Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Joe Słowik

@jfslowik@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

#Infosec, #CTI, and #ICS & Critical Infra Things
https://pylos.co

Also be on the alert for posts on heavy metal, sports ball (or black, cylindrical rubber object game 🏒), and various #shitposting.

Main job: analyzing the threats and doing the #CTI at Dataminr

Sidejob: #CTI and #ICS/#OT training and consulting through Paralus LLC (https://paralus.co)

Happy participant in TootFinder #tfr

3294 Followers
411 Following
36 Posts
Joined October 30, 2022
Personal Web:
https://pylos.co
Paralus Web:
https://paralus.co
LinkedIn:
https://www.linkedin.com/in/joe-slowik/
GitHub (shitty):
https://github.com/serrastusbear
Open post
Joe Słowik @jfslowik@infosec.exchange
· 1w ago
Threat intel acted on or disclosed is often threat intel lost - so how to balance long term collection with immediate needs? I tried exploring this a bit a few years ago… a discussion that I should do a deeper dive into. https://youtu.be/Cuhs4EJqxMw?is=rhsw3FnyToMIgZIY

The Disclosure Dilemma and Ensuring Defense

1
0
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
*Cuba's rickety-ass electric system under huge stress collapses, again* Thought leaders: "BUT WHERE IS THE PROOF THIS 𝗪𝗔𝗦𝗡'𝗧 CYBER???"
22
4
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
All the intelligence wonks in the DMV today:
15
10
1
1
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
All of the cyber vendors releasing Big Expensive Important Report on day one of Black Hat USA
13
0
3
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
CISA: IR-linked TA's are uploading malicious project files to PLCs! Industry & media: zzzzzzzzz Me: https://www.dataminr.com/resources/blog/implications-of-recent-cisa-disclosures-on-iranian-ot-targeting/
dataminr.com
10
1
6
1
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago

Rare ITW Energetic|BerserkBear (Dragonfly/CrouchingYeti/Iron Liberty/Ghost Blizzard/Bromine) sighting

11
0
5
1
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
Google/TAG/Mandoogle/Googliant:
8
1
4
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 1mo ago
Critical infrastructure security: filled with unpatched vulns, default passwords, and adversaries happy to take advantage of these in increasingly concerning ways. OT thought leaders: “that’s not new or novel, have you thought about how to build your brand?”
4
1
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 6mo ago

I FOUND WHERE THEY KEEP THE FURSONAS!!!

29
0
7
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
RE: https://infosec.exchange/@jfslowik/116994081734569429 Relevant: https://www.fox9.com/news/30-minnesota-water-systems-targeted-cyber-attack
Open quoted post
Quoting
Joe Słowik
@jfslowik@infosec.exchange
CISA: IR-linked TA's are uploading malicious project files to PLCs! Industry & media: zzzzzzzzz Me: https://www.dataminr.com/resources/blog/implications-of-recent-cisa-disclosures-on-iranian-ot-targeting/
Open quoted post
infosec.exchange
3
1
3
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
4
2
2
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 5mo ago

Thoughts on the meaning and implications of Mythos and Project Glasswing, what these mean for #informationsecurity, where these items are "right," and where they need to be pushed further for purposes of both security and safety:

https://pylos.co/2026/04/11/myth-mythos-where-do-we-go-from-here/

infosec.exchange
15
0
5
1
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
So the solar failed after 𝙘𝙝𝙚𝙘𝙠𝙨 𝙣𝙤𝙩𝙚𝙨 the sun set? Some big brains occupying Forrestal these days.
3
2
2
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 5mo ago
12
0
5
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
Replying to
@neurovagrant@masto.deoan.org @mttaggart@infosec.exchange Oh my I don't recommend that 😅
2
0
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
RE: https://infosec.exchange/@jfslowik/116964921675243942 We have learned that the bear has sadly passed (electrocuted). 𝙃𝙞𝙨 𝙣𝙖𝙢𝙚 𝙬𝙖𝙨 𝙍𝙤𝙗𝙚𝙧𝙩 𝙋𝙖𝙪𝙡𝙨𝙤𝙣.
infosec.exchange
2
1
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
Replying to
@DaveMWilburn@infosec.exchange This gem: https://www.state.gov/wp-content/uploads/2026/07/Cuba-Report.pdf
state.gov
2
3
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
T1078.001 @mitreattack@infosec.exchangehttps://www.denverpost.com/2026/07/18/coinstar-thefts-richard-pena-colorado/
denverpost.com
2
0
1
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 5mo ago

