frequent Guest on Cybersecurity Defender's Podcast
🔍 Where to Find Me: https://github.com/bromiley
Pinned
Feels like a fresh start, so let's make it one. Nice to meet you :)

I'm a #cybersecurity nerd | security ai r&d
@prophetsecurity.bsky.social | frequent trainer
@sansinstitute.bsky.social, @blackhatevents.bsky.social, and other conferences | Cybersecurity Defenders Podcast | forever #blueteam.
Remember, remember the Seventh of January,
The fracture, the fog, the delay.
I see no reason why chaos and fury
Should ever become “the way”.

When noise wears the mask of conviction,
And volume is mistaken for might,
It isn’t the loud who should lead us forward,
But truth that survives the night.
January 7, 2026 at 10:33 PM
Tonight’s “in the air again” question:

Why did you convert an int to a float to just then convert it back to an int again?

“You’re absolutely right!”
December 18, 2025 at 2:02 AM
@eric.zip always compiling and releasing some of the hottest - but most necessary - modern tools. Can’t wait to sink my teeth into this.
I have always wanted an app like Zimmerman's Timeline Explorer, but for macOS.... Sadly, nothing remotely close exists except Excel 🤮

Stoked to say, I am nearly done with the the MVP! 😎

Supertimelines on MBP! #dfir
November 20, 2025 at 12:34 AM
Reposted by Matt Bromiley
I have always wanted an app like Zimmerman's Timeline Explorer, but for macOS.... Sadly, nothing remotely close exists except Excel 🤮

Stoked to say, I am nearly done with the the MVP! 😎

Supertimelines on MBP! #dfir
November 19, 2025 at 7:19 PM
I’m normally quiet about these things, but have to share a moment of laughter. If someone refers to you as “the dog that hasn’t barked”, you’re not the most powerful person in the room.

That’s leverage.
November 13, 2025 at 3:45 PM
Aww yissssssss...
August 18, 2025 at 4:07 PM
BSky Outreach - Anyone here an Obsidian user (for notes, "second brain", etc.)? Anyone want to sing their praises in a reply; I'm curious what your experience has been like.
August 11, 2025 at 2:18 PM
Usage spent towards troubleshooting Anthropic connectivity shouldn't count against your daily quota...
August 11, 2025 at 5:58 AM
Has anyone been able to get Notion's MCP to stay connected for more than 1 hour? This thing is about as stable as a baby deer.
August 11, 2025 at 2:00 AM
Reposted by Matt Bromiley
During my #BHUSA talk I've released many ETW research tools, of which the most notable is BamboozlEDR. This tool allows you to inject events into ETW, allowing you to generate fake alerts and blind EDRs.

github.com/olafhartong/...

Slides available here:
github.com/olafhartong/...
GitHub - olafhartong/BamboozlEDR: A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.
A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes. - olafhartong/BamboozlEDR
github.com
August 6, 2025 at 8:49 PM
Reposted by Matt Bromiley
day 1 of black hat 2025 in the books 🤓💙🌈

never a dull moment nerding with @eric.zip and @bromiley.io

@blackhatevents.bsky.social #BlackHatUSA
August 3, 2025 at 3:27 AM
Just to think, there _are_ people distracted by the MLK files.
July 21, 2025 at 11:44 PM
T-minus 12 days until my favorite humans - @eric.zip & @whit.zip - and I deliver our Advanced Security Operations and Threat Hunting training at @blackhatevents.bsky.social.

If you're a SOC analyst and/or work in IR, we'd love to have you. Come level up with us :)

www.blackhat.com/us-25/traini...
Black Hat
Black Hat
www.blackhat.com
July 21, 2025 at 4:13 PM
No, THIS is the guy to follow.

