Haag's Avatar

Haag

@mhaggis

Just a person hacking away.

271
Followers
209
Following
34
Posts
16.02.2023
Joined
Posts Following

Latest posts by Haag @mhaggis

Hi

11.09.2025 13:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - MHaggis/ASRGEN: ASR Configurator, Essentials and Atomic Testing ASR Configurator, Essentials and Atomic Testing. Contribute to MHaggis/ASRGEN development by creating an account on GitHub.

🚨 Still on your journey to mastering ASR rules?
Don’t sleep on ASRGEN πŸ›‘οΈπŸ’₯

⚑ Point. Click. Generate ASR rules.
πŸ” Learn + test safely with built-in atomic simulations
πŸ“¦ Export to Intune/GPO-ready formats
🎯 Built for defenders, by defenders

πŸ‘€πŸ”₯
πŸ‘‰ asrgen.streamlit.app

πŸ“š github.com/MHaggis/ASRGEN

21.08.2025 07:36 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
πŸš€ Fresh ClickGrab ✨ | Into the Rabbit Hole πŸ‡πŸŒ€
πŸš€ Fresh ClickGrab ✨ | Into the Rabbit Hole πŸ‡πŸŒ€ πŸ”₯ We started fresh with ClickGrab πŸ–±οΈβœ¨ looking at some new stuff… but then the whole thing flipped upside down πŸŒ€ and turned into a full-on rabbit hole deep dive πŸ•³οΈπŸ‡ πŸ” What we explored: πŸβ€¦

πŸ†•πŸ‡ Just dropped a 1-hour rabbit hole dive into API playgrounds, mocks, & random nerdy finds πŸ€“

We started with ClickGrab, but then it turned into:

🐝 Beeceptor

πŸ› οΈ Mockbin

🧩 Zudoku

πŸ” VirusTotal hunts

πŸ€– ChatGPT making OpenAPI bins & routes

Chaotic, nerdy, fun. Come hang out πŸ‘‰ youtu.be/j7QE-6p9Y9Q

20.08.2025 07:36 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Minted narwhal!

I am/was burnt sienna goose

29.04.2025 19:45 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
ASRGEN Access ASRGEN here on https://asrgen.streamlit.app/

🚨 New ASR rules are now GA:

❌ Block rebooting in Safe Mode
πŸ•΅οΈβ€β™‚οΈ Block copied/impersonated system tools

ASRGEN had these since preview. 😎

Want to:

⚑ Quickly create Intune-ready ASR policies
πŸ§ͺ Simulate and understand rule impacts

Check β†’ asrgen.streamlit.app

Be proactive. Be precise.

14.04.2025 20:15 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ’° The hunt begins…

The first drops for PowerShell-Hunter: Season 2 are coming SOON.
New tools. Smarter hunting. Sexier telemetry.
This isn’t just DFIRβ€”it’s an evolution.

βš”οΈ Hunt smarter. Hunt harder.
⭐ github.com/MHaggis/Powe...

14.04.2025 12:02 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - MHaggis/PowerShell-Hunter: PowerShell tools to help defenders hunt smarter, hunt harder. PowerShell tools to help defenders hunt smarter, hunt harder. - MHaggis/PowerShell-Hunter

🚨 PowerShell-Hunter Season 2 is coming 🚨

πŸ’₯ More atomic tools
🧬 Smarter, faster log analysis
πŸ€– Machine learning meets lateral movement
😈 PowerShell so slick it should be illegal

You’re not readyβ€”but you should be.
⭐ Star the repo or miss the magic:

10.04.2025 17:40 πŸ‘ 5 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
PCA Analyzer Demo: Uncover Hidden Windows Execution History | PowerShell-Hunter Toolkit
PCA Analyzer Demo: Uncover Hidden Windows Execution History | PowerShell-Hunter Toolkit πŸ” Discover the wealth of forensic evidence hiding in your Windows PCA logs!In this demonstration, I showcase the PCA Analyzer - a powerful forensic tool fro...

