cyb3rops Profile Banner
Florian Roth ⚡️ Profile
Florian Roth ⚡️

@cyb3rops

Followers
205K
Following
172K
Media
6K
Statuses
35K

Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim

Frankfurt, Germany
Joined June 2013
Don't wanna be here? Send us removal request.
@cyb3rops
Florian Roth ⚡️
4 years
I've decided to put a screenshot showing the hex editor view of a Turla Kazuar sample behind acrylic glass on my desk to always remind me, why I am doing all this . because I 💛 to be a pain in the neck of the bad guys .
Tweet media one
Tweet media two
@cyb3rops
Florian Roth ⚡️
6 years
It seems that I have some fans over in Russia 🐻. #TurlaLicksAss. thx to the FireEye analyst who brought this to my attention.
Tweet media one
178
307
2K
@cyb3rops
Florian Roth ⚡️
12 hours
RT @kimmonismus: The biggest problem with AI lies elsewhere than most people think. I wouldn't read too much into the article, but it does….
0
41
0
@grok
Grok
6 days
Generate videos in just a few seconds. Try Grok Imagine, free for a limited time.
397
663
3K
@cyb3rops
Florian Roth ⚡️
19 hours
RT @jamieantisocial: we were shook.
Tweet media one
0
4
0
@cyb3rops
Florian Roth ⚡️
19 hours
RT @birchb0y: reversing dprk malware 🇰🇵: hehe its all in this file! you're so welcome! have fun! 🥰. reversing cn malware 🇨🇳: actually go fu….
0
38
0
@cyb3rops
Florian Roth ⚡️
2 days
Good news - even the free THOR Lite detect the webshell that gets dropped by the POC
Tweet media one
@vxunderground
vx-underground
2 days
"Scattered Lapsus$ Hunters (UNC3944)", have released an alleged SAP7 0day exploit onto Telegram. I can't confirm or deny if it's an actual 0day, I have no way to test or confirm anything. However, it is fully weaponized. I've uploaded it to VXUG.
0
39
158
@cyb3rops
Florian Roth ⚡️
2 days
RT @vxunderground: "Scattered Lapsus$ Hunters (UNC3944)", have released an alleged SAP7 0day exploit onto Telegram. I can't confirm or den….
vx-underground.org
The largest collection of malware source code, samples, and papers on the internet.
0
39
0
@cyb3rops
Florian Roth ⚡️
2 days
Everything becomes easier to digest once you turn it into a large infographic. Magically, even the most complex mess turns into a piece of cake.
@bibryam
Bilgin Ibryam
3 days
Kubernetes on-prem security overview 🌟.
Tweet media one
7
21
165
@cyb3rops
Florian Roth ⚡️
2 days
RT @nixcraft: ACME Protocol automates the issuance and renewal of SSL/TLS certificates, making web security management more efficient. Let….
0
145
0
@cyb3rops
Florian Roth ⚡️
2 days
I guess it was the apartment of the UX designer who created the "Enable Content" button in the old MS Office products.
@hourly_shitpost
🕐HOURLY🕑 shitpost
3 days
Tweet media one
4
4
48
@cyb3rops
Florian Roth ⚡️
2 days
I keep seeing reports of attackers going after #ESX hosts – exporting VMs, cloning domain controllers, grabbing NTDIS files. Not really surprising. ESX often ends up being the quiet corner of the network where no one’s looking. Thing is: we’ve had some solid ways to deal with
Tweet media one
2
44
169
@cyb3rops
Florian Roth ⚡️
2 days
“Your tweets look AI-generated.”. Yeah, maybe. But I wrote the blueprint in 2019. If AI mimics me, I take that as a compliment. All I use it for now is to fix grammar quirks from being a non-native speaker. Throwback to my blog post:.
Tweet media one
4
3
57
@cyb3rops
Florian Roth ⚡️
2 days
RT @yo_yo_yo_jbo: New blogpost, this time about different ways to dump lsass. While not novel, I explain all techniques and uploaded a full….
0
102
0
@cyb3rops
Florian Roth ⚡️
2 days
RT @DarkWebInformer: gitGraber: Monitor GitHub to search and find sensitive data in real time for different online services such as: Google….
0
69
0
@cyb3rops
Florian Roth ⚡️
3 days
RT @kimmonismus: The reasons why DeepSeek r2 has been delayed:. Despite a team of Huawei engineers working on site, it was not possible to….
0
97
0
@cyb3rops
Florian Roth ⚡️
3 days
RT @nas_bench: [New Blog 📚] The Fragile Balance: Assumptions, Tuning, and Telemetry Limits In Detection Engineering. If you ever struggle w….
0
26
0
@cyb3rops
Florian Roth ⚡️
3 days
RT @Narcass3: hi. here is ican0220 or RokyangDeveloper0220!. Might also go by Xun Zhu . dev.zhu0712@gmail.com.icandev0220@gmail.com.https:/….
0
8
0
@cyb3rops
Florian Roth ⚡️
3 days
RT @_josehelps: now has SIEM queries and a tool section for those looking to operationalize the data. Thanks to @Cy….
0
43
0
@cyb3rops
Florian Roth ⚡️
3 days
I’m excited to announce two major upgrades in our free product line:. 📦 Archive scanning is now unlocked in THOR Lite - including docx, xlsx, jar, war, and more. 🧠 YARA Forge (my own project) is now integrated – extends the detection coverage with open source rules. 🔍 Also.
@nextronsystems
Nextron Systems
4 days
New in THOR Lite. 📦 Archive scanning with YARA - previously exclusive to the full version. 🧠 Curated rulesets from YARA Forge. Two powerful features, now unlocked.
Tweet media one
Tweet media two
3
45
181
@cyb3rops
Florian Roth ⚡️
3 days
RT @TheHackersNews: 🚨 Active Exploit Alert:. A critical FortiSIEM flaw (CVSS 9.8) lets attackers run code without logging in — and hackers….
0
115
0