tomchop_ Profile Banner
tomchop Profile
tomchop

@tomchop_

Followers
5K
Following
4K
Media
177
Statuses
7K

DFIR @Google by day; threat intel and malware analysis by night · BlueTeam (views are my own) · he/him · @[email protected] / @tomchop.bsky.social

Zurich, Switzerland
Joined June 2009
Don't wanna be here? Send us removal request.
@tomchop_
tomchop
3 years
Finally got a https://t.co/CHLAWQwPMC invite code (thanks!) you can find me at https://t.co/XyOYLly5QV I was warned "it's mostly shitposting" and tbh I think that's a good reason to join
0
1
2
@jberggren
Johan Berggren
1 year
Two new OpenRelik workers released today: 1. Hayabusa from @SecurityYamato - Analyze your Windows Event Logs. 2. Timesketch exporter - export your timelines seamlessly. #DFIR #OpenRelik 🧵👇See this thread for screencasts:
4
31
119
@tomchop_
tomchop
1 year
[also, I hear they host a great movie night with carefully curated films - better get ready @Ministraitor / @adulau / @_saadk]
2
0
2
@tomchop_
tomchop
1 year
I'll be speaking about #DFIQ and how to organize all your forensics intelligence at @hack_lu next month! Come join us, it's a cozy conference run by a great team :) (and jeez, what an honor to be a part of this lineup! 🙏🏻)
@hack_lu
hack_lu
1 year
The first version of the #hacklu 2024 agenda is now live. Check it out here: https://t.co/E9vGmCmOLN Don't miss out—join us for this year's edition! #infosec #conference #Luxembourg
1
5
21
@jberggren
Johan Berggren
1 year
🚀Introducing OpenRelik: Open-source platform for digital forensic investigations. Modular workflows, collaboration, central artifact repository and easily extendable to support new tools in a clean, easy to use interface. https://t.co/fnkTwtsXDd
openrelik.org
OpenRelik OpenRelik is an open-source (Apache-2.0) platform designed to streamline collaborative digital forensic investigations. It combines modular workflows for custom investigative processes, an...
6
87
229
@tomchop_
tomchop
1 year
Pour one out for all the operators out there using memory-only implants on their target's networks.
3
27
112
@Jipe_
🇫🇷 Jean-Ph˙ ͜ʟ˙ppe 🇪🇺🇺🇦
1 year
Even genius engineering teams sending rockets that cost billions to space are defeated by character encoding.
1
14
38
@tomchop_
tomchop
1 year
https://t.co/jFRiEUWLIu has now got a new logo! (and stickers to go with, which got here just in time to be handed out at @passthesaltcon). Thanks a lot to @N1aKan for the great artwork 🫶🏼
3
5
27
@tomchop_
tomchop
1 year
Excited to be chatting a bout attacker simulation exercies at @a41con this afternoon! 🕵️ It's the last talk of the last day, in the underground track. So grab a beer (or any drink), come get cozy and chat about how much blue teams and red teams get to have fun together.
1
4
15
@tomchop_
tomchop
1 year
Very glad to be talking about forensics intelligence and our progress with Yeti, Timesketch, and DFIQ at @passthesaltcon !! Looking forward to catch up with everyone at this awesome event! 🤩
@passthesaltcon
Pass the SALT Conference
1 year
Let's dive into our https://t.co/rvRGogVJHI Starting with the #DFIR & TI session: 🚀@xme will speak about automation in hunting ⚒ #Yeti evolution by @tomchop & @Sebdraven 🤔@adulau will bring back RSS for Security + 2 #workshops to 🙌 Book your 🆓🪑 https://t.co/bSzRhVp7AU
2
7
22
@passthesaltcon
Pass the SALT Conference
1 year
Let's dive into our https://t.co/rvRGogVJHI Starting with the #DFIR & TI session: 🚀@xme will speak about automation in hunting ⚒ #Yeti evolution by @tomchop & @Sebdraven 🤔@adulau will bring back RSS for Security + 2 #workshops to 🙌 Book your 🆓🪑 https://t.co/bSzRhVp7AU
0
7
11
@tomchop_
tomchop
2 years
📢 #Yeti is now part of the ODFIR infrastructure automation project! It's never been easier to connect it to a @TimesketchProj instance and enrich all your sketches with juicy forensics intelligence ✨ More details here 👇🏻 https://t.co/mMf5LdG0i5 #DFIR #CTI #Timesketch
1
24
46
@TheDFIRReport
The DFIR Report
2 years
🎉 Announcing DFIR Labs! 🎉 Introducing our DFIR Labs based on real intrusions from our public reports and private threat briefs! Whether you're starting out or looking to deepen your skills, our labs can help. 1/2
1
129
494
@tomchop_
tomchop
2 years
This would never have happened if the backdoor had been written in rust... 🦀 Threat actors take note.
@gcouprie
Geoffroy Couprie
2 years
Someone is going to publish an optimized version of the xz backdoor right? One that does not add 600ms to the SSH login
1
0
2
@softminus
Alex
2 years
software engineers will notice half a second of latency in something that should be ~instant and will move heaven and earth to fix it, or at least to understand why; and this seems to have blown an operation that had started to install a backdoor on every Debian/Ubuntu SSH server
@haxrob
HaxRob
2 years
Plans to literally "hack the planet" foiled due to 500ms of latency that Andres instinctually investigated. The latency was due how the malicious code parsed symbol tables in memory. https://t.co/WNExkhVbTx
52
3K
20K
@rhacklette41
rhacklette
2 years
🚀 Next up on Rhacklette’s calendar: a workshop on Cloud Forensics from @tomchop_ and @cyjkppr 📍 The training will be split into 2 sessions. 1: 24th April 18:30 to 20:30. 2: 26th April 18:30-20:30 This activity is for members only. More info rhacklette@defcon-switzerland.org
1
4
7
@tomchop_
tomchop
2 years
Super excited about this opportunity 🤩
@rhacklette41
rhacklette
2 years
🚀 Next up on Rhacklette’s calendar: a workshop on Cloud Forensics from @tomchop_ and @cyjkppr 📍 The training will be split into 2 sessions. 1: 24th April 18:30 to 20:30. 2: 26th April 18:30-20:30 This activity is for members only. More info rhacklette@defcon-switzerland.org
0
1
8
@rhacklette41
rhacklette
2 years
🚀Our next event will be: Public Speaking, the stuff nobody ever teaches you. 📍The 25th March 18:30-19:30, Zurich, location TBA. This activity is for members only. If you want to join our community you must identify as FINTA. Send an email to rhacklette@defcon-switzerland.org
0
2
4
@Cyb3rWard0g
Roberto Rodriguez 🇵🇪
2 years
🚨 @udgover sharing "Yeti" ! An open-source threat intelligence platform storing data in a graph database. 🔴 Happening now: https://t.co/ZkJhUWI9Xz
0
4
16