Markus Lassfolk

1.5K posts

Markus Lassfolk

Markus Lassfolk

@lassfolk

Got a passion for Technology in general but with a big Cyber Security focus. VP for Incident Response @Truesec @[email protected]

Sweden เข้าร่วม Şubat 2012
1.2K กำลังติดตาม1.7K ผู้ติดตาม
Markus Lassfolk
Markus Lassfolk@lassfolk·
f1tv - got it working by disabling multiview (under account settings) and watch normal stream 👍
English
0
0
3
819
Markus Lassfolk รีทวีตแล้ว
Johannes Bader
Johannes Bader@viql·
Today, I'm releasing the first version of a small web 🚀: rosti.bin.re It provides IOCs and YARA rules collected semi-automatically from public blog posts and reports of almost 200 cybersecurity sites. I hope it proves useful to some of you ... 🙏✨ #ThreatIntel
Johannes Bader tweet media
English
17
124
372
32.3K
Markus Lassfolk รีทวีตแล้ว
Adam Chester 🏴‍☠️
This hack is brilliant, APT28 hopping into a target environment over wifi by compromising neighbouring companies and finding a dual-homed host within range. volexity.com/blog/2024/11/2… And yet... they got caught doing this!
Adam Chester 🏴‍☠️ tweet media
English
21
101
623
88.8K
Martyn Coupland
Martyn Coupland@mrcoups·
The fix from @CrowdStrike so far is to login to individual servers to fix the issue, if you’re in the enterprise, today is not a great and you have a long weekend coming up. Please remember your sysadmins today!
English
2
1
12
760
Markus Lassfolk
Markus Lassfolk@lassfolk·
@x0rz What about disk-encrypted systems, ie with Bitlocker etc?
English
2
0
0
390
x0rz
x0rz@x0rz·
> PXE boot on a system-rescue.org image > ssh into every workstations/servers > remove faulty .sys file > reboot normally > CrowdStrike updates > ??? > profit and see you on monday
English
5
14
39
4.8K
Markus Lassfolk
Markus Lassfolk@lassfolk·
@vmesc4pe @_JohnHammond We do the same. Its great for automated flows and sharing, all machine-to-machine stuff, and as a database. But we use other tools to actually do the daily job, like OpenCTI and self developed things.
English
0
0
1
135
plato
plato@vmesc4pe·
@_JohnHammond All of the above. We store every ioc we come across and use it to enrich our detections and IR tooling, then share ioc data with other government misp instances. Hooks up to DFIR-IRIS quite well too
English
1
0
3
227
John Hammond
John Hammond@_JohnHammond·
CTI/DFIR people. If I may please prod your mind. Do you actually use MISP?
English
10
2
26
13K
Markus Lassfolk รีทวีตแล้ว
David das Neves
David das Neves@david_das_neves·
Windows 11's new AI Recall feature raises security concerns. Therefore, check this KQL hunting query (see below) designed for Microsoft Defender for Endpoint users to detect any activations of AI Recall on your network which has been created by Steven Lim. #ThreatHunting
David das Neves tweet media
English
1
48
147
16.9K
Markus Lassfolk รีทวีตแล้ว
Markus Lassfolk
Markus Lassfolk@lassfolk·
We are hosting our monthly Community Evening in Stockholm (on-premises, not virtual), this time on the subject of 'Operational Technology' with a guest speaker from SANS. Welcome! Link for pre-Registering: lyyti.fi/reg/Truesec_Te…
English
0
2
5
244
Markus Lassfolk
Markus Lassfolk@lassfolk·
@adbertram Great one! Had no idea. Is there one for DomainNames.tld too? 😀
English
0
0
0
182
Adam Bertram
Adam Bertram@adbertram·
#PowerShell tip of the day: Use the [ipaddress] type accelerator to quickly parse and validate IP addresses.
Adam Bertram tweet media
English
4
23
136
8.9K
Markus Lassfolk
Markus Lassfolk@lassfolk·
@tmels ohhh thank you, had missed that possibility! Will be a great extra project to work on.
English
0
0
0
44
Tony Mels
Tony Mels@tmels·
@lassfolk You can run M365 DSC and run difference report on set intervals.
English
1
0
1
87
Markus Lassfolk
Markus Lassfolk@lassfolk·
Has anyone seen any way to visualize for Corp Users any changes IT does to o365/EntraID/Intune? Im dreaming of an internal website showing anything that has changed, showing any new apps, policy changes etc etc
English
2
1
5
655
Markus Lassfolk รีทวีตแล้ว
Gi7w0rm
Gi7w0rm@Gi7w0rm·
I highly suggest everyone in #CTI to check out the community version of @ValidinLLC. Free availability of historical DNS data going several years back is absolutely amazing to have at hand. I use this tool several times a week during my investigations, with great success.
Validin@ValidinLLC

It's here - our long-awaited update is out! This update builds on our massive passive DNS database and is packed with features requested by the community. ❤️ If you're a threat hunter or researcher, this platform is made for you! validin.com/blog/announcin…

English
3
25
76
16K
Markus Lassfolk รีทวีตแล้ว
Valéry Rieß-Marchive | @valerymarchive.bsky.social
This 👇 is interesting and suggests that we can't anymore consider only the possibility of a common initial access broker #IAB in case of one victim claimed under more than one #ransomware brand. I've counted 88 cases of cross-claims since Jan. 1st, 2023. Let's take a look...
DarkFeed@ido_cohen2

🌐 On the last day, Lockbit #ransomware group announced sixteen new victims despite operation #Cronos 🚨 More than five of the victims are companies that were already been #compromised by BlackCat (ALPHV) team, whose website was allegedly shut down by law enforcement 👀 #Lockbit with a total of 2533 victims 🥇 ➡️ More Info: DARKFEED.IO #BlackCat

English
1
19
51
24.4K