arch_rabbit Profile Banner
Nedim Šabić² 🐰 Profile
Nedim Šabić² 🐰

@arch_rabbit

Followers
302
Following
1K
Media
44
Statuses
483

warheart. I built fibratus.

where bunnies dwell
Joined August 2016
Don't wanna be here? Send us removal request.
@arch_rabbit
Nedim Šabić² 🐰
5 years
I'm thrilled to announce Fibratus - a modern tool for the Windows kernel tracing and observability built in @golang . Fibratus is the fruit of a lot of development.and research during the past two years. To discover more about Fibratus, head to
2
33
91
@arch_rabbit
Nedim Šabić² 🐰
1 month
RT @impromptum2: A small tribute for fellow Dark Souls II fans. ♥️.#DarkSouls.@VaatiVidya.
0
3
0
@arch_rabbit
Nedim Šabić² 🐰
1 month
RT @impromptum2: Quién más recuerda la música de este increíble juego? 🛡️🗡️.#JRPG #PlayStation
0
1
0
@arch_rabbit
Nedim Šabić² 🐰
2 months
🚀 Fibratus 2.4.0 is out!. I'm thrilled to announce the Fibratus 2.4.0 With over 100 commits, this release brings astonishing performance improvements, 24 new rules, threadpool telemetry and much more. Check the full change log.
Tweet card summary image
github.com
Release Notes New features #370b43e: Enable callstack for VirtualAlloc events #8e81077: Enable callstack for OpenProcess and OpenThread events #efdd5e3: Introduce *.path filter fields #9df026f: Ne...
0
2
11
@arch_rabbit
Nedim Šabić² 🐰
3 months
RT @akaclandestine: GitHub - rabbitstack/fibratus: Adversary tradecraft detection, protection, and hunting
Tweet card summary image
github.com
Adversary tradecraft detection, protection, and hunting - GitHub - rabbitstack/fibratus: Adversary tradecraft detection, protection, and hunting
0
20
0
@arch_rabbit
Nedim Šabić² 🐰
7 months
RT @kuzmica75: Ljudi delite, delite #Banjaluka ajmo za nasu @slavka1771, ajmo 🙏
Tweet media one
0
249
0
@arch_rabbit
Nedim Šabić² 🐰
8 months
A short demo of the Eventlog alert sender.
0
0
1
@arch_rabbit
Nedim Šabić² 🐰
8 months
Fibratus 2.3.0 is out!. 🪲𝗥𝗲𝘃𝗮𝗺𝗽𝗲𝗱 𝗬𝗔𝗥𝗔 𝗺𝗲𝗺𝗼𝗿𝘆 𝘀𝗰𝗮𝗻𝗻𝗲𝗿 .🪵𝗘𝘃𝗲𝗻𝘁𝗹𝗼𝗴 𝗮𝗹𝗲𝗿𝘁 𝘀𝗲𝗻𝗱𝗲𝗿.🕵 𝟭𝟬 𝗻𝗲𝘄 𝗱𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻 𝗿𝘂𝗹𝗲𝘀.🪪 𝗠𝗦𝗜 𝗰𝗼𝗱𝗲 𝘀𝗶𝗴𝗻𝗶𝗻𝗴.🛡️ 𝗥𝘂𝗹𝗲 𝗹𝗮𝗻𝗴𝘂𝗮𝗴𝗲 𝗳𝗶𝗲𝗹𝗱𝘀.
Tweet card summary image
github.com
Release Notes New features #3acb68b: Eventlog alert sender #fb4eac8: Augment process events with process flags #bfdceb7: Augment process state with creation flags #2511296: Add process creation fl...
1
3
7
@arch_rabbit
Nedim Šabić² 🐰
10 months
RT @impromptum2: Hi! More SILENT HILL 2 OST 🌫️.Theme Of Laura (Reprise) composed by @AkiraYamaoka . The Soundtrack Preview inspired me for….
0
3
0
@arch_rabbit
Nedim Šabić² 🐰
10 months
RT @impromptum2: 🔥Dark Souls 3 - Firelink Shrine.(Full video on my YouTube channel).#DarkSouls #fromsoftware #bandainamco .
0
2
0
@arch_rabbit
Nedim Šabić² 🐰
10 months
RT @impromptum2: SILENT HILL 2🔺 - True | Piano Solo (composition by @AkiraYamaoka ) .#silenthill2 #Konami
0
4
0
@arch_rabbit
Nedim Šabić² 🐰
10 months
🎉 Fibratus 2.2.1 is out!. This is a maintenance release with a bunch of small enhancements and bug fixes. Chnagelog: Kudos to @JRdefmain for catching and reporting the 🐛.
Tweet card summary image
github.com
Adversary tradecraft detection, protection, and hunting - rabbitstack/fibratus
0
2
9
@arch_rabbit
Nedim Šabić² 🐰
10 months
RT @impromptum2: Hi! New video from The Legend Of Dragoon(⁠◍⁠•⁠ᴗ⁠•⁠◍⁠)💚.#PlayStation #RPG #GamingVibes . @16bitnost….
0
4
0
@arch_rabbit
Nedim Šabić² 🐰
11 months
🎉 Fibratus 2.2.0 is out!. This marks the start of a new era. I'm refocusing the product strategy towards adversary tradecraft detection and protection. Highlights of this release:.- kernel callstack enrichment.- systray alert sender.- 30 new detection rules.
1
2
12
@arch_rabbit
Nedim Šabić² 🐰
1 year
TIL: If you plant a custom wow64log.dll in System32 directory, the DLL will get loaded into every WoW64 process in the system. You might already knew this. But did you know its signature characteristics are retained from kernel image callback perspective?.
0
2
20
@arch_rabbit
Nedim Šabić² 🐰
1 year
RT @impromptum2: Hi! I did " Super Earth Anthem " Hope you like it :). @helldivers2 @Helldiversmedia . #Helldivers2.
0
1
0
@arch_rabbit
Nedim Šabić² 🐰
1 year
post anymore. Any hints?.
0
0
0
@arch_rabbit
Nedim Šabić² 🐰
1 year
To all sec researchers. I'm trying to identify and APT whose initial access consists on delivering a weaponized macro. After execution, the macro will target and terminate the Windows Event Log threads. I recall there was a detailed analysis of this APT, but can't find the blog.
3
0
1