
Florian Roth ⚡️
@cyb3rops
Followers
205K
Following
172K
Media
6K
Statuses
35K
Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Frankfurt, Germany
Joined June 2013
I've decided to put a screenshot showing the hex editor view of a Turla Kazuar sample behind acrylic glass on my desk to always remind me, why I am doing all this . because I 💛 to be a pain in the neck of the bad guys .
It seems that I have some fans over in Russia 🐻. #TurlaLicksAss. thx to the FireEye analyst who brought this to my attention.
178
307
2K
RT @kimmonismus: The biggest problem with AI lies elsewhere than most people think. I wouldn't read too much into the article, but it does….
0
41
0
Good news - even the free THOR Lite detect the webshell that gets dropped by the POC
"Scattered Lapsus$ Hunters (UNC3944)", have released an alleged SAP7 0day exploit onto Telegram. I can't confirm or deny if it's an actual 0day, I have no way to test or confirm anything. However, it is fully weaponized. I've uploaded it to VXUG.
0
39
158
RT @vxunderground: "Scattered Lapsus$ Hunters (UNC3944)", have released an alleged SAP7 0day exploit onto Telegram. I can't confirm or den….
vx-underground.org
The largest collection of malware source code, samples, and papers on the internet.
0
39
0
RT @Dinosn: Telco giant Colt suffers attack, takes systems offline
theregister.com
: London-based multinational takes customer portal and Voice API platform offline as 'protective measure' following breach
0
4
0
I keep seeing reports of attackers going after #ESX hosts – exporting VMs, cloning domain controllers, grabbing NTDIS files. Not really surprising. ESX often ends up being the quiet corner of the network where no one’s looking. Thing is: we’ve had some solid ways to deal with
2
44
169
RT @yo_yo_yo_jbo: New blogpost, this time about different ways to dump lsass. While not novel, I explain all techniques and uploaded a full….
0
102
0
RT @DarkWebInformer: gitGraber: Monitor GitHub to search and find sensitive data in real time for different online services such as: Google….
0
69
0
RT @kimmonismus: The reasons why DeepSeek r2 has been delayed:. Despite a team of Huawei engineers working on site, it was not possible to….
0
97
0
RT @nas_bench: [New Blog 📚] The Fragile Balance: Assumptions, Tuning, and Telemetry Limits In Detection Engineering. If you ever struggle w….
0
26
0
RT @BleepinComputer: Spike in Fortinet VPN brute-force attacks raises zero-day concerns - @billtoulas. https://t.co….
bleepingcomputer.com
A massive spike in brute-force attacks targeted Fortinet SSL VPNs earlier this month, followed by a switch to FortiManager, marked a deliberate shift in targeting that has historically preceded new...
0
55
0
RT @_josehelps: now has SIEM queries and a tool section for those looking to operationalize the data. Thanks to @Cy….
0
43
0
I’m excited to announce two major upgrades in our free product line:. 📦 Archive scanning is now unlocked in THOR Lite - including docx, xlsx, jar, war, and more. 🧠 YARA Forge (my own project) is now integrated – extends the detection coverage with open source rules. 🔍 Also.
New in THOR Lite. 📦 Archive scanning with YARA - previously exclusive to the full version. 🧠 Curated rulesets from YARA Forge. Two powerful features, now unlocked.
3
45
181
RT @TheHackersNews: 🚨 Active Exploit Alert:. A critical FortiSIEM flaw (CVSS 9.8) lets attackers run code without logging in — and hackers….
0
115
0