Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Dhruv AHUJA

@new23d@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Making network egress filtering effective, reliable and usable.

Founder & Chief Engineer at @ChaserSystems@infosec.exchange

0 Followers
0 Following
5 Posts
Joined November 02, 2022
blog:
https://www.new23d.com/
Open post
Dhruv AHUJA @new23d@infosec.exchange
· 2mo ago
65% of breaches could've been prevented according to this research by Niels Provos if only Hardware second factors, Egress control and Positive execution control would've been in place. I couldn't agree more when he says, "most companies don’t realize they need this protection" on #egress filtering. Number of times I've had to explain outbound connections originating from within a network to DevOps, SecOps alike 🤯 https://securityblueprints.io/posts/three-security-invariants-ciso-challenge/
0
0
0
0
Open post
Dhruv AHUJA @new23d@infosec.exchange
· 2mo ago
Update profile on APT28/Unit 26165/Fancy Bear by on Gov·UK [1]. "Unit 26165 accessed private IP cameras near military facilities, ports, train stations and border crossings in Ukraine, Moldova and 11 NATO countries to track the movement of foreign assistance" They seem to have this X-Agent & X-Tunnel pair of malware to pull this off of "private IP" cameras. From ESET's 2016 analysis [2] of it, we can see that the X-Tunnel infected computer will initiate an outbound connection (direction #egress) to first the C2 server then to the victim in the private IP network. While ingress firewalls can reduce noise and offer some degree of control, it's #egress filtering that offers stronger security. [1] https://www.gov.uk/government/publications/profile-gru-cyber-and-hybrid-threat-operations/profile-gru-cyber-and-hybrid-threat-operations [2] https://web-assets.esetstatic.com/wls/2016/10/eset-sednit-part-2.pdf
0
0
0
0
Open post
Dhruv AHUJA @new23d@infosec.exchange
· 1mo ago
RE: https://infosec.exchange/@ChaserSystems/117003455836858257 This isn't a reason to be complacent. We're working on an Agentic Defence Assurance and Product Integrity Testing (ADAPT) harness to continually challenge our assumptions and discover new evasions. More to be released in a few weeks on that. Outbound Traffic Inspection (OTF) / Egress Filtering is an extremely effective post-compromise defence with asymmetric ROI. We also demo in-process resolver monkey-patching, btw. Because that doesn't need write access to files /etc or root.
Open quoted post
Quoting
Chaser Systems
@ChaserSystems@infosec.exchange
Happy to reassure our users that the #egress evasion TTPs used by the Agent in the OpenAI and Hugging Face incident have long been mitigated in #DiscrimiNAT OTF (outbound traffic filtering). In fact, in our demos, we show these attacks being caught. #2 is SNI spoofing, btw. https://huggingface.co/blog/agent-intrusion-technical-timeline
Open quoted post
0
0
0
0
Open post
Dhruv AHUJA @new23d@infosec.exchange
· 1mo ago
Does anybody know an illustrator/graphics designer who can tweak and convert AI-generated two sticker ideas I have to print-ready? Theme is computer circuits, LCD screens and a bit retro Windows 95 dialog boxes. Need this done asap, really. Preferably Cambridge/London based.
0
1
0
0
Open post
Dhruv AHUJA @new23d@infosec.exchange
· 1mo ago
I managed to get on a podcast: https://www.youtube.com/watch?v=PukjmfzBPq0
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:32:43 UTC