Jipe's Avatar

Jipe

@cyberjipe.bsky.social

I fix accepted risks. Incident Response & Purple Teaming @ CrowdStrike. Previously DFIR @ANSSI_FR / @CERT_FR. Former @CertSG team leader.

96 Followers  |  101 Following  |  15 Posts  |  Joined: 16.11.2024
Posts Following

Posts by Jipe (@cyberjipe.bsky.social)

Preview
How Russiaโ€™s War Has Devastated Civilian Life in Ukraine - bellingcat Russia's full-invasion of Ukraine began four years ago today. While Ukraine has resisted, the impact on civilian life continues to be severe.

Exactly four years since Russiaโ€™s full-scale invasion of Ukraine, Bellingcatโ€™s Volunteer Community looks back at the data we have collected on civilian harm during this time - documenting attacks on cities and the near-total destruction of rural villages. www.bellingcat.com/news/2026/02...

24.02.2026 09:20 โ€” ๐Ÿ‘ 728    ๐Ÿ” 293    ๐Ÿ’ฌ 4    ๐Ÿ“Œ 9
Preview
Russiaโ€™s Matryoshka bots begin Epstein-themed disinfo campaign, focusing false claims against Ukraine and France The Kremlin-linked bot network known as โ€œMatryoshkaโ€ has launched a disinformation campaign following the release by the U.S. Justice Department of new documents in the case of Jeffrey Epstein.The cam...

Russiaโ€™s Matryoshka bots begin Epstein-themed disinfo campaign, focusing false claims against Ukraine and France
theins.press/en/news/289109

06.02.2026 08:20 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
GitHub - tomchop/volatility3-autoruns: Autoruns plugin for the Volatility3 framework Autoruns plugin for the Volatility3 framework. Contribute to tomchop/volatility3-autoruns development by creating an account on GitHub.

I rarely post here, but when I do... I just updated my Volatility autoruns plugin to be compatible with Volatility 3 (long overdue!) Here's the goodies: github.com/tomchop/vola... #dfir #forensics #cybersecurity

25.01.2026 09:18 โ€” ๐Ÿ‘ 14    ๐Ÿ” 4    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

We are alarmed by reports that Germany is on the verge of a catastrophic about-face, reversing its longstanding and principled opposition to the EUโ€™s Chat Control proposal which, if passed, could spell the end of the right to privacy in Europe. signal.org/blog/pdfs/ge...

03.10.2025 16:14 โ€” ๐Ÿ‘ 3975    ๐Ÿ” 2408    ๐Ÿ’ฌ 40    ๐Ÿ“Œ 140

Qilin targeting a French critical infrastructure again.

01.10.2025 17:15 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Salesloftโ€“Drift Breach: An Attack Path Case Study - SpecterOps This post analyzes the Salesloftโ€“Drift incident through an attack path lens, showing how violations of the clean source principle, identities in transit, and hidden hybrid paths combined to turn a sin...

It's time to change how you think about SaaS integrations.

The Salesloft attack shows how GitHub โ†’ AWS โ†’ Drift โ†’ Salesforce created an attack highway defenders never saw coming.

Jared Atkinson's analysis details the patterns we should look out for. ghst.ly/4ngDQrD

24.09.2025 17:53 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
4 research institute march together hand in hand for diversity and inclusion in science ยฉ Franck Aubry

4 research institute march together hand in hand for diversity and inclusion in science ยฉ Franck Aubry

ยฉ Franck Aubry

ยฉ Franck Aubry

ยฉ Franck Aubry

ยฉ Franck Aubry

๐ŸŒˆ United for diversity in science ๐ŸŒˆ
Researchers from Institut Pasteur joined the 2025 Pride March alongside @institutcurie.bsky.social, Les Cordeliers Research Center, @institutcochin.bsky.social @institutimagine.bsky.social

๐Ÿ‘ฉโ€๐Ÿ”ฌ Because diverse labs make better science.
#DiversityInScience

30.06.2025 12:36 โ€” ๐Ÿ‘ 50    ๐Ÿ” 20    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 2
Preview
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.

