Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Taylor Parizo

@taylorparizo@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Threat Hunting and former Threat Intelligence | “Doubt is not a pleasant state, but certainty is a ridiculous one” - Voltaire

464 Followers
238 Following
40 Posts
Joined November 08, 2022
Blog:
https://blog.axelarator.net/
PixelFed:
https://pixel.infosec.exchange/taylorparizo
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 2w ago

Physical copy arrived and the print work is amazing @lcamtuf@infosec.exchange

8
0
2
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 4w ago
This might be the first vacation in a long time that I really avoided any cyber-related news. It helps when I was without service most of the week a national park. All I know is I'm glad my Mikrotik product doesn't run RouterOS. The nightmare resumes tomorrow.
2
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 3w ago

New rack arrived today. The audio setup is finally complete.

1
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 4mo ago

We got a little excited at the nursery. There’s spinach, bell pepper, jalepeno, cayenne, Carolina reaper, cinnamon basil, tomatoes and tomatillos. Cilantro is in its own pot because we ran out of space. #gardening

infosec.exchange

Infosec Exchange

11
0
1
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 1mo ago

Starts a honeypot
Immediate ../

2
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 6mo ago

MOIST KEYCHAIN!? We cannot be serious 😂

In early February 2026, the Iranian state-aligned cyber espionage group MuddyWater (also tracked as Seedworm, MERCURY, Static Kitten, MOIST KEYCHAIN, and Mango Sandstorm)
https://krypt3ia.wordpress.com/2026/03/20/threat-intelligence-report-mango-sandstorm-indoor-fakeset-activity/
#ThreatIntel

Threat Intelligence Report: MANGO SANDSTORM Dindoor / Fakeset Campaign
Krypt3ia

Threat Intelligence Report: MANGO SANDSTORM Dindoor / Fakeset Campaign

Date: March 2026By: Krypt3ia Executive Summary In early February 2026, the Iranian state-aligned cyber espionage group MuddyWater (also tracked as Seedworm, MERCURY, Static Kitten, MOIST KEYCH…

12
2
7
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 4mo ago

@cR0w@infosec.exchange Or when the vendor feeds push any reference of an RFC1918 address into an indicator list. Yeah lemme enrich 192.168.2.134, see if any adversaries are using that IP and block it. I sure hope it doesn't appear in our logs or we're cooked 🙃🙃🙃

5
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 3mo ago
Looking for obfuscated IP-KVMs in your environment? Check for devices communicating with 178.62.55.152 (files.pikvm.org). It acts as a "phone home" website on DigitalOcean for PiKVM.
3
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 6mo ago

I've been habitually taking my camera with me when I go out so I take more photos. I thought I'd take more at the museum over the weekend but only ended up taking one. Not even mad because this is one of the more creative ones in a long time. Inside looking out a window so I metered the window light rather than the average room light.
#Fujifilm

infosec.exchange

Infosec Exchange

11
0
4
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 4mo ago

I used to take apart electronics when I was very young mainly because it was cool to see what was inside these common electronics around the house. Kind of wish I stuck with that curiosity because lately I've been interested in hardware hacking and I realized I'm revisiting past interests from 15+ years ago. This post was very interesting to see what tools exist today but I was curious if anyone has their own recommended list? Anyone else do this as a hobby or career?
#HardwareHacking #IoT

https://www.redfoxsec.com/blog/getting-started-with-hardware-hacking

redfoxsec.com

Getting Started with Hardware Hacking: Beginner's Guide

4
0
1
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 6mo ago

Nice list. Some tools have a lot of feature overlap which make enrichment much easier. I’m in Censys, Validin, and Hunt.io (didn’t see mentioned) almost daily. I need to familiarize myself with using BGP tables more though.
https://github.com/curated-intel/Attribution-to-IP

github.com
7
0
5
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 3mo ago

Someday I'll learn how to use a computer. Fought network issues for an hour until I rage quit and restarted the server. That was it. A restart literally fixed it.

2
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 2mo ago
Oh boy ANOTHER ONE https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/
Updated Cyber Threat Actor Naming System | Google Cloud Blog
Google Cloud Blog

Updated Cyber Threat Actor Naming System | Google Cloud Blog

1
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 3mo ago

Internet is down so it’s a perfect time to make use of my record collection

2
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 3mo ago

My ideal employer should learn how to accurately list a job posting.

2
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 2mo ago
I installed Rayhunter when it was first released. At the time, it seemed like a capture tool without a way to truly decipher captured traffic, especially if it "found something." Has the project gotten more user friendly with better heuristics? I see there are some but still leaves a lot of uncertainty. https://cybernews.com/privacy/us-police-israeli-spy-vans-falconet-cognyte/ #spyware #surveillance
cybernews.com
1
1
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 6mo ago

We got a Telnet vulnerability older than some GTA 6 developers.

