Daniel Stein (@_danstein) 's Twitter Profile
Daniel Stein

@_danstein

You can't be common, the common man goes nowhere; you have to be uncommon | Security

ID: 249040500

calendar_today08-02-2011 06:58:58

2,2K Tweet

252 Followers

1,1K Following

Gary W. Sullivan II (@gws2) 's Twitter Profile Photo

📣 Attn: Chicago-area college students! 🎓 I’m giving away 1 VIP ticket to THOTCON!, May 19-20! 🎉 Don't miss this opp to attend one of the best hacking confs in the world. DM for entry into giveaway, must be able to prove current enrollment. #thotcon #cybersecurity #hacker

4n6research (@4n6research) 's Twitter Profile Photo

Stroz Friedberg, a LevelBlue company has released a new tool, SIDR, to parse Windows Search Index databases on Windows 10 and 11. Lot of important info in these DBs that's relevant for DFIR cases. github.com/strozfriedberg… #Windows #DFIR #opensource #StrozFriedberg #incidentresponse

Stroz Friedberg DFIR (@strozdfir) 's Twitter Profile Photo

Want to learn more about the #Windows #Registry and our open-source registry parser? Check out Kim Stone and Shane McCulley's talk on "Windows Registry Forensics: There's Always Something New" at the 2023 #SANS #DFIRSummit on Aug 3 sans.org/cyber-security… #DFIR #StrozFriedberg

Stroz Friedberg DFIR (@strozdfir) 's Twitter Profile Photo

Want to gain insights into unique #M365 attack techniques seen in the wild? Be sure to catch John Ailes and Julia Paluch live at the @SansInstitute #DFIRSummit at 6 PM ET. #StrozFriedberg #DFIR Be sure to register and attend here: sans.org/u/1pkc

Want to gain insights into unique #M365 attack techniques seen in the wild? Be sure to catch John Ailes and Julia Paluch live at the @SansInstitute #DFIRSummit at 6 PM ET.

#StrozFriedberg #DFIR

Be sure to register and attend here: sans.org/u/1pkc
Blue Team Con (@blueteamcon) 's Twitter Profile Photo

“Keep the F in DFIR: The Importance of Digital Forensics in Incident Response” with Partha Alwar and Carly Battaile at Blue Team Con 2023.

“Keep the F in DFIR: The Importance of Digital Forensics in Incident Response” with Partha Alwar and Carly Battaile at Blue Team Con 2023.
™ (@c0ntrol_z) 's Twitter Profile Photo

I made some python (an IDA Python and standalone) scripts for analysis of Crytox/.wait ransomware. It deals with resolving the API hashes used by the malware. github.com/w3tmo/CrytoxTo… #DFIR #Malware #Crytox

Daniel Stein (@_danstein) 's Twitter Profile Photo

Race condition during crash dump -> Signing key in crash dump -> Dump makes its way from isolated network to internet-connected debugging environment -> TA compromises engineer with access to debugging environment

Stroz Friedberg DFIR (@strozdfir) 's Twitter Profile Photo

Threat actors always find creative ways to evade detection by security teams. Join Partha Alwar and Mahmoud El Halabi as they take the stage to present their talk, “The Arms Race of Evasion: Evolving Evasion Techniques in Incident Response” at the SANS APAC DFIR Summit tonight

Threat actors always find creative ways to evade detection by security teams. 

Join Partha Alwar and Mahmoud El Halabi as they take the stage to present their talk, “The Arms Race of Evasion: Evolving Evasion Techniques in Incident Response” at the SANS APAC DFIR Summit tonight
Stroz Friedberg DFIR (@strozdfir) 's Twitter Profile Photo

Stroz Friedberg produced a Client Advisory in August 2023 on the financially motivated criminal group #ScatteredSpider (aka Roasted #0Ktapus, #UNC3944). Read our report about their #socialengineering tactics, #reconnaissance, and our recommendations to prevent similar

Stroz Friedberg DFIR (@strozdfir) 's Twitter Profile Photo

More than half of the breaches investigated by Stroz Friedberg DFIR in 2022 included phishing as an initial access technique. Learn more about evolving #phishing techniques in our latest blog where we talk about brand impersonation, consent phishing, and the usage of phishing kits.

More than half of the breaches investigated by <a href="/StrozDFIR/">Stroz Friedberg DFIR</a>  in 2022 included phishing as an initial access technique. Learn more about evolving #phishing techniques in our latest blog where we talk about brand impersonation, consent phishing, and the usage of phishing kits.
Stroz Friedberg DFIR (@strozdfir) 's Twitter Profile Photo

🚨 Dive into our newest blog post: Detecting "Effluence" - an unauthenticated Confluence Web Shell 🕵️ Stroz Friedberg discovers a persistent backdoor installed by threat actors after exploiting Confluence vulnerabilities. This backdoor is accessible remotely without Confluence

🚨 Dive into our newest blog post: Detecting "Effluence" - an unauthenticated Confluence Web Shell
🕵️ Stroz Friedberg discovers a persistent backdoor installed by threat actors after exploiting Confluence vulnerabilities. This backdoor is accessible remotely without Confluence
Stroz Friedberg DFIR (@strozdfir) 's Twitter Profile Photo

🚨 Gain insights into attack patterns observed across several incidents involving #Makop #ransomware Read more: aon.com/cyber-solution… #DFIR #IncidentResponse #Aon #StrozFriedberg

🚨 Gain insights into attack patterns observed across several incidents involving #Makop #ransomware 

Read more: aon.com/cyber-solution…

#DFIR #IncidentResponse #Aon #StrozFriedberg
Molecule (@molecule_dao) 's Twitter Profile Photo

🔮 Introducing Catalyst Quests: Your chance to step into the storied role of a science patron. Engage with cutting-edge research, grow the community, earn XP, and climb the DeSci leaderboard. Step into your legacy 🧙‍♂️⬇️

🔮 Introducing Catalyst Quests: Your chance to step into the storied role of a science patron.

Engage with cutting-edge research, grow the community, earn XP, and climb the DeSci leaderboard.

Step into your legacy  🧙‍♂️⬇️
Molecule (@molecule_dao) 's Twitter Profile Photo

Let's dive into the science! 🤿 There are just 3 days left to support Project Transfidelity! Still not sure how it fits into brain health and longevity? benjels put on his science teacher hat and walked us through the whole project. 🧑‍🏫

benjels (@benjileibo) 's Twitter Profile Photo

Hiring for a Full Stack Solana Dev at Molecule . Come build science at NASDAQ speeds with us. moleculeto.notion.site/Full-Stack-Sol…

Stroz Friedberg DFIR (@strozdfir) 's Twitter Profile Photo

🚀 Exciting Early Careers Opportunity in #DFIR! 🚀 Love solving puzzles? Want to be on the front lines of investigating cyber investigations? Kickstart your career with our Stroz Friedberg Digital Forensics and Incident Response practice! Our Cyber Associate Program is a

Chris Duggan (@tlp_r3d) 's Twitter Profile Photo

🧵 Thread 1/ So you want to track Scattered Spider but Censys and Shodan are just too slow? Here's the cheat sheet! 🕵️‍♂️ Scattered Spider registers their domains using the nameserver ns3.my-ndns[.]com. We can passively monitor this DNS for new domains. 🕸️ Don't have DomainTools

🧵 Thread 1/ So you want to track Scattered Spider but Censys and Shodan are just too slow? Here's the cheat sheet! 🕵️‍♂️

Scattered Spider registers their domains using the nameserver ns3.my-ndns[.]com. We can passively monitor this DNS for new domains. 🕸️

Don't have DomainTools