Vikas Singh

284 posts

Vikas Singh banner
Vikas Singh

Vikas Singh

@vikas891

I do DF/IR @KrollWire GX-IH. GCIH. GCFA. Lethal Forensicator. DFIR Netwars Champion.

Ahmedabad, India Katılım Ocak 2012
182 Takip Edilen465 Takipçiler
Karan Patel
Karan Patel@iamunited231·
Mast start karege pehle 10 minutes, esa lagega we might snatch a win. Fir essa haggad individual error and game will be gone by first half. Same old, same old. No excitement to turn on the match. @CherrySpeakzz tod mat dena @vikas891 Ka TV. #LIVMUN
English
1
0
0
116
Robert Graham
Robert Graham@robertgraham·
Honest question here. Let's say that you just won a lottery for $1 million, as a lump sum, after taxes. What's the first thing you'd buy?
English
193
3
49
47.8K
Vikas Singh retweetledi
Eric Zimmerman
Eric Zimmerman@EricRZimmerman·
if youve never tried EVTXECmd for event logs, try it. take your favorite logs, generate CSV, load into Timeline Explorer, and group by the Map Description column instant wins. from there, group by logon type, user, and remote host. instant lateral movement on 4624 events ('Successful login' in map description).
English
1
1
51
5K
Vikas Singh
Vikas Singh@vikas891·
@chrissanders88 Reminds me of Edison. When you know the 10,000 ways "something" will not work. Like ShimCache - you know everything it DOES not tell you.
English
0
0
2
291
Chris Sanders 🔎 🧠
Chris Sanders 🔎 🧠@chrissanders88·
Attention to Detail. It's critical for analysts, but how do you know if you excel at it?
English
11
4
36
14.7K
Eric Zimmerman
Eric Zimmerman@EricRZimmerman·
@vikas891 @chad Yep! that just applies the logs to the hive that is in memory. faster, but you dont end up with a clean hive on disk #options
English
1
0
1
429
Vikas Singh
Vikas Singh@vikas891·
Instead of selecting the Hive along with transaction logs, saving them as System_Clean, do this instead.. Select the Hive. Hold Shift while clicking on Open! @chad 👈👀 Tool: Reg Explorer by @EricRZimmerman
Vikas Singh tweet media
English
1
0
2
609
Will
Will@BushidoToken·
Really looking forward to delivering my first workshop 😄 Since being accepted, I’ve made the slide deck, a new template for attendees, and created a Discord Server! I also plan to have a trial run in-person at the Uni with the cybersec students to iron out any issues 👨🏻‍💻📝
Will@BushidoToken

Happy with this! Thanks to the BSides London team for accepting my workshop and I shall see you all in December for some threat actor tracking 🔍 #BSidesLDN2023 @BSidesLondon

English
3
3
50
43.6K
Taz Wake
Taz Wake@tazwake·
At this point, 70% of blue tick accounts are idiots posting idiot takes to get views and reactions. 15% are just evil scum.
Taz Wake tweet media
English
10
3
60
13.6K
sysengineer
sysengineer@_sysengineer·
I will not apologize for the amount of puppy pics I share here
English
22
0
260
59.3K
Vikas Singh
Vikas Singh@vikas891·
@SecurityAura @1ZRR4H Oh hey 😂😭 I meant the IR God in me ain't touching that if you have no MFA. At this point just hand me your money.
English
0
0
1
599
Aura
Aura@SecurityAura·
I'm just gonna go ahead and say it. If you have: Cisco VPN No MFA for it You may get a surprise knock from #Akira #Ransomware soon. So yeah, go look at your AD auth logs for 4624/4625 from a WIN-* machine in your user VPN range. If you have a hit, may the IR Gods help you.
English
14
218
793
142K
Vikas Singh
Vikas Singh@vikas891·
Another interesting JS. The end goal looks like #Remcos RAT but unsure if this family has been analyzed .. yet. Good de-obfuscation practice today! 🎯Clever masking of all stages 🎯Everything being done in-memory
Vikas Singh tweet mediaVikas Singh tweet mediaVikas Singh tweet media
English
1
0
2
208
vx-underground
vx-underground@vxunderground·
NoBit ransomware group states they encrypt data in SHA 😭😭😭
vx-underground tweet media
English
53
106
1.6K
340.4K