Pro tip: I follow @eric.zip therefore YOU should follow Eric.
If you’re in IR/SOC, this is a guy to follow!
Feels like a fresh start, so let's make it one. Nice to meet you :)

I'm a #cybersecurity nerd | security ai r&d
@prophetsecurity.bsky.social | frequent trainer
@sansinstitute.bsky.social, @blackhatevents.bsky.social, and other conferences | Cybersecurity Defenders Podcast | forever #blueteam.
July 21, 2025 at 3:09 PM
As is @philhagen.com !! Sharing the DFIR love
Matt is awesome and you should most definitely follow him!
Feels like a fresh start, so let's make it one. Nice to meet you :)

I'm a #cybersecurity nerd | security ai r&d
@prophetsecurity.bsky.social | frequent trainer
@sansinstitute.bsky.social, @blackhatevents.bsky.social, and other conferences | Cybersecurity Defenders Podcast | forever #blueteam.
July 21, 2025 at 3:08 PM
Feels like a fresh start, so let's make it one. Nice to meet you :)

I'm a #cybersecurity nerd | security ai r&d
@prophetsecurity.bsky.social | frequent trainer
@sansinstitute.bsky.social, @blackhatevents.bsky.social, and other conferences | Cybersecurity Defenders Podcast | forever #blueteam.
July 20, 2025 at 6:08 PM
Defenders out there - CVE-2025-53770 is an unpatched, actively exploited vulnerability in SharePoint. If you have on-prem SharePoint facing the Internet, roll up your sleeves.

Microsoft's guidance:
1. Configure the Windows AMSI integrations and deploy Defender AV.
2. Disconnect from the Internet.
July 20, 2025 at 6:06 PM
They’ve done it again…
🚀 Just launched: DetectionForge — a purpose-built platform for crafting, testing & validating @limacharlie.io detection rules.

Perform detection unit tests & multi-org backtesting + import/export IaC

🔗 Try it: detectionforge.ddi.sh
💻 GitHub: github.com/Digital-Defe... #detectionengineering #secops
DetectionForge
DetectionForge - A comprehensive detection engineering environment for crafting, validating, and testing LimaCharlie detection rules
detectionforge.ddi.sh
June 19, 2025 at 6:48 PM
Reposted by Matt Bromiley
ATTN NERDS:

we'll be teaching at @blackhatevents.bsky.social during hacker summer camp again!

come join me and @eric.zip and @bromiley.io for our 4-day training: Advanced Security Operations and Threat Hunting 🤓🔥💙

www.blackhat.com/us-25/traini...
May 20, 2025 at 10:29 AM
No matter where in the world you go, one thing remains the same: the guy at the gym who slams weights down and then looks around to see who noticed.

🤦‍♂️
March 17, 2025 at 7:38 AM
Kendrick Lamar just owned 2025.
February 10, 2025 at 1:41 AM
Reposted by Matt Bromiley
ATTN NERDS:

We'll be at @blackhatevents.bsky.social USA again this year!

Registration is now open for our Advanced Security Operations and Threat Hunting course 🤓🔥💙

Join @eric.zip, @bromiley.io, and @whit.zip for our 4-day training: www.blackhat.com/us-25/traini...
February 7, 2025 at 5:48 AM
Reposted by Matt Bromiley
Secure Annex can now be used directly from with @limacharlie.io 's SecOps Cloud Platform. Installed agents give visibility into extensions utilized and are now enriched. These attributes can be used to run D&R rules for immediate response to issues.

https://limacharlie.io/blog/automating_browser_e…
LimaCharlie & Secure Annex: Browser Extension Security
Automate browser extension security monitoring with LimaCharlie and Secure Annex. Learn about detection rules, vulnerability monitoring, and comprehensive management tools for enhancing your…
limacharlie.io
January 30, 2025 at 5:25 PM
Another week, another episode of The Cybersecurity Defender's Podcast in the books with @tekgrunt.bsky.social !!

More podcasting news on the horizon for me, but always a fun weekly chat with Chris @limacharlie.io.

Check the podcast out here: limacharlie.io/podcast
January 29, 2025 at 6:39 PM