dfir_it Profile
dfir_it

@dfir_it

Followers
805
Following
2K
Media
15
Statuses
146

We stalk #DFIR on a daily basis and blog once a year.

Joined March 2015
Don't wanna be here? Send us removal request.
@dfir_it
dfir_it
2 years
RT @siedlmar: RooCon Call for Papers is open!.We are now accepting papers for RooCon 2023, Cyber Threat Intelligence and Attribution confer….
rsvp.withgoogle.com
Cyber Threat Intelligence and Attribution Conference
0
14
0
@dfir_it
dfir_it
3 years
RT @JWilsonSecurity: Sometimes you just want to hunt 🔫.Three excellent technologies to investigate are. - VPN Clients. - Proxy Services….
Tweet card summary image
cloud.google.com
0
72
0
@dfir_it
dfir_it
4 years
RT @Int2e_: Don't know what an Azure Run Command is? Neither did I when we first stumbled on an attacker abusing this during a recent IR ca….
Tweet card summary image
cloud.google.com
We highlight Azure Run Commands and provide guidance for mitigations
0
73
0
@dfir_it
dfir_it
4 years
RT @Mandiant: Congrats to everyone who participated in #FLAREOn8! 👏. Check out our blog post for more on this year's contest & read the de….
0
30
0
@dfir_it
dfir_it
5 years
RT @nickharbour: #flareon7 The hall of fame is now live! Congratulations everyone. Prizes will begin shipping in Mi….
0
21
0
@dfir_it
dfir_it
5 years
RT @KarlScheuerman: Just recently realized that SANS Institute posted the presentation deck from the talk @dfir_it and I gave at the SANS….
0
4
0
@dfir_it
dfir_it
6 years
RT @JaneScott: <❔Oneliner PHP Webshells!❔>. Shortest:.<?=`$_GET[1]`?>.*For even shorter, try dropping ?>. Pass cmd in url query string:.sit….
0
85
0
@dfir_it
dfir_it
6 years
RT @KarlScheuerman: Didn't realize it was already posted but here is my and @dfir_it / Piotr's @MITREattack ATT&CKcon 2.0 talk from last mo….
0
3
0
@dfir_it
dfir_it
6 years
RT @saleh_muhaysin: #DFIR Pleased to announce that we have published Kuiper a digital investigation platform. It is designed to aid investi….
Tweet card summary image
github.com
Digital Forensics Investigation Platform. Contribute to DFIRKuiper/Kuiper development by creating an account on GitHub.
0
37
0
@dfir_it
dfir_it
6 years
Another fresh sample and another #OPSEC fail: One Google search away from determining the source organization 🤫
Tweet media one
0
0
1
@dfir_it
dfir_it
6 years
This simple SSH port forwarder has been around for a while. Even the embedded password has not been changed over the years. Samples:.(2017).(2019)
Tweet media one
1
2
5
@dfir_it
dfir_it
6 years
All challenges completed! Thanks @FireEye and the FLARE team for organizing #flareon6!
Tweet media one
0
2
11
@dfir_it
dfir_it
6 years
It looks like distribution of the #kingminer #malware was moved to GitHub: 24132.txt - 24164.txt - n.txt-
Tweet media one
0
1
4
@dfir_it
dfir_it
6 years
But wait, there's more!
Tweet media one
0
0
1
@dfir_it
dfir_it
6 years
Cutting edge cloud security breach notification technology
Tweet media one
0
1
1
@dfir_it
dfir_it
6 years
login-microsoftonline-com0authsecure353f.duckdns[.]org
1
0
2
@dfir_it
dfir_it
6 years
* Tries to download fresh AV signatures from esetcdnserver[.]icu *. * Gets #cobaltstrike beacon *
Tweet media one
0
0
3
@dfir_it
dfir_it
6 years
When you skip OPSEC 101 and go straight to hacking ¯\_(ツ)_/¯
Tweet media one
Tweet media two
Tweet media three
1
5
22