DfirNotes Profile Banner
DFIR Notes Profile
DFIR Notes

@DfirNotes

Followers
968
Following
1K
Media
24
Statuses
13K

design, build, teach threat-informed information security programs and techniques. Also: retweets of interesting classes, tools, research. They/them

Earth (Sol-3)
Joined October 2015
Don't wanna be here? Send us removal request.
@DfirNotes
DFIR Notes
5 years
@dfirnotes is (we're) mostly: Information Security Leader & Educator | Twitter, Github: @dfirnotes BBSTi, CISSP, GIAC**0x0c, GSE**2, ITIL, LPI, MAD CTI Blog at https://t.co/WTp7sUaWtH DMs open for #CyberMentoringMonday or other questions. Be excellent to each other!
0
2
7
@timmisiak
Tim Misiak
3 years
(1/n) WinDbg finally released outside the store, and no more "Preview"! Ecstatic to see my old team hit this milestone! It's come so far since @aluhrs13 and I started the "WinDbgNext" project so many years ago. https://t.co/PtOcgTxQ3C
Tweet card summary image
learn.microsoft.com
Start here for an overview on the Windows debugger and installing WinDbg.
5
92
331
@likethecoins
Katie Nickels
3 years
For $20 a month, you get access to a bunch of knowledge from smart people like @ForensicITGuy on topics from malware analysis to network forensics to EXCEL ❤️, and much more. This isn't sponsored, I just think it's awesome they're making such useful content so accessible!
@NetworkDefense
Applied Network Defense
3 years
We're excited to launch our new Analyst Skills Vault, a subscription-based service that provides access to our growing collection of standalone video lessons.
1
4
26
@tlansec
tlansec
3 years
Domain fronting is hands-down the weirdest thing. I think a lot of blue team (including myself) would have heard the term over the years without looking into it. 1/4
@jaydinbas
Johann Aydinbas
3 years
If I'm reading this config right, it's a #CobaltStrike using the @nytimes content API as a C2: https://t.co/e8h201rcEa dropped by fake @GoIvanti VPN updater ISO: https://t.co/G5dLGGzLWY ISO -> .NET stuff -> custom loader -> reflective loader beacon
1
4
40
@JonnyJohnson_
Jonny Johnson
3 years
@Cyb3rMonk I think it depends on what you want the EDR. Personally, I have never looked at an EDR as a source for detection but a source of telemetry. I see vendors say they detect "x", but I have always used that as one of my detections for a given operation versus the sole detection.
1
2
13
@T3chnicalB
.
3 years
Anyone who wants a mentor, to give back to the community, or to just share resources should definitely check out #CyberMentoringMonday loads of amazing people and info in the tag!!
0
5
24
@virustotal
VirusTotal
3 years
Introducing VT4Splunk, our official App for @splunk https://t.co/bVLsnWnr9k by @thetravelr
1
41
105
@holisticinfosec
Russ McRee
3 years
Reminded by ⁦@jaredcatkinson⁩ what an invaluable project Security Datasets is: OSS initiative that contributes malicious & benign datasets from different platforms to expedite data analysis & threat research. ⁦@Cyb3rWard0g⁩ ⁦@Cyb3rPandaH
github.com
Re-play Security Events. Contribute to OTRF/Security-Datasets development by creating an account on GitHub.
0
5
13
@cyb3rops
Florian Roth ⚡️
3 years
Our Sigma rule extension for @code got a major update by my team member @paulhagertheo It allows lookups of similar and related rules & uses a new web service to do that it's still new & only superficially tested - feedback & bug reports are welcome https://t.co/qwN2owJCrI
4
42
127
@DianaInitiative
The Diana Initiative
3 years
Our call for sponsors is open! Our prospectus is now up at https://t.co/KLJKldRglC Your support will help us do even more amazing things this year. Great opportunity to connect & support #womenInTech #diversity in #infosec #LeadTheChange #TDI2023
Tweet card summary image
dianainitiative.org
Our Values
0
8
9
@NetworkDefense
Applied Network Defense
3 years
"The labs were fun and interesting. The feedback is fast and insightful...I'm not used to that much interaction with an instructor in an asynchronous course!" - Rob
1
2
0
@NetworkDefense
Applied Network Defense
3 years
"If you pay attention and give Investigation Theory its due, you will come out the other side a much better analyst for having taken it."
1
3
3
@bettersafetynet
Mick Douglas 🇺🇦🌻
3 years
@netresec @GuhnooPlusLinux That said, the way meterpreter does TLS is strange, so you can do detection on how it behaves. However, again... this is defaults, you can change the TLS behavior in your payload options and advanced options.
0
1
2
@VictorPPetrov
Victor Petrov
3 years
well, Balkan Cyberia finally has a cover and it is marching robotically towards its publication on the 13th June with @mitpress! It has spies & cyborgs, not just apparatchiks - and will be open access but if you want a copy, there will be a discount code! https://t.co/0yTi1FdbMo
24
66
402
@bettersafetynet
Mick Douglas 🇺🇦🌻
3 years
IMO, BYOD is *the most expensive* cost savings measure ever.
@MalwareJake
Jake Williams
3 years
Lots of CISOs out there rethinking their BYOD policies today. Even if you aren't, your business partners are and you should be expecting TPRM questions about it. #LastPass
3
4
38
@TCMSecurity
TCM Security
3 years
We often get asked how to land a job in cybersecurity. In today's video, Heath discusses the importance of community and giving back as one of the important steps to getting a job in cybersecurity. https://t.co/7ozr8667Mz
3
13
121
@hasherezade
hasherezade
3 years
New release: #PEbear 0.6.5: https://t.co/AsAbJGR9nb - several new features, fixes and improvements - check it out!
19
160
645
@gleeda
Jamie Levy🦉
3 years
I'll be giving a talk next week over my journey into #DFIR and give some tips to help others find their way into this space! #memoryforensics #malware #infosec #infosecurity
@WiCySorg
Women in CyberSecurity (WiCyS)
3 years
The journey into Cybersecurity is not one-size-fits-all but can vary from person to person. In this webinar with @HuntressLabs, Jamie Levy will cover how she found her way into this field and give tips for choosing the right path for you. https://t.co/PxheSf2DTD #WiCyS
1
10
28
@TechEmiiily
P!bbl3
3 years
Assert dominance in your ticket queue by submitting all technical details necessary with screenshot of Hello Kitty terminal.
11
29
233
@OpenSecTraining
OpenSecurityTraining2
3 years
Happy 1st anniversary to @NonprofitCyber!
0
7
29
@SLEUTHCON
SLEUTHCON
3 years
#SLEUTHCON provides cybersecurity newcomers & professionals the opportunity to learn from industry experts in easy-to-follow 30 min talks. Join us online or in Arlington, VA on 5/12! Register today at https://t.co/k217bE6gS0. #cybercrime #infosec #cyberattacks #CTI #ransomware
0
9
5