DFIR Notes

12.7K posts

DFIR Notes banner
DFIR Notes

DFIR Notes

@DfirNotes

design, build, teach threat-informed information security programs and techniques. Also: retweets of interesting classes, tools, research. They/them

Earth (Sol-3) 参加日 Ekim 2015
232 フォロー中963 フォロワー
固定されたツイート
DFIR Notes
DFIR Notes@DfirNotes·
@dfirnotes is (we're) mostly: Information Security Leader & Educator | Twitter, Github: @dfirnotes BBSTi, CISSP, GIAC**0x0c, GSE**2, ITIL, LPI, MAD CTI Blog at dfirnotes.net DMs open for #CyberMentoringMonday or other questions. Be excellent to each other!
English
1
2
7
0
DFIR Notes がリツイート
Tim Misiak
Tim Misiak@timmisiak·
(1/n) WinDbg finally released outside the store, and no more "Preview"! Ecstatic to see my old team hit this milestone! It's come so far since @aluhrs13 and I started the "WinDbgNext" project so many years ago. learn.microsoft.com/en-us/windows-…
English
5
92
330
71.4K
DFIR Notes がリツイート
Katie Nickels
Katie Nickels@likethecoins·
For $20 a month, you get access to a bunch of knowledge from smart people like @ForensicITGuy on topics from malware analysis to network forensics to EXCEL ❤️, and much more. This isn't sponsored, I just think it's awesome they're making such useful content so accessible!
Applied Network Defense@NetworkDefense

We're excited to launch our new Analyst Skills Vault, a subscription-based service that provides access to our growing collection of standalone video lessons.

English
1
4
26
5.7K
DFIR Notes がリツイート
tlansec
tlansec@tlansec·
Domain fronting is hands-down the weirdest thing. I think a lot of blue team (including myself) would have heard the term over the years without looking into it. 1/4
Johann Aydinbas@jaydinbas

If I'm reading this config right, it's a #CobaltStrike using the @nytimes content API as a C2: gist.github.com/usualsuspect/7… dropped by fake @GoIvanti VPN updater ISO: virustotal.com/gui/file/568e3… ISO -> .NET stuff -> custom loader -> reflective loader beacon

English
1
4
40
11.3K
DFIR Notes がリツイート
Jonny Johnson
Jonny Johnson@JonnyJohnson_·
@Cyb3rMonk I think it depends on what you want the EDR. Personally, I have never looked at an EDR as a source for detection but a source of telemetry. I see vendors say they detect "x", but I have always used that as one of my detections for a given operation versus the sole detection.
English
1
2
13
2.2K
DFIR Notes がリツイート
.
.@T3chnical1·
Anyone who wants a mentor, to give back to the community, or to just share resources should definitely check out #CyberMentoringMonday loads of amazing people and info in the tag!!
English
0
5
24
6.7K
DFIR Notes がリツイート
Applied Network Defense
Applied Network Defense@NetworkDefense·
"The labs were fun and interesting. The feedback is fast and insightful...I'm not used to that much interaction with an instructor in an asynchronous course!" - Rob
English
1
2
0
443
DFIR Notes がリツイート
Applied Network Defense
Applied Network Defense@NetworkDefense·
"If you pay attention and give Investigation Theory its due, you will come out the other side a much better analyst for having taken it."
English
1
3
3
614
DFIR Notes がリツイート
Mick Douglas 🇺🇦🌻
Mick Douglas 🇺🇦🌻@bettersafetynet·
@netresec @GuhnooPlusLinux That said, the way meterpreter does TLS is strange, so you can do detection on how it behaves. However, again... this is defaults, you can change the TLS behavior in your payload options and advanced options.
English
0
1
2
189
DFIR Notes がリツイート
Victor Petrov
Victor Petrov@VictorPPetrov·
well, Balkan Cyberia finally has a cover and it is marching robotically towards its publication on the 13th June with @mitpress! It has spies & cyborgs, not just apparatchiks - and will be open access but if you want a copy, there will be a discount code! mitpress.mit.edu/9780262545129/…
Victor Petrov tweet media
English
23
65
391
55.8K
DFIR Notes がリツイート
TCM Security
TCM Security@TCMSecurity·
We often get asked how to land a job in cybersecurity. In today's video, Heath discusses the importance of community and giving back as one of the important steps to getting a job in cybersecurity. youtu.be/pJimy574Sh8
YouTube video
YouTube
TCM Security tweet media
English
3
13
120
16.7K
DFIR Notes がリツイート
Jamie Levy🦉
Jamie Levy🦉@gleeda·
I'll be giving a talk next week over my journey into #DFIR and give some tips to help others find their way into this space! #memoryforensics #malware #infosec #infosecurity
Women in CyberSecurity (WiCyS)@WiCySorg

The journey into Cybersecurity is not one-size-fits-all but can vary from person to person. In this webinar with @HuntressLabs, Jamie Levy will cover how she found her way into this field and give tips for choosing the right path for you. brighttalk.com/webcast/17216/… #WiCyS

English
1
10
28
13.3K
DFIR Notes がリツイート
P!bbl3
P!bbl3@TechEmiiily·
Assert dominance in your ticket queue by submitting all technical details necessary with screenshot of Hello Kitty terminal.
P!bbl3 tweet media
English
11
29
228
17.8K