tomchop
@tomchop_
Followers
5K
Following
4K
Media
177
Statuses
7K
DFIR @Google by day; threat intel and malware analysis by night · BlueTeam (views are my own) · he/him · @[email protected] / @tomchop.bsky.social
Zurich, Switzerland
Joined June 2009
Finally got a https://t.co/CHLAWQwPMC invite code (thanks!) you can find me at https://t.co/XyOYLly5QV I was warned "it's mostly shitposting" and tbh I think that's a good reason to join
0
1
2
Two new OpenRelik workers released today: 1. Hayabusa from @SecurityYamato - Analyze your Windows Event Logs. 2. Timesketch exporter - export your timelines seamlessly. #DFIR #OpenRelik 🧵👇See this thread for screencasts:
4
31
119
[also, I hear they host a great movie night with carefully curated films - better get ready @Ministraitor / @adulau / @_saadk]
2
0
2
I'll be speaking about #DFIQ and how to organize all your forensics intelligence at @hack_lu next month! Come join us, it's a cozy conference run by a great team :) (and jeez, what an honor to be a part of this lineup! 🙏🏻)
The first version of the #hacklu 2024 agenda is now live. Check it out here: https://t.co/E9vGmCmOLN Don't miss out—join us for this year's edition! #infosec #conference #Luxembourg
1
5
21
🚀Introducing OpenRelik: Open-source platform for digital forensic investigations. Modular workflows, collaboration, central artifact repository and easily extendable to support new tools in a clean, easy to use interface. https://t.co/fnkTwtsXDd
openrelik.org
OpenRelik OpenRelik is an open-source (Apache-2.0) platform designed to streamline collaborative digital forensic investigations. It combines modular workflows for custom investigative processes, an...
6
87
229
Pour one out for all the operators out there using memory-only implants on their target's networks.
3
27
112
Even genius engineering teams sending rockets that cost billions to space are defeated by character encoding.
1
14
38
We start day 1 with a dfir & threat Intel session. First, @tomchop_ and @Sebdraven are introducing Yeti. #pts24
https://t.co/pY16CuW9FR
github.com
Your Everyday Threat Intelligence. Contribute to yeti-platform/yeti development by creating an account on GitHub.
2
9
15
Listening to @tomchop_ and @Sebdraven at @passthesaltcon talking about: #Yeti - towards a #Forensics Intelligence Platform https://t.co/fCd1Ioo76M
#pts24
cfp.pass-the-salt.org
Yeti was initially created in 2017, when a very operational french financial CERT had the need for managing threat-intelligence related indicators. When responding to incidents, they wanted quick...
0
2
5
https://t.co/jFRiEUWLIu has now got a new logo! (and stickers to go with, which got here just in time to be handed out at @passthesaltcon). Thanks a lot to @N1aKan for the great artwork 🫶🏼
3
5
27
Excited to be chatting a bout attacker simulation exercies at @a41con this afternoon! 🕵️ It's the last talk of the last day, in the underground track. So grab a beer (or any drink), come get cozy and chat about how much blue teams and red teams get to have fun together.
1
4
15
Very glad to be talking about forensics intelligence and our progress with Yeti, Timesketch, and DFIQ at @passthesaltcon !! Looking forward to catch up with everyone at this awesome event! 🤩
Let's dive into our https://t.co/rvRGogVJHI Starting with the #DFIR & TI session: 🚀@xme will speak about automation in hunting ⚒ #Yeti evolution by @tomchop & @Sebdraven 🤔@adulau will bring back RSS for Security + 2 #workshops to 🙌 Book your 🆓🪑 https://t.co/bSzRhVp7AU
2
7
22
Let's dive into our https://t.co/rvRGogVJHI Starting with the #DFIR & TI session: 🚀@xme will speak about automation in hunting ⚒ #Yeti evolution by @tomchop & @Sebdraven 🤔@adulau will bring back RSS for Security + 2 #workshops to 🙌 Book your 🆓🪑 https://t.co/bSzRhVp7AU
0
7
11
📢 #Yeti is now part of the ODFIR infrastructure automation project! It's never been easier to connect it to a @TimesketchProj instance and enrich all your sketches with juicy forensics intelligence ✨ More details here 👇🏻 https://t.co/mMf5LdG0i5
#DFIR #CTI #Timesketch
1
24
46
🎉 Announcing DFIR Labs! 🎉 Introducing our DFIR Labs based on real intrusions from our public reports and private threat briefs! Whether you're starting out or looking to deepen your skills, our labs can help. 1/2
1
129
494
software engineers will notice half a second of latency in something that should be ~instant and will move heaven and earth to fix it, or at least to understand why; and this seems to have blown an operation that had started to install a backdoor on every Debian/Ubuntu SSH server
Plans to literally "hack the planet" foiled due to 500ms of latency that Andres instinctually investigated. The latency was due how the malicious code parsed symbol tables in memory. https://t.co/WNExkhVbTx
52
3K
20K
🚀Our next event will be: Public Speaking, the stuff nobody ever teaches you. 📍The 25th March 18:30-19:30, Zurich, location TBA. This activity is for members only. If you want to join our community you must identify as FINTA. Send an email to rhacklette@defcon-switzerland.org
0
2
4
🚨 @udgover sharing "Yeti" ! An open-source threat intelligence platform storing data in a graph database. 🔴 Happening now: https://t.co/ZkJhUWI9Xz
0
4
16