Using Timesketch for timeline analysis? We recently added a new feature: LLM summaries of up to 500 events in view. Example below uses Gemini Flash, but you can just as easily use a local Ollama model. Setup guide: timesketch.org/guides/user/...
19.06.2025 18:01 — 👍 6 🔁 4 💬 0 📌 1
01.04.2025 02:50 — 👍 92 🔁 12 💬 4 📌 2
That's not that many cabs.
02.04.2025 10:14 — 👍 5 🔁 0 💬 0 📌 0
Well well well, how the turntables...
29.01.2025 10:04 — 👍 4 🔁 0 💬 0 📌 0
Great stuff from @tomchop.me! Memory analysis and Yara support in #OpenRelik
#DFIR
07.01.2025 18:07 — 👍 5 🔁 3 💬 0 📌 0
Demo of the Volatility 3 worker extracting files and plugin output
Demo of the Yara scanner worker showing matches for a dumb DarkComet rule
I had a look at #OpenRelik last year and wrote a couple workers that might be useful:
* github.com/tomchop/open...: Scan memory images using @volatilityfoundation.org plugins. Supports Yara rules
* github.com/tomchop/open... - Run Yara rules on a directory. Supports third-party systems like #Yeti!
07.01.2025 17:18 — 👍 6 🔁 0 💬 0 📌 1
New #OpenRelik release. Task metrics (queue length, completion, failures etc) & new Prometheus exporter. Plus, a new task dashboard for deep dives into task performance.
📝 openrelik.org/changelog/
🔗 discord.gg/hg652gktwX
#DFIR
12.12.2024 11:29 — 👍 4 🔁 1 💬 0 📌 0
This is also the reason I never talk publicly about my dog, any favorite foods, or the season we were in < 3 months ago
12.12.2024 09:00 — 👍 3 🔁 0 💬 0 📌 0
I made this one, which tracks a bunch of infosec-related keywords (and blocks noisy accounts): bsky.app/profile/did:...
04.12.2024 09:46 — 👍 0 🔁 0 💬 0 📌 0
Looks like the kind of manual you could find in The Last of Us that would allow you to upgrade your rifle
29.11.2024 22:59 — 👍 1 🔁 0 💬 0 📌 0
Travel budgets are tight yo
27.11.2024 12:49 — 👍 0 🔁 0 💬 0 📌 0
Looks like shit just got real @swiftonsecurity.com
27.11.2024 12:47 — 👍 8 🔁 0 💬 1 📌 0
if you have a @github.com profile, can i ask you to update it with your @bsky.app handle? 🙏
👉 it enables some very cool integrations, like auto curated feeds and starter packs for contributors and tech
23.11.2024 13:53 — 👍 1012 🔁 208 💬 84 📌 18
“i know bsky is an echo chamber because those echo chamber posts keep coming back around and i know what an echo is”
23.11.2024 14:19 — 👍 0 🔁 0 💬 0 📌 0
There's probably less content than there was on twitter in 2012, but this already feels much nicer and relevant than what X is right now.
21.11.2024 11:44 — 👍 2 🔁 0 💬 0 📌 0
Shiiiiyet, I'm gonna try to not miss this edition! 🤞🏼🤞🏼🤞🏼
19.11.2024 14:35 — 👍 2 🔁 0 💬 0 📌 0
Amazing, thanks! skyfeed.app offers a (less polished, more hacky) similar interface but also allows you to create custom feeds
19.11.2024 09:55 — 👍 2 🔁 0 💬 0 📌 0
*cue pokémon battle song*
"plaso I choose you!!"
18.11.2024 15:24 — 👍 3 🔁 1 💬 0 📌 0
Thanks, this is useful! I also started a feed a long time ago with more generic infosec keywords: bsky.app/profile/did:...
17.11.2024 22:12 — 👍 2 🔁 0 💬 0 📌 0
Thinking of coming up with a Bluesky #DFIR Starter Pack with @the4711.org... who should we include?
15.11.2024 11:07 — 👍 6 🔁 0 💬 2 📌 0
I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission.
The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().
It's RCE, not auth bypass, and gated/unreplayable.
30.03.2024 17:13 — 👍 692 🔁 278 💬 7 📌 15
Today, we published this Field Guide to incident response for civil society and media, which I’ve been working on for the past year or so and which I am pretty excited about internews.org/resource/fie...