North Koreans reportedly host fake Zoom meeting featuring multiple deepfake colleagues. Targetโ€™s microphone doesnโ€™t work so the colleagues talk them through installing malicious fix. www.huntress.com/blog/inside-...

19.06.2025 10:41 โ€” ๐Ÿ‘ 20    ๐Ÿ” 9    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

La Sociรฉtรฉ Gรฉnรฉrale revient sur le TT, je crois qu'il y a des bons profils ร  recruter au CERT :) #JUSTSayin

19.06.2025 19:05 โ€” ๐Ÿ‘ 7    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

French scams over SMS now requiring human interactions likely to protect from automated remediation and better identify vulnerable targets

13.06.2025 09:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Update: Dumping Entra Connect Sync Credentials Recently, Microsoft changed the way the Entra Connect Connect Sync agent authenticates to Entra ID. These changes affect attacker tradecraft, as we can no longer export the sync account credentialsโ€ฆ

New tricks, same impact
posts.specterops.io/update-dumpi...

09.06.2025 18:21 โ€” ๐Ÿ‘ 6    ๐Ÿ” 7    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Mapping Hidden Alliances in Russian-Affiliated Ransomware

dti.domaintools.com/mapping-hidd...

08.06.2025 11:05 โ€” ๐Ÿ‘ 21    ๐Ÿ” 8    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
ะ”ะตั€ะถะฐะฒะฝะฐ ัะปัƒะถะฑะฐ ัะฟะตั†ั–ะฐะปัŒะฝะพะณะพ ะทะฒโ€™ัะทะบัƒ ั‚ะฐ ะทะฐั…ะธัั‚ัƒ ั–ะฝั„ะพั€ะผะฐั†ั–ั— ะฃะบั€ะฐั—ะฝะธ ะ’ะตะฑัะฐะนั‚ ะ”ะตั€ะถะฐะฒะฝะพั— ัะปัƒะถะฑะธ ัะฟะตั†ั–ะฐะปัŒะฝะพะณะพ ะทะฒโ€™ัะทะบัƒ ั‚ะฐ ะทะฐั…ะธัั‚ัƒ ั–ะฝั„ะพั€ะผะฐั†ั–ั— ะฃะบั€ะฐั—ะฝะธ

cip.gov.ua/ua/news/anal...
Ukrainian CERT published a synthesis on 3 years of war time defensive activity that is well worth reading.

24.05.2025 23:22 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows Flock, which has license plate readers (LPRs) all around the country, wants police to be able to โ€œjump from LPR to person,โ€ according to leaked audio obtained by 404 Media.

New from 404 Media: Flock, the license plate reader company that has cameras all across the U.S., is now building a massive people lookup tool using hacked data. The plan is to "jump from LPR to person." Won't require a warrant. This is according to leak we obtained.

www.404media.co/license-plat...

14.05.2025 13:57 โ€” ๐Ÿ‘ 608    ๐Ÿ” 337    ๐Ÿ’ฌ 25    ๐Ÿ“Œ 67
Post image

This DTEX report on North Korea's hacking capabilities, along with Viginum's Russian info op report from last week, are probably the best reports of the year so far

You MUST read it!

PDF: reports.dtexsystems.com/DTEX-Exposin...

15.05.2025 08:52 โ€” ๐Ÿ‘ 22    ๐Ÿ” 12    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Announcing the Official Parity Release of Volatility 3! Visit the post for more.

We are very excited to announce that Volatility 3 has reached parity with Volatility 2! With this achievement, Volatility 2 is now deprecated. See the full details in our blog post: volatilityfoundation.org/announcing-t...

16.05.2025 14:56 โ€” ๐Ÿ‘ 26    ๐Ÿ” 13    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 3

Let me know should you need to test on another system.

16.05.2025 19:32 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
PS C:\Users\Administrator> Get-AADIntSyncCredentialsUnable to get sync credent - Pastebin.com Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.

