Antonio Sanz(@antoniosanzalc) 's Twitter Profileg
Antonio Sanz

@antoniosanzalc

Fighting evil 24x7. Incident Response & Digital Forensic guy, infosec maniac... and a damn good cook. My team is blue #DFIR - [email protected]

ID:96160040

linkhttp://www.securityartwork.es calendar_today11-12-2009 16:41:16

8,1K Tweets

8,7K Followers

116 Following

Yogesh Khatri(@SwiftForensics) 's Twitter Profile Photo

If you've had this problem (see pic), NTFS Journal REWIND solves it! . New blog post + code. No more unknown paths.
cybercx.com.au/blog/ntfs-usnj…

If you've had this problem (see pic), NTFS Journal REWIND solves it! . New blog post + code. No more unknown paths. cybercx.com.au/blog/ntfs-usnj… #NTFS #DFIR
account_circle
Matt Zorich(@reprise_99) 's Twitter Profile Photo

Microsoft Graph Activity Logs are out of public preview and now generally available. These have quickly become one of my favourite log sources for both detections and investigations, some guidance and example hunting queries here - techcommunity.microsoft.com/t5/microsoft-e…

account_circle
Antonio Sanz(@antoniosanzalc) 's Twitter Profile Photo

Pensamiento polémico del día: no se busca tan bien como en un SIEM, pero en un Linux con syslog y 4 discos SATA de 4Tb en RAID5 te caben MUCHOS logs (más todavía si los comprimes, el texto se reduce a un 10%). Y los puedes buscar con zfgrep... y los te querremos mucho!! 😉

account_circle
Antonio Sanz(@antoniosanzalc) 's Twitter Profile Photo

Lina has been kickin' ass with her DFIR blog posts for a long time... So definitely my team WILL play these labs and ENJOY them (I hope so UwU) 🥳

account_circle
Lukas Beran(@lukasberancz) 's Twitter Profile Photo

Microsoft Entra ID Token Protection is a security feature within Microsoft Entra's Conditional Access that aims to mitigate token theft by ensuring that a token can only be used from the device it was issued to. This is achieved through a process called token binding, which…

Microsoft Entra ID Token Protection is a security feature within Microsoft Entra's Conditional Access that aims to mitigate token theft by ensuring that a token can only be used from the device it was issued to. This is achieved through a process called token binding, which…
account_circle
CCN-CERT(@CCNCERT) 's Twitter Profile Photo

Las Jornadas arrancan mañana, 10 de abril, con récord histórico de inscripciones 🇵🇦
🌐 Más información jornadas.ccn-cert.cni.es/es/ivjornada-p…

Las Jornadas #STICPANAMÁ arrancan mañana, 10 de abril, con récord histórico de inscripciones 🇵🇦 🌐 Más información jornadas.ccn-cert.cni.es/es/ivjornada-p…
account_circle
Antonio Sanz(@antoniosanzalc) 's Twitter Profile Photo

Si quieres conseguir un curro en , aquí tienes una idea de lo que te pueden preguntar en una entrevista. |!Muy muy muy útil!

account_circle
Antonio Sanz(@antoniosanzalc) 's Twitter Profile Photo

Este viernes 12 de 17 a 19h estaré en el Ada Byron de Universidad Zaragoza (Aula A12) dando un taller de Cyberchef ¿Te vienes a 'cocinar' malware, logs y otras deliciosas recetas de ?

Este viernes 12 de 17 a 19h estaré en el Ada Byron de @unizar (Aula A12) dando un taller de Cyberchef ¿Te vienes a 'cocinar' malware, logs y otras deliciosas recetas de #ciberseguridad?
account_circle
Ana Nieto(@cadirneca) 's Twitter Profile Photo

Mañana 10:30🇵🇦 / 17:30 🇪🇸, participaré en las IV Jornadas STIC & Congreso /RootedCON Capítulo Panamá
para hablar de 👇👇👇

Mañana 10:30🇵🇦 / 17:30 🇪🇸, participaré en las IV Jornadas STIC & Congreso @rootedcon Capítulo Panamá #STICPANAMÁ para hablar de #ransomware👇👇👇
account_circle
Evild3ad79(@Evild3ad79) 's Twitter Profile Photo

Check out my new project Microsoft-Analyzer-Suite (Community Edition). A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID extracted by Microsoft-Extractor-Suite. Invictus Incident Response
github.com/evild3ad/Micro…

account_circle
Bastien Cacace(@skisedr) 's Twitter Profile Photo

L’ vient de publier un guide formidable sur la sécurisation de l’administration de l’ portant notamment sur le tiering. Un must-read. Bravo pour ce boulot 👏

cyber.gouv.fr/sites/default/…

account_circle
Placing the Suspect Behind the Keyboard(@PSBK2E) 's Twitter Profile Photo

The clock started on the book launch! If the order page is up, then there are books left :)

Order on Amazon or via this book launch at half price including shipping/handling at:
suspectbehindthekeyboard.com/pl/2148302359

account_circle
DFIR Diva(@DfirDiva) 's Twitter Profile Photo

Placing the Suspect Behind the Keyboard: DFIR Investigative Mindset by Brett Shavers 🙄 is now available on Amazon!

UPDATE: Brett will adding a deal soon so wait a day before purchasing

I had the opportunity to be a beta reader for this book and I highly recommend it to both…

Placing the Suspect Behind the Keyboard: DFIR Investigative Mindset by @Brett_Shavers is now available on Amazon! UPDATE: Brett will adding a deal soon so wait a day before purchasing I had the opportunity to be a beta reader for this book and I highly recommend it to both…
account_circle
Stephan Berger(@malmoeb) 's Twitter Profile Photo

I 💙 xlsxgrep. Here, I'm searching for Bitcoin addresses in a bunch of Excel files:

xlsxgrep -i -P ^(bc1|[13])[a-zA-HJ-NP-Z0-9]{25,39}$ *

'xlsxgrep is a CLI tool to search text in XLSX, XLS, CSV, TSV and ODS files. It works similarly to Unix/GNU Linux grep.' [1]

Go and get it:…

I 💙 xlsxgrep. Here, I'm searching for Bitcoin addresses in a bunch of Excel files: xlsxgrep -i -P ^(bc1|[13])[a-zA-HJ-NP-Z0-9]{25,39}$ * 'xlsxgrep is a CLI tool to search text in XLSX, XLS, CSV, TSV and ODS files. It works similarly to Unix/GNU Linux grep.' [1] Go and get it:…
account_circle