Ref:
https://www.dragos.com/blog/zionsiphon-ot-malware-analysis
&
https://www.nozominetworks.com/blog/zionsiphon-why-ot-threat-claims-need-technical-and-operational-scrutiny

dragos.com
7
0
4
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 3mo ago
Happy July 4th https://youtu.be/9t1IK_9apWs?is=U-UkGS4BYtGXr8L4

Independence Day (4/5) Movie CLIP - The President's Speech (1996) HD

2
1
1
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 3mo ago
SIGH
2
0
1
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
Replying to
@mttaggart@infosec.exchange that's an excellent question - I'm not sure. Let me dig in.
1
2
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
Replying to
@neurovagrant@masto.deoan.org @reverseics@infosec.exchange huh on Mastodon it stopped about 20 seconds in, my bad
1
2
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
Replying to
@reverseics@infosec.exchange @neurovagrant@masto.deoan.org I always loved the swtich from English to Spanish on this bit
1
4
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
Replying to
Deets: https://www.aikido.dev/blog/unauthenticated-rce-in-wordpress-wp2shell
aikido.dev
1
0
2
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 5mo ago

If you missed my #FIRSTCTI26 presentation on evaluating #CTI & threat intel at speed, a related blog is now available for review of the same concepts and argument:
https://www.dataminr.com/resources/blog/orienting-intelligence-for-real-time-alerting-response/

infosec.exchange
3
0
3
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 46mo ago

We're getting into "silly season" at the end of the year. With that in mind, I've thought about the things I did in 2022 that I found most interesting, helpful, or potentially impactful.

First, there's the paper on #CTI-driven #ThreatHunting I wrote and presented on at several events:
https://www.gigamon.com/content/dam/resource-library/english/white-paper/wp-intelligence-driven-threat-hunting-methodology.pdf

Then, there was my @VirusBulletin@infosec.exchange paper on the #XENOTIME actor responsible for the #Triton event, which I thought was neat as a deep-dive into organizational relationships that get masked in our tracking a single "adversary:"
https://www.virusbulletin.com/uploads/pdf/conference/vb2022/papers/VB2022-Zeroing-in-on-XENOTIME-analysis-of-the-entities-responsible-for-the-Triton-event.pdf

On a personal front, I wrote up some prelimianry analysis on the #Industroyer2 attempted (?) #ICS #OT incident as part of the conflict in #Ukraine - and there are still some items raised there for which we don't have answers several months after the incident was discovered:
https://pylos.co/2022/04/23/industroyer2-in-perspective/

Finally, I wrote a blog for my employer diving into the idea of the #FalsePositive in #DetectionEngineering and #SecurityMonitoring that I think is helpful for analysts from #IR to the #SOC
https://blog.gigamon.com/2022/08/05/revisiting-the-idea-of-the-false-positive/

I need to think this over a bit, but look for something covering the most insightful work of others, from my perspective, from the past year!

infosec.exchange
16
2
7
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
Replying to
@reverseics@infosec.exchange @neurovagrant@masto.deoan.org full clip, OPEN WIDE FOR SOME SOCCER: https://www.youtube.com/watch?v=442NF5cZhyc
0
1
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 47mo ago
Replying to
@charlesdardaman@infosec.exchange Sadly what Elon's doing - aside from the public nature of things and the hilarious self-owns - isn't THAT uncommon in the leveraged buy-out space (strip a company to the bone, aggressively cut costs, look for quick turnaround)
0
0
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
Replying to
@wagenseil@infosec.exchange yeah, G2 has def "punched above its weight" over the years, but to remotely rank them/Cuba ahead of _waves hands_ SO MANY OTHER ENTITIES as uniquely threatening outside of narrow/niche concerns is something. Like Ana Montes was REALLY BAD, but not "ZOMG THREAT TO THE HOMELAND" bad.
0
1
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
Replying to on mastodon.social
@Viss@mastodon.social At this point cuz the violators are rich
0
0
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 3mo ago
Me when I find someone unexpected has placed me on a block list: "What is it with this man? Did I kill a relative of his in battle, perhaps?"
0
1
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 3mo ago
Replying to
@Viss@mastodon.social lol yeah I was going through ClearSky and running through things on a whim - "Hmmm don't know them... don't care... oh that's odd.... oh man, I agree on this one... don't know" 😅
0
0
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 2mo ago
Replying to
@infoseclogger@infosec.exchange Things that disappear from the internet: important blogs, papers, and news articles Things that forever remain on the internet: that dumb thing I posted while drunk 14 years ago
0
0
0
0
Open post
Joe Słowik @jfslowik@infosec.exchange
· 3mo ago
Happy 4th of July https://www.youtube.com/watch?v=WM8bTdBs-cw
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 06:01:45 UTC