πŸŽ‰ Exciting News: PCA Analyzer is now part of the PowerShell-Hunter suite! πŸš€

Check it out on GitHub: github.com/MHaggis/PowerShell-Hunter πŸ’»

πŸ“Ί

04.03.2025 08:36 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Atomics on a Tuesday || Introducing The SDDLMaker
Atomics on a Tuesday || Introducing The SDDLMaker 🌟 πŸ”¬ In this EXTRAORDINARY episode of Atomics on a Tuesday 🎯, we venture deep into the mysterious realm of Windows Security Descriptor Definition Language ...

πŸŽ₯ Want a deeper dive? Check out Atomics on a Friday, where we introduce SDDLMaker!
▢️ https://www.youtube.com/watch?v=uSYvHUVU8xY

πŸ”„ RT/Reshare if you find this useful! πŸš€

#WindowsSecurity #SDDL #Cybersecurity #Splunk #AtomicRedTeam

21.02.2025 15:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Analytics Story: Defense Evasion or Unauthorized Access Via SDDL Tampering Date: 2024-12-06 ID: 8ccdd852-3878-4871-ae37-e5af5c67baf3 Author: Nasreddine Bencherchali, Michael Haag, Splunk Product: Splunk Enterprise Security Description This analytic story focuses on…

πŸ› οΈ Splunk Security Content:
πŸ”— https://research.splunk.com/stories/defense_evasion_or_unauthorized_access_via_sddl_tampering/

🧠 Mind Map:
πŸ”— https://github.com/MHaggis/SDDLMaker/tree/main/MindMap

🧡 (5/)

21.02.2025 15:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
SDDL Parser Welcome to , a handcrafted bespoke tool to revolutionize the way you build and analyze Windows Se...

πŸ’‘ Need to decode or generate SDDL? Try SDDLMaker πŸ”§
πŸ‘‰ https://thesddlmaker.streamlit.app/

πŸ“œ Read the full blog:
πŸ”— https://www.splunk.com/en_us/blog/security/windows-security-sddl-guide-access-control.html

🧡 (4/)

21.02.2025 15:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Top 3 Things You'll Learn:
1️⃣ How attackers exploit SDDLβ€”event log tampering, service hardening, & more
2️⃣ How to decode SDDL strings & analyze permissions, DACLs, and ACEs
3️⃣ How to defend against SDDL abuse with detections & Atomic Red Team tests

🧡 (3/)

21.02.2025 15:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

In our latest blog, we break down SDDL: πŸ”Ή How it structures Windows security
πŸ”Ή How attackersβ€”from LockBit to RomComβ€”manipulate it for privilege escalation & defense evasion
πŸ”Ή How to detect & defend πŸ›‘οΈ

🧡 (2/)

21.02.2025 15:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image Post image

πŸ” Windows Security and SDDL: What You Need to Know πŸ”

Windows permissions misconfigurations are a goldmine for attackers. SDDL (Security Descriptor Definition Language) remains overlooked yet highly exploitable. 🚨

@nasbench.bsky.social and I break it down -->

🧡 (1/)

21.02.2025 15:55 πŸ‘ 2 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

Tomorrow, join us for a legendary episode of Atomics on a Friday featuring Jonathan Johnson (@jsecurity101) as we dive deep into JonMonβ€”the tool redefining Windows telemetry!

24.01.2025 03:02 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

πŸŽ„ Twas the night before JonMon, and all through the net,
πŸ” Defenders were stirring, their systems to vet.
πŸ› οΈ The telemetry was hung in EventViewer with care,
✨ In hopes that Jonny Johnson soon would be there.

πŸ“… Friday, January 24th
⏰ 11 AM MST | 1 PM EST
πŸ“Ί

YouTube: youtube.com/watch?v=CqEhtg…

24.01.2025 03:02 πŸ‘ 5 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
a girl in a pink sweater is raising her arms in the air while a group of people are standing around her . ALT: a girl in a pink sweater is raising her arms in the air while a group of people are standing around her .
13.12.2024 01:22 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I got you!

13.12.2024 01:18 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Good Tidings - Holiday Sweet Coffee With a delicious blast of candied fruit, Good Tidings warms up crisp mornings and brightens any breakfast! Sweet and syrupy with notes of orange ribbon candy, lilac, Amaretto, and Grand Marnier. Pair ...

