
DFIR Notes
12.7K posts

DFIR Notes
@DfirNotes
design, build, teach threat-informed information security programs and techniques. Also: retweets of interesting classes, tools, research. They/them



We're excited to launch our new Analyst Skills Vault, a subscription-based service that provides access to our growing collection of standalone video lessons.

If I'm reading this config right, it's a #CobaltStrike using the @nytimes content API as a C2: gist.github.com/usualsuspect/7… dropped by fake @GoIvanti VPN updater ISO: virustotal.com/gui/file/568e3… ISO -> .NET stuff -> custom loader -> reflective loader beacon















Lots of CISOs out there rethinking their BYOD policies today. Even if you aren't, your business partners are and you should be expecting TPRM questions about it. #LastPass






The journey into Cybersecurity is not one-size-fits-all but can vary from person to person. In this webinar with @HuntressLabs, Jamie Levy will cover how she found her way into this field and give tips for choosing the right path for you. brighttalk.com/webcast/17216/… #WiCyS






