ThreatHuntersForge (@huntersforge) 's Twitter Profile
ThreatHuntersForge

@huntersforge

Data Science, Threat Hunting & Open Source Projects 🍻 Founders: @Cyb3rward0g @Cyb3rPandaH

ID: 1177375313589940224

calendar_today27-09-2019 00:12:09

21 Tweet

1,1K Followers

2 Following

Jose Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rpandah) 's Twitter Profile Photo

Feel free to join the ThreatHuntersForge public slack πŸ€—πŸ’œ and let's continue building and empowering our community TOGETHER!! #ThreatHunting Roberto Rodriguez πŸ‡΅πŸ‡ͺ launchpass.com/threathunting πŸΉβš”οΈπŸ»πŸ’œ

Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

Happy to release Part II: Shipping ETW events toΒ THE-HELK from the Threat Hunting with ETW events and HELK series! Also, releasing the Mordor Erebor 🐲environment to collect ETW events for new datasets! πŸ‘ΏπŸ“œ #ThreatHunting ThreatHuntersForge @Mordor_Project medium.com/threat-hunters…

Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

Jose Rodriguez πŸ‡΅πŸ‡ͺ & I had so much fun ATT&CK #ATTACKcon sharing our research w/ Project Jupyter notebooks , Binder Team , ThreatHunter-Playbook βš”οΈ & @Mordor_Project #ThreatHunting Talk: youtube.com/watch?v=L3KxKA… Slides: speakerdeck.com/cyb3rward0g/re… BinderHub Demo: youtu.be/mQZFHbnDH4A

Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

I always wondered how I could share #ThreatHunting detections via Project Jupyter notebooks in a more practical and interactive way so that anyone in 🌎 can reproduce the research! Thx to Binder Team πŸ’œ ThreatHunter-Playbook @Mordor_Project it is now possible medium.com/threat-hunters…

Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

Interested in learning about what you can do with STIX/TAXII 2.0 APIs and some Python 🐍 code? I created a new function for the attackcti Python library to automate the creation of ATT&CK Navigator group layer files πŸ˜ŠπŸ»πŸŒŽπŸ’œ and shared the process medium.com/threat-hunters…

Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

I decided to write a book πŸ˜…! An online Interactive Book πŸ’₯! A book on the top of ThreatHunter-Playbook , Project Jupyter #notebooks and w/ Binder Team BinderHub links all put together w/ the amazing Jupyter Book project! #ThreatHunting Merry Christmas πŸŽ„πŸŽ 🍻 medium.com/threat-hunters…

Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

Looking for anything to do while you wait for 2020 πŸŽ‰? I just created a Jupyter Book for the @Mordor_Project ! You can now explore mordor datasets w/ Project Jupyter #notebooks via BinderHub 🌎 Pre #ThreatHunting activities for 2020 🍻🀣! New Site: mordordatasets.com

Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

🚨πŸ’₯ Registration for the first community Infosec Jupyterthon is open! Also, check the current talks & speakers that would love share their knowledge with you πŸ’œ 🍻 πŸ—“οΈ Current Agenda: infosecjupyterthon.com/agenda.html πŸ“’ Registration Form: bit.ly/InfosecJupyter… See you on Friday 5/8

Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

Trying to revamp a project πŸ”₯ & document interesting SACLs (Audit Rules) πŸ˜‰ 🍻 First attempt: 1) git clone github.com/GhostPack/Seat… 2) egrep -rhio '(SOFTWARE\\|SYSTEM\\).*\"' Seatbelt/Seatbelt/Commands/* 3) gist.github.com/Cyb3rWard0g/02… 4) github.com/OTRF/Set-Audit… (work in progress)

Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

Thank you for sharing Adam Chester πŸ΄β€β˜ οΈ πŸ’œ I took some time in the 🌞 to read a little bit about it. I'm sure there are + resources out there, but I put together these initial notes from a detection perspective. Maybe a SACL & sigma rules for the reg approach? 😈gist.github.com/Cyb3rWard0g/a4…

Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

πŸ”₯ How to Community Evaluate FREE Telemetry 🌎 following the ATT&CK evals methodology πŸ“‹ Sharing detections, sigma rules, data & a Project Jupyter notebook created during an ongoing hackathon to empower others & create research opportunities πŸ™ medium.com/threat-hunters…

Security Datasets (@secdatasets) 's Twitter Profile Photo

WE HAVE PCAPs 😈 a) Suricata IDS/IPS βž• ET Rules! b) git clone github.com/hunters-forge/… && cd mordor/datasets/large c) find apt29/day*/pcaps -name '*.zip' -execdir unzip -P infected {} \; c) find apt29/day*/pcaps -name '*cap' -execdir suricata -r {} -k none \; TY Jason Trost πŸ™

WE HAVE PCAPs 😈

a) <a href="/Suricata_IDS/">Suricata IDS/IPS</a> βž• ET Rules!

b) git clone github.com/hunters-forge/… &amp;&amp; cd mordor/datasets/large

c) find apt29/day*/pcaps -name '*.zip' -execdir unzip -P infected {} \;

c) find apt29/day*/pcaps -name '*cap' -execdir suricata -r {} -k none \;

TY <a href="/jason_trost/">Jason Trost</a> πŸ™
Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

🏑 Saturday project (WIP..)! πŸ˜… a) Doc #Bloodhound cypher queries from the community in YAML b) Auto parse queries & create #jupyter notebook to query a Neo4j DB via py2neo c) Docker #jupyter server & #neo4j w/ #Bloodhound ExampleDB d) Jupyter Book bloodhoundnotebook.com

🏑 Saturday project (WIP..)! πŸ˜…

a) Doc #Bloodhound cypher queries from the community in YAML

b) Auto parse queries &amp; create #jupyter notebook to query a <a href="/neo4j/">Neo4j</a> DB via py2neo

c) Docker #jupyter server &amp; #neo4j w/ #Bloodhound ExampleDB

d) Jupyter Book bloodhoundnotebook.com
Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

I started to document Win RPC interfaces & their respective methods πŸ“‹& ended up using sigpwn for the 1st time, integrating code from Adam Chester πŸ΄β€β˜ οΈ & @Sektor7Net research πŸ˜… and using Project Jupyter notebooks & #GraphFrames πŸ”— to analyze the results 🍻 medium.com/threat-hunters…

Roberto Rodriguez πŸ‡΅πŸ‡ͺ (@cyb3rward0g) 's Twitter Profile Photo

HOW to contribute a @Mordor_Project dataset in 2 mins ⏳w/ the help of Red Canary, a Zscaler company ART & then contribute to sigma after exploring the data! Open Threat Research ♻️ Clear, Exec & Collect: youtu.be/6iteEfbuwU8 😈 Data: mordordatasets.com/notebooks/smal… 🏹 Rule: github.com/OTRF/sigma/blo…

Microsoft Security (@msftsecurity) 's Twitter Profile Photo

It's time to go to SimuLand! 🎠🎑🎒 But it isn't a new vacation theme park hot spot, it's a new open-source initiative that will help you deploy a lab environment to reproduce real attack scenarios to test your security defenses. Get the details: msft.it/6017VxcHv