vikas891 Profile Banner
Vikas Singh Profile
Vikas Singh

@vikas891

Followers
469
Following
518
Media
96
Statuses
284

I do DF/IR @KrollWire GX-IH. GCIH. GCFA. Lethal Forensicator. DFIR Netwars Champion.

Ahmedabad, India
Joined January 2012
Don't wanna be here? Send us removal request.
@vikas891
Vikas Singh
2 years
dude 😐
Tweet media one
0
0
1
@vikas891
Vikas Singh
2 years
Thank you for the feature πŸ€—πŸ«‚.
@phillmoore
Phill Moore
2 years
Week 04 - 2024 #DFIR.
0
0
2
@grok
Grok
5 days
What do you want to know?.
397
240
2K
@vikas891
Vikas Singh
2 years
RT @RusEmbIndia: Happy Republic Day, #India! . From Russia with love ❀️. #RepublicDay2024 #RussiaIndia #Π΄Ρ€ΡƒΠΆΠ±Π°ΰ€¦ΰ₯‹ΰ€Έΰ₯ΰ€€ΰ₯€
0
4K
0
@vikas891
Vikas Singh
2 years
It's a really nice initiative, Phil! I have some ideas, I can't wait to contribute. Also, thank you for the mention πŸ˜‰.
@phillmoore
Phill Moore
2 years
I made a thing, based on the excellent work of other people and some of my own experience. It's ok for a v1, but it still needs work to make it more useful. I'm still learning proper source management, so it's a start. #DFIR.
0
0
2
@vikas891
Vikas Singh
2 years
RT @EricRZimmerman: @SwiftOnSecurity if youve never tried EVTXECmd for event logs, try it. take your favorite logs, generate CSV, load into….
0
1
0
@vikas891
Vikas Singh
2 years
Instead of selecting the Hive along with transaction logs, saving them as System_Clean, do this instead. Select the Hive. Hold Shift while clicking on Open! .@chad πŸ‘ˆπŸ‘€ .Tool: Reg Explorer by @EricRZimmerman
Tweet media one
1
0
2
@vikas891
Vikas Singh
2 years
@techyteachme πŸ‘€.
0
0
0
@vikas891
Vikas Singh
2 years
Interested in Cloud Forensics? .Check out my latest blogpost which walks you through a simulated breach within an AWS environment. We'll ingest AWS CoudTrail in Splunk and run queries - it's all free and exciting! πŸ‘€.#FOR509 @PwnedLabs .
Tweet card summary image
vikas-singh.notion.site
Introduction
1
8
29
@vikas891
Vikas Singh
2 years
Another interesting JS. The end goal looks like #Remcos RAT but unsure if this family has been analyzed . yet. Good de-obfuscation practice today!.🎯Clever masking of all stages.🎯Everything being done in-memory
Tweet media one
Tweet media two
Tweet media three
1
0
2
@vikas891
Vikas Singh
2 years
Interesting sample off VT. >TA tries to blend in by registering SubmitTelem.exe as a service called "Sophos Update Service" <- clever, difficult to spot. >Forcibly hides the service using clever techniques.>Looks like a backdoor written in Go - can't find the project anymore πŸ‘€
Tweet media one
0
0
5
@vikas891
Vikas Singh
2 years
Tweet media one
0
0
2
@vikas891
Vikas Singh
2 years
In hindsight, it should've been the first place you looked.
1
0
3
@vikas891
Vikas Singh
2 years
Pretty excited to announce my 11 Year workiversary by smashing the πŸ‘‘ of IR certifications out there. 25 Practical Questions mimicking real world scenarios. I so wanted to choose GX-CS because it looked easier 😐 but switched to GX-IH!.@CertifyGIAC πŸ‘€DM for Coupon Collab maybe?
Tweet media one
2
0
6
@vikas891
Vikas Singh
2 years
🫑.
@Sophos
Sophos
2 years
Peter Mackenzie, Director of Incident Response, shares details on the MOVEIt software exploit, how to protect against #SupplyChain attacks and more on @BBCNews:
0
0
0
@vikas891
Vikas Singh
2 years
I made the list! Thank you Zack πŸ₯Ί πŸ‘‰πŸ‘ˆ.
0
0
2
@vikas891
Vikas Singh
2 years
If you'd like to give your knowledge a slight push in the world of Browser Extensions, please go through my latest article which scratches the surface on this topic. Microsoft DfE/SentinelOne examples within. #DFIR .
Tweet media one
0
9
35
@vikas891
Vikas Singh
2 years
DFIR nerds, here's a helpful bookmark for you. Remote Access Software (ab)used by adversaries. Of course the list is looong, but we have to start somewhere, right? .. @MITREattack T1219
Tweet media one
0
0
2
@vikas891
Vikas Singh
3 years
Malware Persistence? .Windows Scheduled Tasks ↔ Linux Cronjobs. A quick refresher attached from a Live case. You can also grep your way through to which user had it installed if it isn't a system-wide job. @SentinelOne Terminal Color Scheme βœ”πŸ‘‘
Tweet media one
0
1
4
@vikas891
Vikas Singh
3 years
I wrote my first KAPE Module! It parses Windows Tasks XMLs recursively to give you a neat CSV as an output!.Read: Happy Holidays πŸŽ„πŸŽ….#forensics
Tweet media one
0
4
10
@vikas891
Vikas Singh
3 years
Sneaky of @NotionHQ to give this option only when you open a Code block's Menu πŸ˜‚
Tweet media one
0
0
2