Evild3ad79 (@evild3ad79) 's Twitter Profile
Evild3ad79

@evild3ad79

ID: 271308262

calendar_today24-03-2011 07:39:06

4,4K Tweet

1,1K Followers

405 Following

LETHAL FORENSICS (@lethal_dfir) 's Twitter Profile Photo

macos-collector v1.1.0 released today! We have added the collection of Desktop Service Store Files (.DS_Store) and Apple Unified Logs (AUL). Check it out!🚀 github.com/LETHAL-FORENSI…

JPCERT/CC (@jpcert_en) 's Twitter Profile Photo

New Blog Post: YAMAGoya: A Real-time Client Monitoring Tool Using Sigma and YARA Rules blogs.jpcert.or.jp/en/2025/11/YAM…

LETHAL FORENSICS (@lethal_dfir) 's Twitter Profile Photo

We've added four new PowerShell scripts to the MacOS-Analyzer-Suite: - BTM-Analyzer (Persistence) - DSStore-Analyzer - Storyline-Analyzer (Aftermath) - Timeline-Analyzer (Aftermath) Happy Threat Hunting! 🚀 github.com/LETHAL-FORENSI…

LETHAL FORENSICS (@lethal_dfir) 's Twitter Profile Photo

We are pleased to announce the release of macos-collector v1.2.0! We have added support for more macOS Forensic Artifacts and DMG creation to preserve Apple extended attributes.🚀 github.com/LETHAL-FORENSI…

sapir federovsky (@sapirxfed) 's Twitter Profile Photo

My gift for Thanksgiving 💜 I wrote for you the blog post I always wanted to read! Happy holiday!🦃 PLEASE READ IT!!! wiz.io/blog/recent-oa…

LETHAL FORENSICS (@lethal_dfir) 's Twitter Profile Photo

macos-collector v1.3.0 released today! We have added Spotlight Database File Collection (incl. Live Searches) and BTM Database File Collection. Check it out!🚀 #macOS #MacForensics #DFIR #DigitalForensics #incidentresponse github.com/LETHAL-FORENSI…

Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

Been working hard on KnockKnock v4.0 that'll have new persistence enumerations, better VirusTotal integration, & many new community-requested features & improvements! 😍 Want to take a prerelease for a spin? github.com/objective-see/… ...just lmk if anything breaks 😅🙏🏽

Been working hard on KnockKnock v4.0 that'll have  new persistence enumerations, better VirusTotal integration, & many new community-requested features & improvements! 😍

Want to take a prerelease for a spin? github.com/objective-see/…

...just lmk if anything breaks 😅🙏🏽
Objective-See Foundation (@objective_see) 's Twitter Profile Photo

Knock Knock? Who’s there? KnockKnock v4.0 🔍 KnockKnock just turned 10 🥳 and version 4.0 is now out, bringing new features & improvements: 1️⃣ Start at login 2️⃣ Scan comparisons 3️⃣ Better VirusTotal integration 4️⃣ New plugin: Shell configuration files objective-see.org/products/knock…

Knock Knock? Who’s there? KnockKnock v4.0 🔍

KnockKnock just turned 10 🥳 and version 4.0 is now out, bringing new features & improvements:
1️⃣ Start at login
2️⃣ Scan comparisons
3️⃣ Better <a href="/virustotal/">VirusTotal</a> integration 
4️⃣ New plugin: Shell configuration files

objective-see.org/products/knock…
LETHAL FORENSICS (@lethal_dfir) 's Twitter Profile Photo

Just released macos-collector v1.4.0 with the newest version of KnockKnock by Objective-See Foundation. System Information Collection and Recent Items Collection added. Happy macOS Threat Hunting!🚀 github.com/LETHAL-FORENSI…

Arsenal Recon (@arsenalrecon) 's Twitter Profile Photo

A very important announcement for digital forensics practitioners - Swap Recon v1.0.0.14 just released with support for the latest Windows compression format (x64 & Arm) & decompression of corrupt compressed blocks. Take a new look at cold cases? ArsenalRecon.com #DFIR

A very important announcement for digital forensics practitioners - Swap Recon v1.0.0.14 just released with support for the latest Windows compression format (x64 &amp; Arm) &amp; decompression of corrupt compressed blocks. Take a new look at cold cases? ArsenalRecon.com #DFIR
Stephan Berger (@malmoeb) 's Twitter Profile Photo

📢 Hands-On Training: Anti-Forensics (and Anti-Anti-Forensics) Techniques for Incident Responders @ BruCON 2026 I’m excited to announce my upcoming hands-on training at BruCON 2026 in Mechelen. This in-depth technical course is designed for Incident Responders who want to

📢 Hands-On Training: Anti-Forensics (and Anti-Anti-Forensics) Techniques for Incident Responders @ BruCON 2026

I’m excited to announce my upcoming hands-on training at BruCON 2026 in Mechelen. This in-depth technical course is designed for Incident Responders who want to
Matt (@matteturner) 's Twitter Profile Photo

I just published Starship Vector! 🚀 An OS-independent + fast csv data explorer. Built with: 🦀 Tauri 🎨 Tailwind CSS 🦆 DuckDB I’d love for the DFIR community to check it out. I'm looking for feedback! starship.zip #DFIR #CyberSecurity #IncidentResponse #StarshipZip

Renzon (@r3nzsec) 's Twitter Profile Photo

DFIR analysts who use macOS as their daily driver deserve free and native forensic tooling. So I built one. 🍎 Introducing 𝗜𝗥𝗙𝗹𝗼𝘄 𝗧𝗶𝗺𝗲𝗹𝗶𝗻𝗲 — a timeline analysis app built from the ground up for Mac-based DFIR folks, forensic investigators, or SOC analysts. Built in

LETHAL FORENSICS (@lethal_dfir) 's Twitter Profile Photo

We just released macos-collector v1.5.0 with TrueTree Snapshot Collection and a bunch of additional system information. Check it out! 🚀#macOS #MacForensics #DFIR #DigitalForensics #IncidentResponse github.com/LETHAL-FORENSI…

Renzon (@r3nzsec) 's Twitter Profile Photo

One of the biggest pain points for macOS-based DFIR analysts: "I have a raw Master File Table ($MFT) or USN Journal ($J), but I need a Windows VM just to parse it." Not anymore. IRFlow Timeline now imports raw $MFT and $J files directly: a two-pass binary parser extracts 22

LETHAL FORENSICS (@lethal_dfir) 's Twitter Profile Photo

MacOS-Analyzer-Suite v1.2.0 released today! We have added two new PowerShell scripts: - KnockKnock-Analyzer - VirusTotal-Analyzer Happy Threat Hunting! 🚀 #MacForensics #DFIR #DigitalForensics #IncidentResponse #macOS github.com/LETHAL-FORENSI…

13Cubed (@13cubeddfir) 's Twitter Profile Photo

🎉 It’s time for a new 13Cubed episode! For macOS forensics, Fuji from Andrea Lazzarotto is a must-have. This episode is an excerpt from Investigating macOS Endpoints and covers the latest version, with major new changes. Let’s walk through a live acquisition! youtube.com/watch?v=9ZkLdF…