LETHAL_DFIR Profile Banner
LETHAL FORENSICS Profile
LETHAL FORENSICS

@LETHAL_DFIR

Followers
88
Following
3
Media
1
Statuses
10

Official X account for LETHAL FORENSICS. #DigitalForensics #IncidentResponse #Investigation #Microsoft365 #BEC

Hannover, Germany
Joined November 2024
Don't wanna be here? Send us removal request.
@LETHAL_DFIR
LETHAL FORENSICS
9 days
Microsoft-Analyzer-Suite v1.6.0 released today! 🚀.This update includes multiple new detections for Microsoft Entra ID OAuth Phishing Attacks based on the research by Elastic Security Labs. Check out the changelog for more information. Happy M365/Azure Threat Hunting!.#M365.
0
3
11
@LETHAL_DFIR
LETHAL FORENSICS
1 month
We just released MemProcFS-Analyzer v1.2.0 with various enhancements. Check out the changelog for more information. Happy Memory Analysis!. #MemProcFS #MemoryAnalysis #DFIR.
Tweet card summary image
github.com
[1.2.0] - 2025-06-24 Added EZTools (.NET 9) DFIR RECmd Batch File v2.11 (2025-03-31) 423 YARA Custom Rules FS_Process_Console FS_SysInfo_Network: DNS Information Digital Signature Fixed Minor fi...
0
19
66
@LETHAL_DFIR
LETHAL FORENSICS
2 months
We just released Microsoft-Analyzer-Suite v1.5.1. This update includes bug fixes and a new version of RiskyDetections-Analyzer. Check out the changelog for more information. Happy M365/Azure Threat Hunting!.#M365 #Azure #Entra #BEC #CloudIncidentResponse #DFIR #Microsoft.
0
9
15
@LETHAL_DFIR
LETHAL FORENSICS
3 months
Microsoft-Analyzer-Suite v1.5.0 is now available!🚀 We improved among other things the Device Code Flow Abuse detections and added support for the detection of suspicious 'UpdateInboxRules' operations (e.g. used by eM Client). Check out the changelog for more information and.
0
7
20
@LETHAL_DFIR
LETHAL FORENSICS
4 months
Quick update on some blacklists of the Microsoft-Analyzer-Suite: ApplicationPermission-Blacklist.csv, DelegatedPermission-Blacklist.csv, and UserAgent-Blacklist.csv. The update of the UserAgent-Blacklist covers the new M365 Account Takeover Attacks using HTTP Client Tools.
0
1
3
@LETHAL_DFIR
LETHAL FORENSICS
5 months
Just released Collect-MemoryDump v1.1.0 with various improvements. Triage Collection w/ MAGNET Response (Optional), Microsoft Protection Logs (MPLogs), Automated Processing of 'ProcessesAndModules-Extended_Info.tsv' (MAGNET Response), and much more. #MemoryAnalysis
Tweet media one
Tweet media two
Tweet media three
0
1
4
@LETHAL_DFIR
LETHAL FORENSICS
5 months
Happy to announce the release of Microsoft-Analyzer-Suite v1.4.0. It is our first company-branded release!🚀. The new OAuthPermissions-Analyzer uses the output of the new Graph-based 'Get-OAuthPermissionGraph' cmdlet of the Microsoft-Extractor-Suite v3.0.2, which we co-developed.
0
1
6