Down to the end of my last Christmas blend, what do you recommend this holiday season? I typically get Red Rooster or Atomic.

www.redroostercoffee.com/products/goo...

atomicroastery.com/products/mer...

07.12.2024 14:11 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Happy Monday

02.12.2024 18:04 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
notes/utilities/ApachePHPBuild at master Β· MHaggis/notes Full of public notes and Utilities. Contribute to MHaggis/notes development by creating an account on GitHub.


πŸ”₯ Tools for Testing:

➑️ Apache Builder: https://buff.ly/4fOt8F9
➑️ IIS Builder: https://buff.ly/4fLGySm

Empower your security team to hunt, detect, and patch gaps before attackers exploit them. πŸ›‘οΈ

Test, learn, and refine! #CyberSecurity #ThreatHunting #WebShellDetection

27.11.2024 18:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
notes/utilities/ApachePHPBuild at master Β· MHaggis/notes Full of public notes and Utilities. Contribute to MHaggis/notes development by creating an account on GitHub.

πŸ’» How to Use:

1️⃣ Deploy your favorite tools (Sysmon, EDR, XDR, etc.)
2️⃣ Grab a webshell of choice, upload it, and start testing!
3️⃣Observe logs, alerts, and behaviors to identify gaps in your coverage.

27.11.2024 18:13 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
notes/utilities/ApachePHPBuild at master Β· MHaggis/notes Full of public notes and Utilities. Contribute to MHaggis/notes development by creating an account on GitHub.

πŸ” Detection Opportunities:
Use these servers to validate analytic coverage for:

πŸ—‚οΈ File modifications (webshell uploads)
βš™οΈ Process executions (commands from shells)
🎯 Suspicious behaviors triggered by shells

27.11.2024 18:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image Post image

πŸ’‘ Webshell Testing for Defenders πŸ’‘

Having automated tools to spin up web servers isn’t just convenientβ€”it’s a game-changer for defenders. Here's why:

27.11.2024 18:13 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Cracking Braodo Stealer: Analyzing Python Malware and Its Obfuscated Loader | Splunk The Splunk Threat Research Team break down Braodo Stealer's loader mechanisms, obfuscation strategies, and payload behavior.

🚨 Unlocking the Secrets of Braodo Stealer! 🚨

Dive into our latest blog where the Splunk Threat Research Team dissects the elusive Python malware and its sneaky obfuscated loader! πŸπŸ”βœ¨

πŸ”“ Cracking the code of Braodo Stealer's obfuscation

27.11.2024 14:46 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
notes/utilities/ApachePHPBuild at master Β· MHaggis/notes Full of public notes and Utilities. Contribute to MHaggis/notes development by creating an account on GitHub.

"Things that get built on a Monday... πŸ€”

"'Haag do you have a easy way to build a Apache|NGINX|IIS server to easy simulate webshells?'
Hold my coffee... β˜•

β€’ 5-min Apache+PHP setup πŸš€
β€’ Drop-in webshell support 🎯

See you Tuesday! 😎

25.11.2024 20:00 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Atomics on a Friday Episode 4 IIS sassins In this Atomics on a Friday, Paul and Michael will dive into IIS Components and showcase details on this stealthy technique and how adversaries abuse it.Refe...

βš›οΈ Blast from the past Atomics on a Friday βš›οΈ

Attackers are weaponizing IIS modules for persistence, post-exploitation, and data theft.
Check out the blog + AOAF for more πŸ”₯:
https://buff.ly/40UUWAI
Don’t waitβ€”watch to strengthen your defenses:

22.11.2024 17:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Stargazers Ghost Network - Check Point Research Check Point Research identified a network of GitHub accounts (Stargazers Ghost Network) that distribute malware or malicious links via phishing repositories. The network consists of multiple accounts…

🌟 Living off GitHub: The Stargazers Ghost Network!🌐

πŸ”₯ I somehow missed this, but WOWβ€”what a fascinating deep dive into a DaaS operation! πŸš€ Fully automated, primed for quick Ops, and makes you wonder about the ones we haven’t uncovered yet. πŸ‘€
https://buff.ly/3LCYEIP 🚨

20.11.2024 17:01 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0