Arioch

818 posts

Arioch banner
Arioch

Arioch

@ZeArioch

CERT peep. #DFIR

Katılım Haziran 2011
330 Takip Edilen468 Takipçiler
Arioch retweetledi
Airbus CERT
Airbus CERT@AirbusCERT·
Have you ever tried setting up a shared and reproductible forensics lab? After hitting several brick walls with Docker, Ansible and others, we ended up finding a solution that ticked all the boxes we wanted: Nix. See for yourselves! skyblue.team/posts/nix-fore… #DFIR #NixOS
English
0
2
11
841
Arioch retweetledi
Nicolas Bareil
Nicolas Bareil@nbareil·
He is awesome: My fellow @eeriedusk from the Airbus CERT added file hashes to process execution event logs to Sysmon for Linux, congrats man! github.com/Sysinternals/S… Let's try to have features parity with the Windows version now.
English
0
13
19
2K
Arioch retweetledi
Jonny Johnson
Jonny Johnson@JonnyJohnson_·
I've always thought that in order for Defenders to be truly effective, it is vital they know where the telemetry they are leveraging is coming from. Today I am releasing a project called TelemetrySource that is meant to support that cause. Blog: posts.specterops.io/uncovering-win…
English
7
173
341
0
Arioch retweetledi
Airbus Security Lab
Airbus Security Lab@AirbusSecLab·
Anaïs Gantet, Nicolas Devillers (@Nikaiw) and Mouad Abouhali (@_m00dy_ ) are going to present “The unavoidable pain of backups: security deep-dive into the internals of NetBackup” at #HEXACON2022. A thought to Jean-Romain Garnier (@JRomainG) that was not able to participate.
Airbus Security Lab tweet media
English
1
10
49
0
Arioch retweetledi
Sylvain Peyrefitte
Sylvain Peyrefitte@citronneur·
The results are out! We are very honoured to have won first place🥇in the Hex-Rays plugin contest 2022 🎉 Our entry was "ttddbg", a time-travel debugging plugin for IDA already presented at #SSTIC 2022. Many congratulations to all the other entrants!
Hex-Rays SA@HexRaysSA

🥁 We have the winners of the Hex-Rays Plugin Contest 2022! Our congratulations go to: 🥇 ttddbg by @simsor and @citronneur 🥈 ida_kcpp by Uriel Malin and Ievgen Solodovnykov 🥉 FindFunc by Felix B. Take a look at the full list: hex-rays.com/contests_detai… #PluginContest #IDA

English
6
21
62
0
Arioch retweetledi
Katie Mack
Katie Mack@AstroKatie·
Still don't know how to respond when people try to portray it as "irrational" to state a strong preference to avoid getting sick with an extraordinarily contagious, sometimes deadly, sometimes disabling virus, whether or not it's likely to be "mild" in one individual case.
English
89
763
4.8K
0
Arioch retweetledi
Sylvain Peyrefitte
Sylvain Peyrefitte@citronneur·
Merry Christmas Blue Teamers! 🎄🎅🎁🔔 Invoke-Bof allows you to load and execute any #CobaltStrike Beacon Object File (BOF) to test your detection capabilities! #DFIR github.com/airbus-cert/In… Airbus CERT is looking for new team member, if you're interested get in touch!
English
1
82
196
0