Mathias Fuchs (@mathias_fuchs) 's Twitter Profile
Mathias Fuchs

@mathias_fuchs

Something with IR and Intelligence @InfoGuardAG, Certified Instructor and author @SANSInstitute (@SANSEMEA), Former Principal IR Consultant @Mandiant

ID: 84042728

linkhttps://www.cyberfox.blog calendar_today21-10-2009 09:44:50

1,1K Tweet

2,2K Followers

970 Following

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

Does anyone have information on how Amazon will deal with the Digital Market Act specifically regarding their Echo Show 15 devices. They went to great lengths about a year ago to prevent side loading. Now I guess they are required to lift that ban again.

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

I can see how users fall for that, but 5 vendors classify it ok too, including security vendors. That domains quite a s*hole forwarder. We observed that the site forwarded to one distributing magniber ransomware.

I can see how users fall for that, but 5 vendors classify it ok too, including security vendors. That domains quite a s*hole forwarder. We observed that the site forwarded to one distributing magniber ransomware.
Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

What the hell is going on at Contabo. Total outage of my servers. Only daily updates on the issue are not acceptable. I'll move my stuff to somewhere else.

SANS DFIR (@sansforensics) 's Twitter Profile Photo

🎉 Congrats to Mathias Fuchs on being promoted to #SANS Senior Instructor! Mat is an instructor for #FOR508 & #FOR608. Congrats again, Mat! We are so lucky to have you be an instrumental part of the #DFIR curriculum! 👏 Learn more about Mat, here: sans.org/profiles/mathi…

🎉 Congrats to <a href="/mathias_fuchs/">Mathias Fuchs</a> on being promoted to #SANS Senior Instructor! Mat is an instructor for #FOR508 &amp; #FOR608.

Congrats again, Mat! We are so lucky to have you be an instrumental part of the #DFIR curriculum! 👏

Learn more about Mat, here: sans.org/profiles/mathi…
Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

Even the best responders can’t work miracles in the dark. 🔍 Why visibility is everything in incident response – and what EDRs & network monitoring don't tell you. Read the blog 👉 medium.com/@mathias.fuchs… #DFIR #CyberSecurity #IncidentResponse #Velociraptor

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

🛡️ Microsoft's new ReFS filesystem is changing the rules of digital forensics & IR. NTFS artifacts are evolving—are you ready? Read our deep dive here: medium.com/@mathias.fuchs… #DFIR #ReFS #CyberSecurity #IncidentResponse #Forensics

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

Think Mac forensics is harder than Windows? Think again. 🍏 Unified logs, fewer artifacts, built-in snapshots—macOS might be easier for DFIR. Except memory. That’s still hell. 🔥 Full deep dive for IR pros here 👉 medium.com/@mathias.fuchs… #DFIR #macOS #forensics #cybersecurity

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

Last week: macOS forensics (easy!). This week: Linux forensics (not easy at all!). Ever wondered why Linux is tougher than Windows forensics? Scripts, logs, chaos! ☕🐧 #DFIR #Linux #CyberSecurity medium.com/@mathias.fuchs…

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

Choosing an IR partner = Picking a parachute packer. 🪂 Know your red flags 🚩, must-haves ✅, and absolute no-gos ❌ before you're in free-fall. Dive into my latest blog 👉 medium.com/@mathias.fuchs… #CyberSecurity #IncidentResponse #DFIR #CISO

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

Tier 1 SOC Analysts: Highest responsibility, least experience, infinite alerts—what could go wrong? Plenty. Find out how automation and AI could save your analysts' sanity (and yours). ☕️🤖 #CyberSecurity #SOC #AI medium.com/@mathias.fuchs…

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

🕵️‍♂️ How do attackers ghost past your EDR? New blog post dives deep into evasion tricks—LOLBins, memory games, syscall magic & more. Time to up your detection game! 👻🔍 👉 medium.com/@mathias.fuchs…

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

🚨 Bob from Accounting could be your biggest cyber threat. Seriously. 83% of orgs saw insider attacks last year. Tesla sabotage, Snowden leaks—your office has never felt spookier. Read how to spot & stop these insider rogues 👉medium.com/@mathias.fuchs… #CyberSecurity #InsiderThreat

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

🗓 Logs lie. Prefetch tattles. ShimCache whispers. Timestamps dance. Building timelines in DFIR isn’t just science—it’s chaos theory in action. Join me in taming Chronos: medium.com/@mathias.fuchs… #DFIR #IncidentResponse #CyberSecurity

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

Attackers love RDP for sneaky lateral moves—but every pixel leaves a clue! 🕵️‍♂️ Check out my latest blog on tracking attackers through logs, bitmap caches, and clipboard trails (plus a printer tale too funny to miss). #DFIR #BlueTeam #CyberSecurity medium.com/@mathias.fuchs…

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

🚨 Identity is now global. Are your IR skills? Explore how breaches leverage Microsoft, Google, Apple, GitHub, and AWS—and master the practical GLIDER Framework for modern incident response. Full guide here 👉 medium.com/@mathias.fuchs… #CyberSecurity #IncidentResponse #GLIDER

Mathias Fuchs (@mathias_fuchs) 's Twitter Profile Photo

Most EDR tests are easy mode — Agents spawning commands, “AtomicTest-T1055.ps1.” Your SOC spots them instantly. GHOST changes that: Zero footprint. Real attacker commands. Realistic process trees. If analysts can’t tell it’s a test, you’re ready. More: medium.com/@mathias.fuchs…