
Nasreddine Bencherchali
@nas_bench
Followers
11K
Following
24K
Media
1K
Statuses
8K
Detection @Splunk & @cisco | previously @nextronsystems | @sigma_hq & @magicswordio maintainer | Eternal Learner
HAL
Joined August 2011
RT @33y0re: I cleaned up the code I have been working on for the last few days into a tool I’m calling “Vtl1Mon”!. Vtl1Mon traces VTL 1 ent….
github.com
Virtual Trust Level (VTL 1) secure call tracing. Contribute to connormcgarr/Vtl1Mon development by creating an account on GitHub.
0
52
0
Because I and the rest of the maintainer team we dont have infinite time. I'm going to be pretty aggressive on PRs submitted to @sigma_hq New so called DEs copy pasting random rules and not having the capacity to read the specs will lead to an auto close.
github.com
Main Sigma Rule Repository. Contribute to SigmaHQ/sigma development by creating an account on GitHub.
3
5
37
A gentle reminder that comes with every threat report that gets released. You can catch the 80% by focusing on Lolbins and using what's called "brittle rules".
nasbench.medium.com
I never played poker so don’t quote me on that
1
19
74
RT @timb_machine: A little something I'm working on. Telemetry sources for telecomms infrastructure.
infosec.exchange
Playing with a matrix of detection telemetry sources mapped against infrastructure components and then against public guidance on what to monitor etc. It's interesting to see quite how patchy the...
0
9
0
RT @M_haggis: 🔥💻 New tool drop! Meet MSIXBuilder 🎁 — the ultimate MSIX package creator for security testing, red team ops, and detection en….
0
39
0
RT @_JohnHammond: I FINALLY got a chance to chat with James Kettle @albinowax and hear about his latest research, with a cool caption "HTTP….
0
43
0
RT @33y0re: You can trace calls to VslpEnterIumSecureMode ("enter/exit" into VTL 1) through the (the value is undocumented?) PERF_VTL1_ENTE….
0
19
0
RT @cyb3rops: People on here act like someone decides not to patch. Like there’s a guy who knows the service is vulnerable, knows it runs i….
0
108
0
RT @HackingLZ: Since lots of people turned AI or better yet just LLMs into a religion/cult, it gets lost that while AI can and will be impa….
0
8
0
RT @TeamCherryGames: Hollow Knight: Silksong will be available September 4 on all platforms and day one on Xbox Game Pass!. Watch the relea….
0
21K
0
RT @Wietze: Windows Defender blocks any procdump execution referencing "lsass" on the command line (1️⃣). Simply querying lsass' process ID….
0
140
0
RT @TeamCherryGames: The countdown is on!. Join us in 48 hours for a special announcement about Hollow Knight: Silksong!. Premiering here:….
0
33K
0
RT @anton_chuvakin: Just heard a new comical take on #SIEM and AI agents: "I do not need a SIEM . because I can just ask the agent to GO….
0
11
0