Thomas Fischer

44.5K posts

Thomas Fischer banner
Thomas Fischer

Thomas Fischer

@FVT

Avid MMORPG'er by night, Insane IT Security Advocate! All around DFIR/SecOps curmudgeon My tweets are my own! MASTADON: @[email protected] Post.: fvt___

Dublin,IE Tham gia Şubat 2007
1.4K Đang theo dõi1.8K Người theo dõi
Thomas Fischer đã retweet
Threat Hunting Labs
Threat Hunting Labs@ThruntingLabs·
Introducing Threat Hunting Labs. A training platform focused on realistic intrusion investigations. Start from an alert, analyze real telemetry, and work through structured investigation paths. Built for threat hunters, incident responders, and detection engineers. More details: threathuntinglabs.com/blog/introduci…
English
1
23
114
12.4K
Thomas Fischer đã retweet
ANY.RUN
ANY.RUN@anyrun_app·
⚠️️️ 𝗡𝗲𝘄 𝗦𝘁𝗮𝗴𝗲𝗿 𝗟𝗲𝗮𝗱𝗶𝗻𝗴 𝘁𝗼 𝗥𝗔𝗧 𝗗𝗲𝗽𝗹𝗼𝘆𝗺𝗲𝗻𝘁: 𝗗𝗲𝘁𝗲𝗰𝘁 𝗜𝘁 𝗘𝗮𝗿𝗹𝘆 We caught #RUTSSTAGER, a malware that stores a DLL in the Windows registry in hexadecimal form, hiding the payload and delaying detection. In the observed chain, the stager delivered #OrcusRAT, followed by a supporting binary that maintains persistence, uses PowerShell for system checks, and restarts the RAT process. ✅ In the #ANYRUN Sandbox, behavioral analysis and file system monitoring exposed the full execution chain. Process synchronization events revealed coordination between the stager and its payload, helping confirm multi-stage malware activity early. 👾 See the analysis session and collect #IOCs to speed up detection and response: app.any.run/tasks/b357aa61… 🔍 Pivot from indicators and subscribe to Query Updates to proactively track evolving attacks: intelligence.any.run/analysis/looku… 👨‍💻 Learn how #ANYRUN Sandbox helps SOCs detect complex threats and contain incidents faster: any.run/features/?utm_… #ExploreWithANYRUN
ANY.RUN tweet media
English
1
13
47
4.2K
Thomas Fischer đã retweet
SANS DFIR
SANS DFIR@sansforensics·
📄 Need a handy reference for your forensic investigations? Our #SIFT Cheat Sheet is designed for #DFIR analysts with essential tools and techniques on the SANS #Linux SIFT Workstation Download your copy: buff.ly/PM3AKjT
SANS DFIR tweet media
English
0
19
53
4.4K
Thomas Fischer đã retweet
Hunt.io
Hunt.io@Huntio·
💡 A Practical Look at AWS Threat Hunting hunt.io/glossary/aws-t… AWS environments generate massive telemetry. The challenge isn’t collecting logs, it’s turning one suspicious signal into context. This is our practical workflow: 1) Start with VPC Flow Logs, GuardDuty, or CloudTrail. 2) Enrich the IP/domain using our platform. 3) Pivot to related domains, certs, hashes, C2s. 4) Map the campaign, not just the alert. 5) Feed findings back into detection. Effective AWS threat hunting starts with a signal and expands from there. #AWS #ThreatHunting #CyberSecurity
English
0
7
40
2.6K
Thomas Fischer đã retweet
The DFIR Report
The DFIR Report@TheDFIRReport·
We analyzed a DPRK-linked Contagious Interview intrusion where fake job lures abused npm install for C2 using trusted packages. A modular toolset (OtterCookie, InvisibleFerret, Tsunami) enabled cross-platform access and data theft targeting wallets, creds, and docs.
The DFIR Report tweet media
English
2
44
159
10.3K
Thomas Fischer đã retweet
SpecterOps
SpecterOps@SpecterOps·
Seeing identity attack paths is one thing. Eliminating them safely is another. @ChannelInsider breaks down BloodHound Scentry and how it helps teams operationalize Identity APM faster. ⤵️ ghst.ly/3OioUg2
English
0
2
7
1.5K
Thomas Fischer đã retweet
SSD Secure Disclosure
SSD Secure Disclosure@SecuriTeam_SSD·
New advisory was just published! 🚨 Three new post auth vulnerabilities have been found in ISPConfig. These vulnerabilities allow attackers who have either Reseller or Client accounts to escalate to root level access.
English
0
11
158
270.5K
Thomas Fischer đã retweet
blackorbird
blackorbird@blackorbird·
The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World This book explores how intelligence and cyber-security analysts can uncover hidden links between threat actor infrastructure and ongoing investigations by pivoting on both classic and unconventional indicators — many of which are often overlooked. The material is grounded in empirical, field-tested strategies used in cyber-security, digital forensics, cyber threat intelligence, and intelligence analysis more broadly. Our goal is to provide analysts with a practical toolkit of analytical methods, supported by real-world examples, to enhance investigative workflows without locking them into a single mindset, strict model, or overly rigid technical strategy. Instead, the book encourages creative exploration, data-driven reasoning, and the use of diverse data points — from traditional IOCs to subtle metadata traces — as part of a flexible and repeatable analytical process. #threathunting github.com/blackorbird/AP…
blackorbird tweet mediablackorbird tweet mediablackorbird tweet media
English
3
127
599
37.9K
Thomas Fischer đã retweet
Proton VPN
Proton VPN@ProtonVPN·
The OFFICIAL Proton VPN CLI is now available on: ✅ Arch (btw) ✅ Debian ✅ Ubuntu ✅ Fedora Next, we're adding features to let you specify P2P, TOR, and Secure Core for your connection, and the ability to see all countries/cities. Here's a quick demo and how to install it 👇
English
93
147
1.7K
103.3K
Thomas Fischer đã retweet
abuse.ch
abuse.ch@abuse_ch·
Love letter ❤️ from a threat actor 🕵️exploiting React2Shell vulnerability (CVE-2025-55182) to spread #Mirai malware ⤵️ fuckoffurlhaus 😂 Payload URLs 🌐: urlhaus.abuse.ch/host/45.153.34… Mirai botnet C2s 📡: marvisxoxo .st (ISTanCo 🇷🇸) 45.156.87 .231:23789 (AS51396 PFCLOUD 🇩🇪) Malware sample 📄: bazaar.abuse.ch/sample/9a84057…
abuse.ch tweet media
English
0
19
83
9.5K
Thomas Fischer đã retweet
BSides London
BSides London@BSidesLondon·
There have been many posts asking about whether the #BSidesLDN2025 talks were recorded. Yes they were! They will be available on our YouTube channel youtube.com/channel/UCXXNO… Please subscribe, we only upload once a year, and you’ll be notified when the videos are available!
English
2
11
25
1.5K
Thomas Fischer đã retweet
The DFIR Report
The DFIR Report@TheDFIRReport·
Huge congratulations to @RussianPanda9xx on winning SANS Difference Makers 2025 – Practitioner of the Year (Cyber Defense) 🎉
RussianPanda 🐼 🇺🇦@RussianPanda9xx

