Tsof

164 posts

Tsof banner
Tsof

Tsof

@tsof_relox

5ß9f43l9x Threat Researcher | Threat Hunter | APT, Malware Addicts | DFIR #ThreatHunter #ThreatHunting

Присоединился Eylül 2016
404 Подписки68 Подписчики
Tsof
Tsof@tsof_relox·
@G60930953 how do you know?
English
0
0
1
87
Tsof ретвитнул
Renzon
Renzon@r3nzsec·
DFIR analysts who use macOS as their daily driver deserve free and native forensic tooling. So I built one. 🍎 Introducing 𝗜𝗥𝗙𝗹𝗼𝘄 𝗧𝗶𝗺𝗲𝗹𝗶𝗻𝗲 — a timeline analysis app built from the ground up for Mac-based DFIR folks, forensic investigators, or SOC analysts. Built in appreciation of, and inspired by, Eric Zimmerman’s Timeline Explorer. Every feature in this tool was shaped by real IR casework. Handling massive timelines, parsing artifacts here and there, and pivoting across logs during active investigations. I built IRFlow Timeline to be the native macOS timeline analyzer that actually keeps up with a live case. Every button and view is intentional; if it’s in the app, it’s because I needed it mid-case and realized the standard tools fell short. No dependencies. Zero setup. Just drag, drop, and analyze. #dfir #incidentresponse #timeline #macos #threathunitng #digitalforensics
English
20
117
500
36.4K
Tsof ретвитнул
The DFIR Report
The DFIR Report@TheDFIRReport·
"The unusual command copied to the user's clipboard abused the SSH ProxyCommand option to quietly invoke the Windows Installer (msiexec) and download a payload, marking the start of the intrusion."
The DFIR Report tweet media
English
2
7
58
6.2K
RussianPanda 🐼 🇺🇦
RussianPanda 🐼 🇺🇦@RussianPanda9xx·
Okay wait... this actually happened?! 🥹💙 SANS Difference Makers 2025 - Community Choice Winner Practitioner of the Year - Cyber Defense This is the proudest moment of my life. A huge thank you to @MaxRogers5 for nominating me. That meant more than you know. To the incredible cybersecurity community - every single vote, every word of encouragement, every share - YOU did this. This award belongs to all of us. The late nights analyzing malware, chasing the bad guys, the blog posts, the "hey did you see this sample?" DMs - that's what this community is about. @SANSInstitute, thank you for shining a light on the defenders. Thank you for making quiet . louder 🔊
SANS Institute@SANSInstitute

The Practitioner of the Year – Cyber Defender Award 🛡️ honors a leading force in cyber defense—someone making a real impact on front-line security. The Community Winner for 2025 goes to @RussianPanda9xx. Congratulations! #SANSDMA #CyberDefense

English
45
22
307
33.5K
Tsof ретвитнул
Fox_threatintel
Fox_threatintel@banthisguy9349·
They can go cry me a river. womp womp
b0mb3r@0x_b0mb3r

@banthisguy9349 you got sum haters bro lmao. found this in touchmedaddy.mp3, a ps1 dropper

English
3
3
29
6K
Tsof ретвитнул
ܛܔܔܔܛܔܛܔܛ
ܛܔܔܔܛܔܛܔܛ@skocherhan·
DESKTOP-I1P3HMO Bang_Luong_Thang_11_2025.csv E001,John Smith,Manager,3000,500,400,200,3700,Excellent performance E002,Alice Johnson,Accountant,2200,300,150,100,2550,Accurate and punctual E003,Michael Brown,HR Officer,2000,250,200,50,2400,Great teamwork E004,Emma Davis,Sales Executive,1800,400,350,80,2470,Exceeded sales targets E005,David Wilson,IT Support,2100,200,100,120,2280,Reliable support E006,Sosona Mikari,IT Dev,2300,200,100,100,2500,
Szabolcs Schmidt@smica83

'salary_staistics.rar' seen from Viet Nam @abuse_ch CVE-2025-6218 and CVE-2025-8088 exploit bazaar.abuse.ch/sample/278bc81… @skocherhan

English
0
3
8
1.2K
Tsof ретвитнул
hithere
hithere@asdasd13asbz·
Hello, while investigating the Midnight or EndPoint ransomware, for which a decryption tool was recently released, I discovered several suspicious points and decided to compile a brief report about them Report : github.com/errbody/DPRK-R… #Ransomware #Kimsuky #Lazarus #APT
English
0
17
88
10K
Tsof ретвитнул
Tsof ретвитнул
mr.d0x
mr.d0x@mrd0x·
A follow up on last week’s FileFix blog. FileFix (Part 2) mrd0x.com/filefix-part-2/
English
6
63
221
19.1K
Tsof ретвитнул
Intel 471
Intel 471@Intel471Inc·
🚨 EMERGING THREAT: MOMMY ACCESS BROKER Leaked guide linked to mommy reveals how this actor exploits CVEs and sells access to high-value targets like governments and telecoms. 🔗 Read the full report: hubs.la/Q03v1Bkn0 #threatintel #cybersecurity #threathunting
Intel 471 tweet media
English
0
5
10
1.3K
Tsof ретвитнул
The DFIR Report
The DFIR Report@TheDFIRReport·
We had a blast speaking at the Ransomware Summit! 🎤💥 Huge thanks to everyone involved! 🎥 Missed our keynote? No worries — you can catch the full session here: 👉 youtube.com/live/nhB-xkmbS…
YouTube video
YouTube
Ryan "Chaps" Chapman@rj_chap

AMAZING keynote coming up at the @SANSInstitute | @sansforensics #RansomwareSummit 2025! @TheDFIRReport's @_pete_0 & @angelo_violetti are presenting "Adapting Tradecraft: Examining #Ransomware Attacks in 2024 - Insights from The DFIR Report"! FREE reg @: sans.org/u/1yCa

English
0
11
55
15.4K