Scott Lynch

20.4K posts

Scott Lynch banner
Scott Lynch

Scott Lynch

@packetengineer

Certified @SANSDefense Instructor | SECOPS/CERT Manager | Defcon BTV | Navy Vet | Sailor | Tweets Are My Own

Beigetreten Temmuz 2011
4.9K Folgt2.5K Follower
Scott Lynch retweetet
Security Onion
Security Onion@securityonion·
Security Onion 3 is coming soon! Are you ready?
Security Onion tweet mediaSecurity Onion tweet mediaSecurity Onion tweet mediaSecurity Onion tweet media
English
7
26
212
17.6K
Scott Lynch retweetet
gabsmashh
gabsmashh@gabsmashh·
a SIEM is not a dumping ground for every log your company generates. if your strategy is “ingest everything so we don’t miss anything,” you have built a data lake instead and your analysts are going to drown in it (pun intended).
English
77
131
1.2K
57.1K
Scott Lynch retweetet
Chris Sanders 🔎 🧠
Chris Sanders 🔎 🧠@chrissanders88·
Investigation Scenario 🔎 Your SIEM flags an OAuth consent grant to “Adobe Secure Share” from a user's M365 account at 07:13 AM. The audit log shows consent to files.readwrite.all. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC
English
4
10
86
11.1K
Scott Lynch retweetet
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
It's cooking ... - complete rewrite of Loki in Rust - uses yara-x instead of yara - uses YARA-Forge as signature set - improved UX
Florian Roth ⚡️ tweet media
English
9
48
336
48.9K
Scott Lynch retweetet
Kostas
Kostas@Kostastsale·
𝗝𝘂𝘀𝘁 𝗹𝗮𝘂𝗻𝗰𝗵𝗲𝗱 𝗮𝘄𝗲𝘀𝗼𝗺𝗲-𝗱𝗳𝗶𝗿-𝘀𝗸𝗶𝗹𝗹𝘀 𝘄𝗶𝘁𝗵 @fr0gger_ ! Designed to save time during investigations and everyday DFIR tasks Thomas has built an excellent malware triage skill, and I’ve added a couple of timeline analysis skills to help you get started. Feel free to contribute and use these skills to save a ton of time, like we already do. github.com/tsale/awesome-… Learn about skills: - developers.openai.com/codex/skills/ - support.claude.com/en/articles/12…
English
8
81
360
28.3K
Scott Lynch retweetet
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
Really excited about this one ⚡️ This post dives deep into Aurora - Nextron’s free ETW-based detection agent - and shows how it can help detection engineers, IR teams, and monitoring specialists explore and understand what’s actually observable via ETW 🔎🌊 - Free (Aurora Lite) - Local #ETW visibility - no audit policy or EDR needed - Perfect for detecting noisy things like browser credential store access - Adds rich context fields (e.g., ProcessTree, GrandparentImage, PE metadata) - Great for writing & validating #Sigma rules with real telemetry If you care about writing good detections, this is the tool - and the writeup - to check out
Nextron Research ⚡️@nextronresearch

We’ve published a deep dive into how Aurora uses ETW to reconstruct structured event data for detection engineering The post covers: - ETW-based logsource mappings - Custom field enrichment (e.g., ProcessTree, GrandparentCommandLine) - Gaps in ETW coverage and where minimal Sysmon configs help - Practical detection use cases with full Sigma rules - Techniques for exploring ETW with --trace and writing custom rules 🔗 nextron-systems.com/2025/07/31/aur… by @_swachchhanda_ #Sigma #AuroraAgent #ETW #DetectionEngineering

English
2
17
87
13.2K
Scott Lynch retweetet
Scott Lynch retweetet
spencer
spencer@techspence·
Shadow IT/Shadow SaaS is a bigger threat than _most_ of the critical and high vulnerabilities the average vuln report spits out…
English
22
17
254
14.8K
Scott Lynch retweetet
SANS Institute
SANS Institute@SANSInstitute·
Starting in 30 minutes! - The world's top cyber minds gather at the SANS #EmergingThreatsSummit 2025 to reveal: - How quantum computing will break today's encryption - How AI is weaponizing cyberattacks - How to defend critical infrastructure in a hyperconnected world and more! @robtlee @chrishvm 🔗 Register Now sans.org/u/1zh8
SANS Institute tweet media
English
0
12
9
2.3K
Scott Lynch retweetet
Mark Simos
Mark Simos@MarkSimos·
A tale of two (large) purchases and cybersecurity Let’s take the case of purchasing a new expensive software-controlled piece of equipment that supports business operations like MRI Machines, heavy manufacturing equipment, ATM Machines, etc. a short 🧵
Mark Simos tweet media
English
2
6
40
3K