
Andurin
@4ndur1n
Followers
101
Following
324
Media
4
Statuses
142
IT-Security, Cyber Threat Analyst
Germany
Joined December 2016
RT @0xdabbad00: CISA is requiring all Federal agencies to disconnect Ivanti products by Friday at midnight (Ivanti Connect Secure & Ivanti….
cisa.gov
0
182
0
RT @DCSO_CyTec: Our newest article provides a closer look at recent reporting on Volt Typhoon's "JDY" botnet management, which suggests tha….
medium.com
Not all Tor relays are created equal. A closer look at network communication between a Volt Typhoon C2 and a Tor relay prompts questions.
0
8
0
RT @DCSO_CyTec: #ShortAndMalicious.Our researchers recently discovered an installer for the mandatory 🇷🇺Russian tax filling software "Sprav….
0
6
0
Elasticsearch keyword searches are fast and fine but misses case-insensitive searches. Event-Query-Language (EQL) sounds like a valuable answer for many security related use cases. Today I'm allowed to release pySigma-backend-elasticsearch (v1.0.8 ) with a EQL Support. @sigma_hq.
1
10
39
RT @alexanderjaeger: 🕶️🧐👀🥷🥁A new project by the Security Response team of @Google: It fills a gap I have seen for….
0
91
0
Hey @MITREattack ,.why are there two different GH Projects for nearly the same content?.and. Why does attack-stix-data contains the "x_mitre_version" and cti doesn't?.
1
0
2
@sigma_hq Also the pySigma-backend-opensearch got some updates - mainly caused by the version bump from ES.
github.com
pySigma OpenSearch backend. Contribute to SigmaHQ/pySigma-backend-opensearch development by creating an account on GitHub.
0
0
1
Just released a fresh version of pySigma-backend-elasticsearch. More tests for more stable development, based on the latest pySigma 0.8.12. Far better `|re` functionality. Update before its cold 😃. @sigma_hq.
github.com
pySigma Elasticsearch backend. Contribute to SigmaHQ/pySigma-backend-elasticsearch development by creating an account on GitHub.
2
14
34
RT @adulau: A huge thank to @Joseliyo_Jstnk for the work on converting automatically @sigma_hq rules into a @MISPProject galaxy. I finally….
0
19
0
APT41 — The spy who failed to encrypt me by @DCSO_CyTec
link.medium.com
This blog post is based on our recent investigation into one of APT41’s operations against an unnamed German company from the financial…
0
0
7