28.11.2023 17:39 — 👍 9 🔁 3 💬 0 📌 0
Yes, for sure. Otherwise does the project even exist?? I tried briefly playing a bit with Dall-E but didn't get any satisfying results :(
14.11.2023 12:30 — 👍 1 🔁 0 💬 1 📌 0
We are looking forward to integrating formats such as dfiq.org, shipping tighter integrations with DFIR platform tools like timesketch.org, turbinia.plumbing, and misp-project.org!
14.11.2023 11:47 — 👍 0 🔁 0 💬 0 📌 0
Please feel free to use (and tell us when you do! we love hearing about people's use-cases), file lots of bugs, and feel free to contribute: guides, documentation, even cool screenshots, everything is welcome.
14.11.2023 11:46 — 👍 0 🔁 0 💬 1 📌 0
The changes in the codebase have been massive (remember, it's only 2 people working on this): 480 commits to the API server. 139 commits to the frontend SPA.
14.11.2023 11:46 — 👍 0 🔁 0 💬 1 📌 0
This version marks the start of a focus shift away from classic CTI and towards a platform for DFIR teams wishing to integrate CTI in their pipelines for incident response, threat hunting, and detection, and to be able to collate "forensics intelligence" to share with other teams
14.11.2023 11:45 — 👍 1 🔁 0 💬 1 📌 0
Screenshot of Yeti showing information on the Scattered Spider intrusion set.
This has been years in the making, literally. @Sebdraven and I are happy to announce the release of #Yeti 2.0 (after we promised an EOM release at @hack_lu last month)
Website: yeti-platform.io
Release: github.com/yeti-platform/yeti
mini-🧵👇🏻
#DFIR #infosec #CTI #cybersec
14.11.2023 11:45 — 👍 8 🔁 3 💬 1 📌 0
privacy, game dev, infosec, AI red teaming
https://github.com/StuxnetStudios
British, But In Las Vegas and NYC
ezitron.76 Sig
Newsletter - wheresyoured.at
https://linktr.ee/betteroffline - podcast w/ iheartradio
Chosen by god, perfected by science
CEO at EZPR.com - Award-Winning Tech PR
Journaliste à Mediapart "n'ayant jamais pris place dans une colonne d'assaut" (Cazeneuve), "manipulateur de l'information" (Darmanin). matthieu.suc@mediapart.fr
Cryptographer @ ANSSI (@anssi-fr.bsky.social). Coach for #ECSC #TeamFR. Admin #Hackropole. Posts are my own.
🏛️ https://hackropole.fr
Web App (mostly) Hacker @NetSPI | Cybersecurity Educator | Content Creator | Ex-Brit | Links: http://linktr.ee/tib3rius (he/him) 🇺🇸 A mostly unserious person.
Cybersecurity Researcher and Assist Prof in ČVUT University. Machine Learning. AI. Detection with IDS/IPS in the network. Reinforcement Learning. Agents. Attacking/Defending. DNS. VPNs. Honeypots. Malware analysis.
Wrangling coffee. Hunting CyberChef. Drinking malware. Confusing verbs.
Technologist @ Human Rights Watch (previously Amnesty, Citizen Lab)
Malware, Threats, Online Investigations, Disinformation, Human Rights and silly memes.
On Mastodon: tek@todon.eu
Also on https://maynier.eu/
I do DFIR at Google and I like incident response, threat intelligence, security operations and blue team stuff.
Artist, musician, programmer, game developer. Not necessarily in that order.
Website: https://www.predictable-paul.com
Music: https://paulgreveson.bandcamp.com/
Compte officiel de l'Agence nationale de la sécurité des systèmes d'information (ANSSI) | Retrouvez les alertes de #cybersécurité sur le compte @cert-fr.bsky.social
edtech and digital /cyber strategy/ advisor against tech enabled harm/ domestic abuse #edtech #education #harmreduction she/her
I write songs and make sex jokes
▫ 🏳️🌈 sapphic ⚢ insurgent 🏳️🌈
▫ 100% That Bitch (from Vault 101)
▫ she/her ▫ lesbian ▫ tin•da•zaz•chek
Security Engineer, D&R @Google.
Excelling at mediocrity, I run, make beer and then drink it. 🍻
Opinions are my own. pcap or it didn't happen.
Also, John Muir was the best.
mitmproxy developer, making cloud more secure at Google. TLS, web, networks, and open source.
Mostly active on http://fedi.hi.ls these days, mirroring announcements here.
Security Robot Overlord @ Google.
Vulnerability Management
ProPublica reporter | Email me at joshua.kaplan@propublica.org | Contact info & stories here: propublica.org/people/joshua-kaplan