@drazuread.com Hi, Entra Connect Sync now uses a MSA account for its service by default. Is Get-LSASecrets handling MSA accounts already or just gMSA?
AD sync itself is still performed by a MSOL_ account.
Thank you!
AADInternals 0.9.8
Microsoft Entra Connect Sync 2.4.131.0
pastebin.com/UU4u7YZR

11.05.2025 08:24 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Dear Americans, what have you doneโ€ฆ

28.02.2025 22:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx

In our latest article, @croco_byte proposes an implementation of a trick discovered by James Forshaw in his research regarding Kerberos relaying. Discover how to perform pre-authenticated Kerberos relay over HTTP with our Responder and krbrelayx pull requests!
www.synacktiv.com/publications...

27.01.2025 12:06 โ€” ๐Ÿ‘ 16    ๐Ÿ” 12    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
Active Directory Hardening Series - Part 4 โ€“ Enforcing AES for Kerberos | Microsoft Community Hub Disabling Kerberos RC4 is a top priority for many organizations today but identifying devices that don't support AES has been very challenging.  In this...

ยซย Active Directory Hardening Series - Part 4 โ€“ Enforcing AES for Kerberosย ยป techcommunity.microsoft.com/blog/coreinf...

23.02.2025 09:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

ยซย LSA SECRETS: REVISITING SECRETSDUMPย ยป by @synacktiv.com www.synacktiv.com/lsa-secrets-...

23.02.2025 09:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Everyone knows your location How I tracked myself down using leaked location data in the in-app ads, and what I found along the way.

An eye-opening blog post on ads-based tracking: ยซย Everyone knows your location: tracking myself down through in-app adsย ยป timsh.org/tracking-mys...

01.02.2025 12:04 โ€” ๐Ÿ‘ 9    ๐Ÿ” 7    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Windows Recycle Bin - The known and the unknown This is my blog about topics in the field of digital forensics.

Windows Recycle Bin - The known and the unknown bebinary4n6.blogspot.com/2025/01/wind...

21.01.2025 21:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - AlbinoGazelle/esxi-testing-toolkit: ๐Ÿงฐ ESXi Testing Tookit is a command-line utility designed to help security teams test ESXi detections. ๐Ÿงฐ ESXi Testing Tookit is a command-line utility designed to help security teams test ESXi detections. - AlbinoGazelle/esxi-testing-toolkit

github.com/AlbinoGazell...

18.01.2025 14:53 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
ADFSโ€Šโ€”โ€ŠLiving in the Legacy of DRS Itโ€™s no secret that Microsoft have been trying to move customers away from ADFS for a while. Short of slapping a โ€œdeprecatedโ€ label on itโ€ฆ

Achievement unlocked, my first blog with SpecterOps ๐Ÿค— This post looks at ADFS OAuth2 support, Device Registration, Enterprise PRT, and a brain dump of things that I didnโ€™t want to leave sat on Notion. buff.ly/4j41VQU

07.01.2025 14:33 โ€” ๐Ÿ‘ 36    ๐Ÿ” 18    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 1
Preview
Michael Kirchner on LinkedIn: API keys of AWS IAM users are often used when on-prem systems need toโ€ฆ | 14 comments API keys of AWS IAM users are often used when on-prem systems need to connect to your AWS environment. They are difficult to replace (you need some form ofโ€ฆ | 14 comments on LinkedIn

Leaked API keys is a huge issue. GitHub detects around 7,000 tokens in public repos **every month**! www.linkedin.com/feed/update/...

22.12.2024 10:15 โ€” ๐Ÿ‘ 0    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Could anyone in this business explain to me how a random app can share PII with 800+ companies?

16.12.2024 12:27 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

New #AADInternals version is finally out now:
โ–ช Moved endpoint related stuff to new module: AADInternals-Endpoints
โ–ช Added blue team stuff
โ–ช Added red team stuff

See full change log at: aadinternals.com/aadinternals...

10.12.2024 16:53 โ€” ๐Ÿ‘ 44    ๐Ÿ” 21    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 2