
Ryan Benson
1K posts

Ryan Benson
@_RyanBenson
I do digital forensics and work on open source DFIR tools @Google. I kinda like web browsers, too. Not on Twitter often anymore, reach me at ryan 'at' https://t.co/Zcq6BJG4xC
SF Bay Area Katılım Nisan 2009
265 Takip Edilen4.4K Takipçiler
Sabitlenmiş Tweet

Here's the blog post on my new tool:
dfir.blog/introducing-un…
Unfurl takes a URL🔗 and expands ("unfurls") it to show all the data it contains. It's amazing how much can be hidden inside URLs!
Take it for a spin and tell me what interesting stuff you find🔗🌿#DFIR #Python
GIF
English
Ryan Benson retweetledi

@GergelyOrosz FYI that link in the screenshot is acquired by the user tapping "Copy Link" button from the Twitter app on iPhone. That's what the parameter "s=46" means. It's safe to also drop that from the final URL.
Here's where I got the s-parameter table to look up:
dfir.blog/unfurl-parsing…
English

@_RyanBenson here is a large list of Mastodon instances coxy.co/mastodon/
English

With all the uncertainty @Twitter, I've seen more people talking about alternatives like #Mastodon.
Like tweets, Mastodon IDs have embedded timestamps in them, and Unfurl can parse them:
🔗@Gargron/109256990373721673" target="_blank" rel="nofollow noopener">dfir.blog/unfurl/?url=ht…
#DFIR #OSINT

English

@phillmoore @inversecos It doesn't. These files are in the SNSS format, which involves some serialization. AFAIK, there aren't any working open source parsers (github.com/cclgroupltd/cc… & github.com/JRBANCEL/Chrom… worked at least partially in the past) and I haven't taken a pass at parsing it myself yet.
English

@inversecos @_RyanBenson does hindsight have coverage for this file?
English

1\ #DFIR: Chrome Forensics - How to Recover CLEARED History
If a user just cleared their browser history, you can still recover everything they were just looking at from the session files:
%appdata%\Local\Google\Chrome\User Data\Default\Sessions
inversecos.com/2022/10/recove…

English
Ryan Benson retweetledi

We are reviewing our @MISPProject warning lists and we are looking for a maintained list of hosts which are domain parking. Do you know someone doing such thing? or should we start to build one from scratch? #threatintelligence
English
Ryan Benson retweetledi

@WebBreacher Double-click any node and it copies the text to clipboard. I need to make that feature more visible, sorry.
English

@_RyanBenson for unfurl...when it decodes one of the long URLs I have into all the parts, I cannot select a decoded part and copy it to clipboard. I have to use CyberChef or something to recreate what unfurl does.
Any way we can get a copy/paste of the nodes as text?
English

@_RyanBenson I used your TikTok research to figure out the Linkedin post timestamp from URL in case you want to add to Unfurl github.com/Ollie-Boyd/Lin…
English

Nice little tidbit here about decoding #LinkedIn profile ids from URLs, then using their sequential nature to estimate profile creation time.
I see an @unfurl_link update in the future! #DFIR #OSINT
Jack Crook@jackcr
All of the profiles listed in the article and this thread were created within days of each other. jennie-biller-9b631120a victor-sites-40139b20a charolette-pare-93b3a220a vivian-christy-b1246320a maryann-robles-2924b620a 1/4
English

Apparently TikTok uses the same ID scheme for job postings as it does for videos? Random, but kind of interesting.🤷♂️
Example: dfir.blog/unfurl/?url=ht…
More info on TikTok timestamps: dfir.blog/tinkering-with…
#DFIR #TikTok #OSINT

English

@WebBreacher Ha, thanks 😉. I updated the logo at least for dark mode, other components will take more time.

English

@_RyanBenson LOL. It is a terrific tool! I appreciate all the work you put into it. And yes, the logo could look nicer in DM....but that was not my intent of this post!
English
Ryan Benson retweetledi

@WebBreacher Thanks! Glad you like it. And after seeing your screenshot, I'll make the logo look better in dark mode ;)
English

@WHInspector If you're interested in browser forensics, check out hindsig.ht
English

Ok I am doing my first steps on browser #DFIR.
I know one thing for sure: If someone steals your laptop/PC and he knows what he is doing, you are screwed. 😨😱
English

Hey, thanks! Your #DailyOSINT looks really interesting too!
White Hat Inspector@WHInspector
Of course I didn't know that when I started but, this guy @_RyanBenson has been doing a #DailyDFIR before I have even thought about it! If u re interested in #DFIR, definitely check out his hashtag! (7/8)
English
Ryan Benson retweetledi



