Andrew Rathbun

1.3K posts

Andrew Rathbun banner
Andrew Rathbun

Andrew Rathbun

@bunsofwrath12

Husband, Father, #DFIR @ Unit 42, Digital Forensics Discord Admin, AboutDFIR Contributor, Author, #USMC Veteran, Former LE, NHL Fan, Dark Mode, Animals, Music

Michigan, United States Inscrit le Eylül 2013
722 Abonnements2.9K Abonnés
Andrew Rathbun retweeté
Detroit Red Wings
Detroit Red Wings@DetroitRedWings·
GOLDEN 🥇🇺🇸
Detroit Red Wings tweet media
English
127
1.4K
9.2K
205.4K
Andrew Rathbun retweeté
13Cubed
13Cubed@13CubedDFIR·
We just issued our 500th 13Cubed certification! 🎉 Learn more at 13cubed.com/certs. All Windows, Linux, and macOS courses include certification attempts at no extra cost, allowing you to demonstrate real-world practical application of forensic investigative techniques. 🏅
13Cubed tweet media
English
0
1
15
2K
Andrew Rathbun retweeté
13Cubed
13Cubed@13CubedDFIR·
Windows forensics is essential—but don’t overlook Linux or macOS. These platforms are steadily gaining ground in enterprise environments. Make sure you have the skills you need to investigate them too! youtube.com/watch?v=_D6oHm…
YouTube video
YouTube
English
0
12
64
6.2K
Andrew Rathbun retweeté
Nextron Research ⚡️
Nextron Research ⚡️@nextronresearch·
We analyzed the top 500 most successful THOR rules – “successful” meaning: they detected samples that were either ignored or missed by nearly all AV engines on VirusTotal. Some rules detect clear malware. Others reveal dual-use tools, renamed hacktools, misused admin binaries, or forensic leftovers. Most of these samples showed 0 AV detections, the rest only minimal hits. Not all threats are payloads. Not all detections are flashy. But these rules consistently light up the blind spots in AV and EDR coverage – where attackers hide comfortably. THOR doesn’t replace existing tools. It shows you what they forgot to tell you. nextron-systems.com/2025/06/18/the…
Nextron Research ⚡️ tweet mediaNextron Research ⚡️ tweet media
English
2
43
124
46K
Andrew Rathbun retweeté
13Cubed
13Cubed@13CubedDFIR·
🎉 Big news! Investigating macOS Endpoints is now live—plus our new *NIX Bundle and XPlat Bundle Complete (all 13Cubed courses in one package). Thanks for patiently waiting! Dive in now 👉 training.13cubed.com #DFIR #macOS #Linux
English
1
7
66
5.2K
Andrew Rathbun retweeté
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
I recommend this if you’re tired of doomscrolling X or chasing updates across a dozen security slacks If you’re into good old RSS feeds or just want a weekly blog-style summary of what happened in DFIR, check out "This Week in 4n6" by @phillmoore & @hexplates a human-curated, no-BS roundup: thisweekin4n6.com
Florian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet media
English
5
64
260
22.7K
Andrew Rathbun retweeté
13Cubed
13Cubed@13CubedDFIR·
🎉 Happy Friday! Two quick updates: Investigating macOS Endpoints and related bundles are now open for waitlisting! 👉 13cubed.com 13Cubed Merch Store is LIVE with fresh designs and premium shirts! 👉 shop.13cubed.com
English
0
4
26
1.6K
Andrew Rathbun
Andrew Rathbun@bunsofwrath12·
@nas_bench Very much appreciate your work on this to provide a better frontend for the data. I use the repo all the time
English
0
0
3
114
Nasreddine Bencherchali
Nasreddine Bencherchali@nas_bench·
@bunsofwrath12 Thanks! Its sad we don't have but I'm planning to make use of the data we have even more and let people filter down and have some amazing stats.
English
1
0
5
436
Andrew Rathbun retweeté
Nasreddine Bencherchali
Nasreddine Bencherchali@nas_bench·
Introducing 🚀Eventlog Compendium 🚀 A new Streamlit app, that aims to be the go-to resource for understanding and playing with Windows Event Logs. Explore it 👉 eventlog-compendium.streamlit.app Includes the following utilities and docs ⚙️ Build your own Advanced Audit Policy based on different data points making your policy data driven. 🧭EventID to Audit Policy mapping as well MITRE ATT&CK to Event ID explorer 📊Leveraging the EVTX-ETW-Resources project, you can explore the different ETW providers by build, version and filter down on key message strings. 📄 EVTX Baseline Search & Match - Explore the evtx-baseline project in a visual way. Where you can paste logs and check if they match in real time 🧮Event Field Decoder - Decode common Windows Security Event fields such as Logon Types, Access Masks, Active Directory GUIDs and SIDs 🔒Built-in SACL Explorer - leveraging SACL Scanner from Alexander DeMine, you can explore the built-in SACLs on a windows system. And much more to come. Stay tuned
Nasreddine Bencherchali tweet media
English
5
105
310
25.5K
Andrew Rathbun retweeté
13Cubed
13Cubed@13CubedDFIR·
It's time for a new 13Cubed episode covering a very obscure evidence of execution artifact. youtube.com/watch?v=edJa_S… Enjoy! #DFIR
YouTube video
YouTube
English
0
14
52
5.2K
Andrew Rathbun retweeté
Kevin 🤖🕵️🍺
Kevin 🤖🕵️🍺@KevinPagano3·
Good news, The Hitchhiker's Guide to DFIR book v1.5 has been released, thanks to Eli Woodward for contributing Chapter 15, "2023 from a Cyber Threat Intelligence Perspective". Grab a copy of the book at the link below, it's free! #DFIR leanpub.com/TheHitchhikers…
English
3
62
198
13.6K
Andrew Rathbun
Andrew Rathbun@bunsofwrath12·
@KevinPagano3 Also, something like EditPad Pro or similar to slice and dice it to something more manageable.
English
0
0
0
72
Kevin 🤖🕵️🍺
Kevin 🤖🕵️🍺@KevinPagano3·
Suggestions on software to open 10+GB CSV files?
English
15
0
2
1.1K
Andrew Rathbun retweeté
Eric Zimmerman
Eric Zimmerman@EricRZimmerman·
Do you like EZTools? Do you like up to date runtimes? Well I have news for you... All EZ Tools are now available as net9 executables! Get-ZimmermanTools has been updated to support this, but net6 is still the default to give people time to transition. Within a few months, net9 will be the default and the net6 versions will be no more. I also added documentation on how to build self-contained executables, so you do not even need the runtime installed at all. ericzimmermanstools.com Enjoy!
English
10
54
222
12.6K
Eric Zimmerman
Eric Zimmerman@EricRZimmerman·
Damn you penguins. How many two goal leads you gonna blow?
English
1
0
1
955