Arioch (@zearioch) 's Twitter Profile
Arioch

@zearioch

CERT peep. #DFIR

ID: 314081257

calendar_today09-06-2011 17:47:17

820 Tweet

473 Followers

332 Following

Sylvain Peyrefitte (@citronneur) 's Twitter Profile Photo

Merry Christmas Blue Teamers! šŸŽ„šŸŽ…šŸŽšŸ”” Invoke-Bof allows you to load and execute any #CobaltStrike Beacon Object File (BOF) to test your detection capabilities! #DFIR github.com/airbus-cert/In… Airbus CERT is looking for new team member, if you're interested get in touch!

Nicolas Bareil (@nbareil) 's Twitter Profile Photo

To celebrate this new release of msticpy, we share a "Today I Learned" blog post on how to extract Sysmon data from Splunk and visualize as a Process Tree: skyblue.team/posts/using-ms…

To celebrate this new release of <a href="/msticpy/">msticpy</a>, we share a "Today I Learned" blog post on how to extract Sysmon data from Splunk and visualize as a Process Tree: 
skyblue.team/posts/using-ms…
Katie Mack (@astrokatie) 's Twitter Profile Photo

Still don't know how to respond when people try to portray it as "irrational" to state a strong preference to avoid getting sick with an extraordinarily contagious, sometimes deadly, sometimes disabling virus, whether or not it's likely to be "mild" in one individual case.

Sylvain Peyrefitte (@citronneur) 's Twitter Profile Photo

Want to simulate any #ETW logs using powershell, even the security one? Do you want to import any evtx files into the current eventlog session? github.com/airbus-cert/nt… will help you to test your detection rules! #DFIR #Powershell

Want to simulate any #ETW logs using powershell, even the security one?
Do you want to import any evtx files into the current eventlog session?
github.com/airbus-cert/nt… will help you to test your detection rules!
#DFIR #Powershell
x0rz (@x0rz) 's Twitter Profile Photo

Anomaly detection in command lines with Markov chains, Splunk app provided 🤩 github.com/ANSSI-FR/AnoMa… by ANSSI #SSTIC

Sylvain Peyrefitte (@citronneur) 's Twitter Profile Photo

The results are out! We are very honoured to have won first placešŸ„‡in the Hex-Rays plugin contest 2022 šŸŽ‰ Our entry was "ttddbg", a time-travel debugging plugin for IDA already presented at #SSTIC 2022. Many congratulations to all the other entrants!

Airbus Security Lab (@airbusseclab) 's Twitter Profile Photo

AnaĆÆs Gantet, Nicolas Devillers (NK) and Mouad Abouhali (Mouad Ł…Ų¹Ų§Ų° Abouhali ) are going to present ā€œThe unavoidable pain of backups: security deep-dive into the internals of NetBackupā€ at #HEXACON2022. A thought to Jean-Romain Garnier (Jean-Romain) that was not able to participate.

AnaĆÆs Gantet, Nicolas Devillers (<a href="/Nikaiw/">NK</a>) and Mouad Abouhali (<a href="/_m00dy_/">Mouad Ł…Ų¹Ų§Ų° Abouhali</a> ) are going to present ā€œThe unavoidable pain of backups: security deep-dive into the internals of NetBackupā€ at #HEXACON2022.
A thought to Jean-Romain Garnier (<a href="/JRomainG/">Jean-Romain</a>) that was not able to participate.
SSTIC (@sstic) 's Twitter Profile Photo

Le SSTIC aura lieu du 7 au 9 juin 2023. L'appel Ć  contributions est en ligne: sstic.org/2023/cfp/. Date limite de soumission : 30 janvier. Vous hĆ©sitez ? Relisez nos conseils: blog.sstic.org/2017/01/06/com…

Sylvain Peyrefitte (@citronneur) 's Twitter Profile Photo

The #flareon9 write-ups from my team ! skyblue.team/posts/flareon9/ We are still looking for new talents ! More on pastebin.com/hqt4mqhX

The #flareon9 write-ups from my team !
skyblue.team/posts/flareon9/

We are still looking for new talents !
More on pastebin.com/hqt4mqhX
Jonny Johnson (@jsecurity101) 's Twitter Profile Photo

I've always thought that in order for Defenders to be truly effective, it is vital they know where the telemetry they are leveraging is coming from. Today I am releasing a project called TelemetrySource that is meant to support that cause. Blog: posts.specterops.io/uncovering-win…

Chetan Nayak (Brute Ratel C4 Author) (@ninjaparanoid) 's Twitter Profile Photo

Brute Ratel v1.3 is now released. This release brings in complete malleability, new shellcode, evasions to the core and detection rules for the previous version for the blueteam community. #BRc4 bruteratel.com/release/2022/1…

Sysinternals (@sysinternals) 's Twitter Profile Photo

A new update with Active Directory Explorer, Contig, and Sysmon has now been posted! Get the tools at sysinternals.com See what's new on the Sysinternals Blog: techcommunity.microsoft.com/t5/sysinternal…

Nicolas Bareil (@nbareil) 's Twitter Profile Photo

He is awesome: My fellow eeriedusk from the Airbus CERT added file hashes to process execution event logs to Sysmon for Linux, congrats man! github.com/Sysinternals/S… Let's try to have features parity with the Windows version now.

Airbus CERT (@airbuscert) 's Twitter Profile Photo

Have you ever tried setting up a shared and reproductible forensics lab? After hitting several brick walls with Docker, Ansible and others, we ended up finding a solution that ticked all the boxes we wanted: Nix. See for yourselves! skyblue.team/posts/nix-fore… #DFIR #NixOS

Airbus CERT (@airbuscert) 's Twitter Profile Photo

scrings is a strings utility that will output only semantically valid strings based on tree-sitter grammar. scrings support #python #javascript #sql #powershell #bash #php A #volatility plugin is also available to catch scripts in memory ! github.com/airbus-cert/sc…