DFIR Notes
@DfirNotes
Followers
968
Following
1K
Media
24
Statuses
13K
design, build, teach threat-informed information security programs and techniques. Also: retweets of interesting classes, tools, research. They/them
Earth (Sol-3)
Joined October 2015
@dfirnotes is (we're) mostly: Information Security Leader & Educator | Twitter, Github: @dfirnotes BBSTi, CISSP, GIAC**0x0c, GSE**2, ITIL, LPI, MAD CTI Blog at https://t.co/WTp7sUaWtH DMs open for #CyberMentoringMonday or other questions. Be excellent to each other!
0
2
7
(1/n) WinDbg finally released outside the store, and no more "Preview"! Ecstatic to see my old team hit this milestone! It's come so far since @aluhrs13 and I started the "WinDbgNext" project so many years ago. https://t.co/PtOcgTxQ3C
learn.microsoft.com
Start here for an overview on the Windows debugger and installing WinDbg.
5
92
331
For $20 a month, you get access to a bunch of knowledge from smart people like @ForensicITGuy on topics from malware analysis to network forensics to EXCEL ❤️, and much more. This isn't sponsored, I just think it's awesome they're making such useful content so accessible!
We're excited to launch our new Analyst Skills Vault, a subscription-based service that provides access to our growing collection of standalone video lessons.
1
4
26
Domain fronting is hands-down the weirdest thing. I think a lot of blue team (including myself) would have heard the term over the years without looking into it. 1/4
If I'm reading this config right, it's a #CobaltStrike using the @nytimes content API as a C2: https://t.co/e8h201rcEa dropped by fake @GoIvanti VPN updater ISO: https://t.co/G5dLGGzLWY ISO -> .NET stuff -> custom loader -> reflective loader beacon
1
4
40
@Cyb3rMonk I think it depends on what you want the EDR. Personally, I have never looked at an EDR as a source for detection but a source of telemetry. I see vendors say they detect "x", but I have always used that as one of my detections for a given operation versus the sole detection.
1
2
13
Anyone who wants a mentor, to give back to the community, or to just share resources should definitely check out #CyberMentoringMonday loads of amazing people and info in the tag!!
0
5
24
1
41
105
Reminded by @jaredcatkinson what an invaluable project Security Datasets is: OSS initiative that contributes malicious & benign datasets from different platforms to expedite data analysis & threat research. @Cyb3rWard0g @Cyb3rPandaH
github.com
Re-play Security Events. Contribute to OTRF/Security-Datasets development by creating an account on GitHub.
0
5
13
Our Sigma rule extension for @code got a major update by my team member @paulhagertheo It allows lookups of similar and related rules & uses a new web service to do that it's still new & only superficially tested - feedback & bug reports are welcome https://t.co/qwN2owJCrI
4
42
127
Our call for sponsors is open! Our prospectus is now up at https://t.co/KLJKldRglC Your support will help us do even more amazing things this year. Great opportunity to connect & support #womenInTech #diversity in #infosec
#LeadTheChange #TDI2023
dianainitiative.org
Our Values
0
8
9
"The labs were fun and interesting. The feedback is fast and insightful...I'm not used to that much interaction with an instructor in an asynchronous course!" - Rob
1
2
0
"If you pay attention and give Investigation Theory its due, you will come out the other side a much better analyst for having taken it."
1
3
3
@netresec @GuhnooPlusLinux That said, the way meterpreter does TLS is strange, so you can do detection on how it behaves. However, again... this is defaults, you can change the TLS behavior in your payload options and advanced options.
0
1
2
well, Balkan Cyberia finally has a cover and it is marching robotically towards its publication on the 13th June with @mitpress! It has spies & cyborgs, not just apparatchiks - and will be open access but if you want a copy, there will be a discount code! https://t.co/0yTi1FdbMo
24
66
402
IMO, BYOD is *the most expensive* cost savings measure ever.
Lots of CISOs out there rethinking their BYOD policies today. Even if you aren't, your business partners are and you should be expecting TPRM questions about it. #LastPass
3
4
38
We often get asked how to land a job in cybersecurity. In today's video, Heath discusses the importance of community and giving back as one of the important steps to getting a job in cybersecurity. https://t.co/7ozr8667Mz
3
13
121
New release: #PEbear 0.6.5: https://t.co/AsAbJGR9nb - several new features, fixes and improvements - check it out!
19
160
645
I'll be giving a talk next week over my journey into #DFIR and give some tips to help others find their way into this space! #memoryforensics #malware #infosec #infosecurity
The journey into Cybersecurity is not one-size-fits-all but can vary from person to person. In this webinar with @HuntressLabs, Jamie Levy will cover how she found her way into this field and give tips for choosing the right path for you. https://t.co/PxheSf2DTD
#WiCyS
1
10
28
Assert dominance in your ticket queue by submitting all technical details necessary with screenshot of Hello Kitty terminal.
11
29
233
#SLEUTHCON provides cybersecurity newcomers & professionals the opportunity to learn from industry experts in easy-to-follow 30 min talks. Join us online or in Arlington, VA on 5/12! Register today at https://t.co/k217bE6gS0.
#cybercrime #infosec #cyberattacks #CTI #ransomware
0
9
5