Log inSign up
Allan “Ransomware Sommelier🍷” Liska
24K posts
user avatar
Allan “Ransomware Sommelier🍷” Liska
@uuallan
Back The Press Guardian & The Clock:1942 kickstarter.com/projects/green…
Virginia, USA
kickstarter.com/profile/greena…
Joined April 2011
5,887
Following
16.8K
Followers
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Aug 16, 2021
    How it started. How it went. How it ended.
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    May 27, 2022
    🧵 I've been working on a presentation that looks at signs that you are probably in the early stages of a ransomware attack. The idea is to look at logs/threat hunting indicators that are almost always a sign of ransomware reconnaissance. Here is the list I have, I'd love to see
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Sep 12, 2021
    I sincerely appreciate all of the great suggestions. Here is the updated chart based on everyone's input. I had to reformat it make it readable. I originally had company logos where the ransomware icon is but I figure companies won't want their logo on a ransomware chart 🤣.
    user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Sep 12, 2021
    I could use your (yes you) help. I am trying to compile a list of vulnerabilities ransomware groups (or their access brokers) use to gain initial access. Excepting Kaseya, are there any others I am missing from this list? Remember, this is initial access only.
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Sep 26, 2021
    I am trying to map out the anatomy of a ransomware attack. Are there any glaring steps or tools I am missing from this diagram (I know I didn't get all the tools ransomware groups use, but did I miss any big ones)?
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Oct 20, 2021
    Big News 🚨! My ransomware book is out, but the book is just one part of a bigger project, ransomware.org. A comprehensive site designed to help orgs defend against ransomware...and they are making all the content from the book available at no cost. Please visit!
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Aug 18, 2023
    Weird question, but does anyone know where I got these cards? I thought it was @dustrial, but I don’t see them on their site. I just sent my last one and want to order more.
    Greeting card with the phrase: “Sorry to hear you’ve had a ‘Security Guard incident’”
    53K
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Feb 22, 2022
    Meme for my talk today...
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Jan 31, 2022
    20+ years ago, when I entered Infosec the books I read were about firewall configuration and deep dives into protocols. Now, I am reading @VossNegotiation’s book, “Never Split the Difference,” to understand better ways to deal with ransomware groups.
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Sep 17, 2021
    So, we are up to 42 vulnerabilities across 17 technologies (with 1 pending) that ransomware groups exploit for initial access. This is why preaching “just patch” isn’t good enough. I don’t know what the answer is, but what we’re doing clearly isn’t working.
    user avatar
    pancak3
    @pancak3lullz
    Sep 17, 2021
    Replying to @uuallan and @serghei
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Jun 13, 2023
    Well, this is awkward timing.
    Barracuda wins in the 2023 Cloud Security Awards
Barracuda Logo. (PRNewsFoto/Barracuda Networks, Inc.)
NEWS PROVIDED BY
Barracuda Networks, Inc. 
13 Jun, 2023, 09:02 ET
Awards recognize Barracuda CloudGen Firewall and Barracuda Email Protection as outstanding cloud security solutions
    55K
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Jun 30, 2023
    It is always amazing to me the things it never occurred to anyone to start tracking. It am glad this is being done now.
    FBI creates a national database to track swatting
    From abcnews.com
    42K
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Sep 12, 2021
    I could use your (yes you) help. I am trying to compile a list of vulnerabilities ransomware groups (or their access brokers) use to gain initial access. Excepting Kaseya, are there any others I am missing from this list? Remember, this is initial access only.
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Jun 3, 2021
    I want to expand on the targeting point I made yesterday, but in non-meme format. This is a breakdown of known ransomware victims by industry in 2020 and 2021 that @ddd1ms and I have been working on. Notice, that with the exception of healthcare and possibly local government 1/4
  • user avatar
    Allan “Ransomware Sommelier🍷” Liska
    @uuallan
    Jul 24, 2023
    All the people going to Blackhat/Defcon who talk about burner phones and burner laptops obviously don't know how to conference. I just bring my own portable Faraday Cage on wheels. Makes it easier to get around AND no one can hack me. Just kidding, I just don't go 🤣
    28K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms of Service|Privacy Policy|Cookie Policy|Accessibility|Ads info|© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up