The SolarWinds hack is a fundamental challenge, but I went into work yesterday focused on the same basics.

This may be a game-changer for policy and industry, but the essentials are what make the difference here. It revalidates basic visibility and monitoring. Same as before.

I do not see complex networks as they exist today as bastions where you can close your eyes anywhere assuming you're fine.

What if an attacker just compromised Orion with an exploit like a normal attacker? Or pivoted into its memory space from elsewhere?

What's the difference?
You've got to have pretty incredible network segmentation and administrative tiering and insider threat program before this kind of attack is the biggest risk to worry about.

That doesn't mean it's not incredibly serious. But we're failing way worse than this every single day.
This is a hard dichotomy to talk about without sounding dismissive, but I think it's worth bringing up. Be ever more mindful, but keep our foot on the gas on our fundamentals without letting up.
I'm putting some thoughts together, but I can't get over the fact _they didn't even try to infect your network if it looked like you were watching the machine_.

Like, we should be screaming about this. They know this shit works against them.
Note: This is not saying FireEye and other networks did not have monitoring in place, but it may not have been with tools in their list of "nope I'm not even trying" list.

The fact they hit FireEye seems like a massive mistake since they have internal custom tooling.
Everyone is doom and gloom while I'm like Neil Patrick Harris in Starship Troopers where he puts his hand on the bug and says "they feel fear" and everybody cheers.
It's worth saying, cyber hygiene may be in refutation of buzzwords, but it's not the end-all-be-all of IT protection.
You do need top-flight systems and people at the edges looking for the exceptional vectors.
But I want to keep harping on these fundamentals for everybody else.

More from War

[THREAD] On the recent ISIS Sinai video.

This is done with help from @war_noir, go follow.

As the ISIS insurgency in the Sinai continues, this video shows a very interesting mix of SALW, with some usual suspects appearing, but also more interesting things...

1/


First, the most prominent feature of the video is (as always), large IEDs blowing up army vehicles, with varied effectiveness. This has been a constant for years by now.

IS Sinai retain substantial IED expertise, with these...

2/


Also being laid in an anti personnel manner. Multiple targets are seen hit. Conventional close-range attacks are seen also.

3/


Now, let's turn to small arms. As usual, we see a mix of typical AKs, FALs, etc.

These include Type 56-1 and 2, FN FAL 50.00, FAL Para, AKM variants, and the ever present Libyan AK-103-2 (See thread here). We also see AMD-65.

https://t.co/CLIyU64RUD

4/


When it comes to heavier weapons, the commonly seen DShK/M and Type 54 are seen. These are common.

It is notable that IS Sinai have the operational freedom to use these on Technicals, despite the presence of the Egyptian Air Force. Oh, and 81/2mm mortar (Helwan M-69?)

5/

You May Also Like

1/12

RT-PCR corona (test) scam

Symptomatic people are tested for one and only one respiratory virus. This means that other acute respiratory infections are reclassified as


2/12

It is tested exquisitely with a hypersensitive non-specific RT-PCR test / Ct >35 (>30 is nonsense, >35 is madness), without considering Ct and clinical context. This means that more acute respiratory infections are reclassified as


3/12

The Drosten RT-PCR test is fabricated in a way that each country and laboratory perform it differently at too high Ct and that the high rate of false positives increases massively due to cross-reaction with other (corona) viruses in the "flu


4/12

Even asymptomatic, previously called healthy, people are tested (en masse) in this way, although there is no epidemiologically relevant asymptomatic transmission. This means that even healthy people are declared as COVID


5/12

Deaths within 28 days after a positive RT-PCR test from whatever cause are designated as deaths WITH COVID. This means that other causes of death are reclassified as
One of the most successful stock trader with special focus on cash stocks and who has a very creative mind to look out for opportunities in dark times

Covering one of the most unique set ups: Extended moves & Reversal plays

Time for a 🧵 to learn the above from @iManasArora

What qualifies for an extended move?

30-40% move in just 5-6 days is one example of extended move

How Manas used this info to book


Post that the plight of the


Example 2: Booking profits when the stock is extended from 10WMA

10WMA =


Another hack to identify extended move in a stock:

Too many green days!

Read
Margatha Natarajar murthi - Uthirakosamangai temple near Ramanathapuram,TN
#ArudraDarisanam
Unique Natarajar made of emerlad is abt 6 feet tall.
It is always covered with sandal paste.Only on Thriuvadhirai Star in month Margazhi-Nataraja can be worshipped without sandal paste.


After removing the sandal paste,day long rituals & various abhishekam will be
https://t.co/e1Ye8DrNWb day Maragatha Nataraja sannandhi will be closed after anointing the murthi with fresh sandal paste.Maragatha Natarajar is covered with sandal paste throughout the year


as Emerald has scientific property of its molecules getting disturbed when exposed to light/water/sound.This is an ancient Shiva temple considered to be 3000 years old -believed to be where Bhagwan Shiva gave Veda gyaana to Parvati Devi.This temple has some stunning sculptures.