Okay wait... this actually happened?! 🥹💙 SANS Difference Makers 2025 - Community Choice Winner Practitioner of the Year - Cyber Defense This is the proudest moment of my life. A huge thank you to @MaxRogers5 for nominating me. That meant more than you know. To the incredible cybersecurity community - every single vote, every word of encouragement, every share - YOU did this. This award belongs to all of us. The late nights analyzing malware, chasing the bad guys, the blog posts, the "hey did you see this sample?" DMs - that's what this community is about. @SANSInstitute, thank you for shining a light on the defenders. Thank you for making quiet . louder 🔊

English
1
6
53
15.6K
Thomas Fischer đã retweet
CNIL
CNIL@CNIL·
#Sharenting 👶📱Et si on réfléchissait avant de publier ? En France, 53 % des parents ont déjà partagé des photos ou vidéos de leurs enfants en ligne. 📺Du 11 au 17 décembre 2025, découvrez notre vidéo de sensibilisation diffusée sur les antennes de @Francetele.
CNIL@CNIL

#Sharenting Partager des photos ou vidéos de vos enfants n’est pas anodin. 📽️ Découvrez notre vidéo de sensibilisation réalisée avec la @DPCIreland. Infos et réflexes 👉 cnil.fr/fr/partage-de-…

Français
2
18
15
3.7K