5
0
1
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 7mo ago

Hands on is the way to learn, so I built an email service with SES, setup IRC in EC2, used Pacu for recon/persistence and analyzed logs along the way in CloudTrail.
#aws #cloud

https://blog.axelarator.net/learn-by-doing-aws/

Learn By Doing - AWS — Axelarator
blog.axelarator.net

Learn By Doing - AWS — Axelarator

It

6
0
2
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 5mo ago

A reminder to use google ads transparency center for a quick pivot on some phishing domains.
#phishing #clickfix #ThreatIntel
https://sakshamanand.com/blog/clickfix-google-ads-discovery/

infosec.exchange

Infosec Exchange

3
0
1
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 3mo ago
Replying to
I went with fluent bit. Not a fan of having to write a custom XML parser for Windows events but Linux and Zeek logs were simple enough. https://docs.fluentbit.io/manual #opensearch #ThreatHunting
docs.fluentbit.io
1
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 3mo ago
Replying to
This has been a fun guide to learn from. Good information without getting too in-depth. https://beej.us/guide/bgc/html/split/pointers.html
beej.us

Beej's Guide to C Programming

1
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 5mo ago
Replying to
I took the idea a step further and contracted some work to run Ethernet through the home. Primary ISP coax line used to run straight into my office from outside. Now it’s routed to the basement where the rack lives and Ethernet is terminated to the patch panel. Still need to get that Sliger chassis though but my wallet needs to heal first… #homelab
2
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 4mo ago

This just sounds like a Nuclei vuln scanner with extra steps ✨but make it AI so the industry freaks out✨

https://www.utoronto.ca/news/u-t-researchers-demonstrate-ai-worm-could-target-any-online-device

U of T researchers demonstrate AI worm could target any online device
University of Toronto

U of T researchers demonstrate AI worm could target any online device

A team of researchers at the University of Toronto has discovered a new class of cyberthreat that gives hackers more power and reach at far less cost. It can be built with free AI models. Every online device is a potential target. And current cyber defences are not yet ready for it.

1
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 7mo ago

Time for coffee (decaf)

3
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 6mo ago

Might be time to sell my 32Gb of RAM for a network switch. #FCC

infosec.exchange

Infosec Exchange

2
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 4mo ago

@cR0w@infosec.exchange Oh for sure I don't think you can vibe code any of this with an ounce of reproducibility. I don't have Cursor to test these prompts so I'm curious how close some of these claims even get.

1
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 4mo ago

New post where I explore Zeek, Arkime and JA4+.
#ThreatHunting
https://blog.axelarator.net/we-have-packet-capture-at-home/

infosec.exchange

Infosec Exchange

1
1
3
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 7mo ago
Replying to
@apth Do something with it. We can send links all day but before pressing send, ask why you’re doing it, what you expect out of it, and share your own thought about it. In the large enterprise, “is this relevant to our org or customer?”, “what can we do with the Intel provided?” That’s the simple part. What’s not so easy is how to convey Intel to teams in a manner that makes sense and isn’t just another talking point to gloss over. This article was recently posted which provides a real example. https://feedly.com/ti-essentials/posts/how-to-fuse-cti-with-threat-hunting
How to Integrate CTI with Threat Hunting: A Practical Guide | TI Essentials | Feedly
Threat Intelligence Essentials - Best Practices for CTI Pros

How to Integrate CTI with Threat Hunting: A Practical Guide | TI Essentials | Feedly

2
0
1
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 7mo ago
Replying to
Yeah this sums it up. #threatintel
2
0
1
1
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 7mo ago
Replying to
One more for good measure because why not: host.services.cert.parsed.issuer_dn="cgWUqATNuKVKop+/nRG88+u7AEo2ulPc/6DzDNJyq3Q" #ThreatIntel #CTI #MuddyWater
1
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 7mo ago

I’ve gone down the hyprland rabbit hole. Doomscrolling has been replaced by modifying config files.
#Hyprland

infosec.exchange

Infosec Exchange

1
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 7mo ago
Replying to
@apth work. Although I’ve dealt with Intel platforms that are more information panels than they are functional
1
2
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 7mo ago
Replying to
The second html_title query has been updated to: host.services.endpoints.http.html_title={"McCluskey", "MotoGP Fans Deutschland"}
0
1
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 2mo ago

I'm not pirating, I'm training a local model on my Plex library

0
0
0
0
Open post
Taylor Parizo @taylorparizo@infosec.exchange
· 4mo ago

So happy to not only see GW3 is happening after 14 years since GW2 released but they also aren't killing any prior live services and will continue to update GW2 even after 3 releases. I created a new character in GW2 last night and bought the first 4 DLCs. I logged countless hours in this game a decade ago and this announcement brought me back.

https://www.guildwars2.com/en/news/future-of-the-guild-wars-franchise/

The Future of the Guild Wars Franchise: Our Commitment to Tyria – GuildWars2.com
GuildWars2.com

The Future of the Guild Wars Franchise: Our Commitment to Tyria – GuildWars2.com

Hear directly from our leadership team about our plans and how you can help shape what comes next in Guild Wars 2.

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 00:54:28 UTC