Nicolas Bareil

283 posts

Nicolas Bareil

Nicolas Bareil

@nbareil

Incident responder

France Katılım Nisan 2010
806 Takip Edilen940 Takipçiler
Nicolas Bareil retweetledi
Sergey Nazarov
Sergey Nazarov@sergeynazarovx·
We used to go to a special website, ask strangers for help with programming, and get humiliated in return
Sergey Nazarov tweet media
English
303
3.5K
39.4K
843.4K
Nicolas Bareil
Nicolas Bareil@nbareil·
Reviewing old reports... Who remembers when TZWorks’ forensic tools were the gold standard? 🫠
English
0
0
3
147
Nicolas Bareil
Nicolas Bareil@nbareil·
@kepano Is there a way in Obsidian to have the "Unlinked mentions" suggestion feature limited to one link per document? For example, if I have 40 times a word that could be turned into a link, having just one single link is enough. Thanks!
English
0
0
0
65
Nicolas Bareil
Nicolas Bareil@nbareil·
@marclou Are you sure the "Transferring licence to another device" process described in the FAQ works? I don't manage to make it work 😭
English
0
0
0
30
Marc Lou
Marc Lou@marclou·
I made an app to fix my terrible posture. It uses my MacBook Pro camera to watch me work. When AI detects that I’m sitting like a shrimp 🦐, it sends me a notification with a preview of my posture so I can reposition myself. Everything stays local. It works offline too. > supershrimp.io And because apparently my brain only responds to fake rewards, I added XP: good posture makes my shrimp evolve (currently level 7).
English
419
43
2.1K
642.6K
Nicolas Bareil retweetledi
Renzon
Renzon@r3nzsec·
DFIR analysts who use macOS as their daily driver deserve free and native forensic tooling. So I built one. 🍎 Introducing 𝗜𝗥𝗙𝗹𝗼𝘄 𝗧𝗶𝗺𝗲𝗹𝗶𝗻𝗲 — a timeline analysis app built from the ground up for Mac-based DFIR folks, forensic investigators, or SOC analysts. Built in appreciation of, and inspired by, Eric Zimmerman’s Timeline Explorer. Every feature in this tool was shaped by real IR casework. Handling massive timelines, parsing artifacts here and there, and pivoting across logs during active investigations. I built IRFlow Timeline to be the native macOS timeline analyzer that actually keeps up with a live case. Every button and view is intentional; if it’s in the app, it’s because I needed it mid-case and realized the standard tools fell short. No dependencies. Zero setup. Just drag, drop, and analyze. #dfir #incidentresponse #timeline #macos #threathunitng #digitalforensics
English
20
118
503
38.9K
Nicolas Bareil retweetledi
Stephan Berger
Stephan Berger@malmoeb·
My teammate Matt not only wrote a new blog post, but also created two new Velociraptor artifacts - now available on the Velociraptor Artifact Exchange! 🥳🥇 Check out his blog and explore the new detection capabilities 🤓
Matthew Green 🌻@mgreen27

I wrote a new blog: Hunting reflected .NET assemblies at scale with Velociraptor, detecting CLR patching, and dumping in-memory payloads for triage. #DFIR #Velociraptor labs.infoguard.ch/posts/clraptor…

English
0
2
25
3.9K
Nicolas Bareil
Nicolas Bareil@nbareil·
Actually, there’s a kernel+shell convention: exit code >128 means the process died from a signal. Subtract 128 to find which one. Here it’s 130 → SIGINT (2), sent by Ctrl+C — matching the suspicion of hands-on-keyboard activity 🤘
English
0
0
1
82
Nicolas Bareil
Nicolas Bareil@nbareil·
Interesting nerd snipe today: On Linux, an EDR-like logged an exit-code of 130 for a process establishing C2, leading the customer to believe the execution was unsuccessful and safe.
Nicolas Bareil tweet media
English
1
0
1
122
Fabien Penso
Fabien Penso@fabienpenso·
@nbareil @home_assistant @sonoff_global ah yeah, home automation basics: start small, add automation slowly. First lights + motion sensors, then door/window sensors + alarmo with automatic turnon when you’re not here. Then water heater automation, etc.
English
1
0
0
42
Nicolas Bareil
Nicolas Bareil@nbareil·
@fabienpenso @home_assistant @sonoff_global It would be fantastic to hear your tips and tricks for a connected home. The little things that bring you joy when you use them. My home assistant dashboard is quite limited at the moment, probably because I’m not sure what to do with it.
English
1
0
0
39
Nicolas Bareil
Nicolas Bareil@nbareil·
Thanks @foxit for github.com/fox-it/dissect. This project is totally underrated. I tried it once before, but it didn’t click until a few weeks ago. It’s a masterpiece that radically changed my IR workflows, enabling me to implement forensics playbooks I dreamed for years 💙💙💙
English
0
2
13
288
Nicolas Bareil
Nicolas Bareil@nbareil·
It's my one-year anniversary at Unit 42, and I'm excited to share a major piece of research I co-authored with the team. It's a deep dive on a telecom-focused threat actor (known as LightBasin), based on incident response engagements I've been a core part of this past year.
English
1
1
12
1.4K