Joseph Moronwi (@joseffmoronwi) 's Twitter Profile
Joseph Moronwi

@joseffmoronwi

Computer programmer and cyber-security enthusiast

ID: 1206107621499047936

linkhttps://digitalinvestigator.blogspot.com calendar_today15-12-2019 07:04:44

61 Tweet

37 Followers

63 Following

Het Mehta (@hetmehtaa) 's Twitter Profile Photo

The Complete Cyber Security Course ⚔ #Infosec ~ Part 1 ~ Part 2 ~ Part 3 ~ Part 4 šŸ‘‡FREE Download Link šŸ–‡ļø mega.nz/folder/j8JzmYj…

Joseph Moronwi (@joseffmoronwi) 's Twitter Profile Photo

This post examines a compromised Linux web server to determine how the adversary gained entry and the exploits used. The image analysed was provided by Ali Hadi | B!n@ry at the 2019 OSDFCon digitalinvestigator.blogspot.com/2023/09/linux-…

mRr3b00t (@uk_daniel_card) 's Twitter Profile Photo

some WMI Fun! Get-WmiObject -Query "SELECT * FROM Win32_NetworkAdapterConfiguration" Get-WmiObject -Query "SELECT * FROM Win32_NTEventlogFile" Get-WmiObject -Query "SELECT * FROM Win32_PnPEntity" Get-WmiObject -Query "SELECT * FROM Win32_PnPDevice" Get-WmiObject -Query "SELECT *

mRr3b00t (@uk_daniel_card) 's Twitter Profile Photo

if you wanted to write some logic for sandbox detection... check if the disk is encrypted... But you need LOCAL ADMIN to check this namespace Dan! Get-WmiObject -namespace "Root\cimv2\security\MicrosoftVolumeEncryption" -ClassName "Win32_Encryptablevolume" -filter

Joseph Moronwi (@joseffmoronwi) 's Twitter Profile Photo

In this article, I examined a HDFS cluster breach case provided by Ali Hadi | B!n@ry using Tsurugi Linux, the sharpest weapon in your DFIR arsenal. digitalinvestigator.blogspot.com/2023/09/linux-…

Ali Hadi | B!n@ry (@binaryz0ne) 's Twitter Profile Photo

Tomorrow will be my first Linux Forensics training for Cyber 5W... The folks who registered are in for a good treat, not just in terms of content, but many other advantages! Thank you so much for registering and see you tomorrow! #DFIR #Linux

NSA Cyber (@nsacyber) 's Twitter Profile Photo

ELITEWOLF is on the hunt! NSA released a repository of signatures and analytics to secure Operational Technology. Check it out on GitHub: github.com/nsacyber/elite…

ELITEWOLF is on the hunt! NSA released a repository of signatures and analytics to secure Operational Technology. Check it out on GitHub: github.com/nsacyber/elite…
Joseph Moronwi (@joseffmoronwi) 's Twitter Profile Photo

PowerShell commands for penetration testing. No modules, just plain Windows PowerShell digitalinvestigator.blogspot.com/2024/01/powers…

Ali Hadi | B!n@ry (@binaryz0ne) 's Twitter Profile Photo

One of the most important skills in #DFIR is using a hex-editor. Therefore, I created a 40+ video series on how to use 010-editor, which is probably the best Hex Editor out there! youtube.com/playlist?list=…

One of the most important skills in #DFIR is using a hex-editor. Therefore, I created a 40+ video series on how to use 010-editor, which is probably the best Hex Editor out there!
youtube.com/playlist?list=…
Joseph Moronwi (@joseffmoronwi) 's Twitter Profile Photo

Decoding Antivirus Malware Detection Names for Incident Responders and Malware Analysts: All you need to know digitalinvestigator.blogspot.com/2024/11/decodi…

Joseph Moronwi (@joseffmoronwi) 's Twitter Profile Photo

Dive into this post for a comprehensive guide to Linux log forensics. Perfect for investigators, sysadmins, and tech enthusiasts! šŸ›”ļø Read it here: digitalinvestigator.blogspot.com/2024/11/analyz… Linux forensic image provided by Ali Hadi | B!n@ry, and forensic tool is Tsurugi Linux.

Joseph Moronwi (@joseffmoronwi) 's Twitter Profile Photo

This article cover in succinct details, the hunting of adversary tradecraft with Windows event logs digitalinvestigator.blogspot.com/2025/03/uncove…

Joseph Moronwi (@joseffmoronwi) 's Twitter Profile Photo

This long, but highly informative , read discussed in great details how to analyze a Windows Shell Link file. It does not discuss any tool usage but pure hexadecimal analysis to enlighten the DFIR examiner. digitalinvestigator.blogspot.com/2025/04/window…