Sven Ulke 🐷🟪 (@n3x771) 's Twitter Profile
Sven Ulke 🐷🟪

@n3x771

#DFIR #Malware #ThreatIntel #Python #Golang #DFIRTrack #GIRAF 🐷🟪

ID: 999181650079768576

calendar_today23-05-2018 06:54:04

2,2K Tweet

222 Followers

850 Following

CISA Cyber (@cisacyber) 's Twitter Profile Photo

We’ve released a Malware Analysis Report with analysis & detection signatures on files related to Microsoft SharePoint vulnerabilities known as #ToolShell. Review IOCs and detection signatures in our 🆕report 👉 cisa.gov/news-events/an…

Nextron Systems (@nextronsystems) 's Twitter Profile Photo

⏱️ Instant Timelines with THOR - No manual tagging. No log wrangling. DFIR expert Maurice Fielenbach shows how to map persistence in minutes: ✔️ Registry Run Keys ✔️ Startup folder implants ✔️ LOLBin payloads 👉 Step-by-step guide & tool usage here: eu1.hubs.ly/H0mvr2d0

⏱️ Instant Timelines with THOR - No manual tagging. No log wrangling.

DFIR expert Maurice Fielenbach shows how to map persistence in minutes:

✔️ Registry Run Keys
✔️ Startup folder implants
✔️ LOLBin payloads

👉 Step-by-step guide & tool usage here: eu1.hubs.ly/H0mvr2d0
Fabian Bader (@fabian_bader) 's Twitter Profile Photo

You work with #XDR and always wanted to the process tree data outside of the Defender portal? With XDR Story Parser you can ▫️Redact sensitive information ▫️Export process tree as screenshot ▫️Extract PowerShell and command-lines ▫️Zoom in onto a process f-bader.github.io/XDRStoryParser/

You work with #XDR and always wanted to the process tree data outside of the Defender portal?

With XDR Story Parser you can
▫️Redact sensitive information
▫️Export process tree as screenshot
▫️Extract PowerShell and command-lines
▫️Zoom in onto a process

f-bader.github.io/XDRStoryParser/
Matt Zorich (@reprise_99) 's Twitter Profile Photo

Highly recommend everyone read the latest Microsoft Threat Intelligence blog, especially if you are involved in identity or cloud security. It details how threat actors can pivot between both your on-premises and cloud identity planes and cause destruction across both. Without proper guardrails

Highly recommend everyone read the latest <a href="/MsftSecIntel/">Microsoft Threat Intelligence</a> blog, especially if you are involved in identity or cloud security. It details how threat actors can pivot between both your on-premises and cloud identity planes and cause destruction across both.

Without proper guardrails
Matthew Green 🌻 (@mgreen27) 's Twitter Profile Photo

Interesting report from Sophos covering malicious Velociraptor use 🔎 news.sophos.com/en-us/2025/08/… Checking out this msi: 💾 • they used Velociraptor version 0.73.4. • Server likley installed on ~04/08/2025 10:03:15 (self signed certificate) • v2.msi - virustotal.com/gui/file/649bd… As

Matt Zorich (@reprise_99) 's Twitter Profile Photo

Interested in what real world Active Directory compromise looks like and how to prevent it? I wrote a deep dive on what we continually see when Active Directory gets owned. Hint: stop letting domain admins log onto all your endpoints Read here - techcommunity.microsoft.com/blog/microsoft…

Interested in what real world Active Directory compromise looks like and how to prevent it? I wrote a deep dive on what we continually see when Active Directory gets owned.

Hint: stop letting domain admins log onto all your endpoints

Read here - techcommunity.microsoft.com/blog/microsoft…
Mustafa (@mustafa_kh4n) 's Twitter Profile Photo

writing C in 2025? this is the book. > this book covers the new C23 standard and teaches how to write safe, fast, and modern C code that actually scales. > perfect for embedded devs, systems engineers, and anyone who wants to master the language that built everything

writing C in 2025? this is the book. 

&gt; this book covers the new C23 standard and teaches how to write safe, fast, and modern C code that actually scales. 
&gt; perfect for embedded devs, systems engineers, and anyone who wants to master the language that built everything
spencer (@techspence) 's Twitter Profile Photo

Regular reminder… this hardening series by Jerry Devore is super awesome. There’s no way you won’t learn things by reading these. Part 1 - Disabling NTLMv1 Part 2 - Removing SMBv1 Part 3 - Enforcing LDAP Signing Part 4 - Enforcing AES for Kerberos Part 5 - Enforcing LDAP

Kostas (@kostastsale) 's Twitter Profile Photo

This is an absolute goldmine of information for blue🔵| red🔴| purple🟣... Seriously, you need to know about these tools! These are the tools that threat actors use frequently. There aren't any magic or fancy tools responsible for 99% of intrusions. go.spenceralessi.com/adsecurity

Thomas Roccia 🤘 (@fr0gger_) 's Twitter Profile Photo

🎁 GenAI x Sec Advent 11 - Inside the AI arsenal I’ve built Over the past few years I tested a lot of ideas around AI for threat intelligence and security. I created workflows, agents, advanced RAG setups, and concepts I talk about in this space all the time! I wanted to show

Dan (@_xdanx) 's Twitter Profile Photo

Open Klara released - your own private cloud Yara scanner! Together with our community member Gajesh, I would like to announce the fork of the KLara project into Open Klara! We aim to maintain, support and fix future bugs. Open KLara is a community-driven fork of the original

Matthew Green 🌻 (@mgreen27) 's Twitter Profile Photo

The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World github.com/adulau/the-art…

Black Hills Information Security (@bhinfosecurity) 's Twitter Profile Photo

🚨 It’s back! 🚨 The INFOSEC SURVIVAL GUIDE has returned! Read our FREE Orange Book: Incident Response below or at the link here -- blackhillsinfosec.com/prompt-zine/pr… In the United States? Get a physical copy shipped to you for FREE -- spearphish-general-store.myshopify.com/products/the-i… If you loved our Yellow

🚨 It’s back! 🚨

The INFOSEC SURVIVAL GUIDE has returned!

Read our FREE Orange Book: Incident Response below or at the link here -- blackhillsinfosec.com/prompt-zine/pr…

In the United States?

Get a physical copy shipped to you for FREE -- spearphish-general-store.myshopify.com/products/the-i…

If you loved our Yellow