Toño Díaz @jupyterjones
We Investigate Anything ? ? ? León Joined June 2019-
Tweets40
-
Followers24
-
Following86
-
Likes203
The award-winning Qualys Threat Research Unit (TRU) has discovered a critical vulnerability in OpenSSH, designated CVE-2024-6387 and aptly named "regreSSHion." This Remote Code Execution bug grants full root access, posing a significant exploitation risk. blog.qualys.com/vulnerabilitie…
Windows Internals Crash Course, by @mrexodia youtu.be/I_nJltUokE0
The Key to Identify PsExec This blog post by Fabian Mendoza explains how USN journal entries can be used to identify the source system of a PsExec execution aboutdfir.com/the-key-to-ide…
1/ @hackerkartellet and I were investigating an IIS web server exhibiting strange behavior (screenshot below). Even though the customer reinstalled the server, the AppPools were still crashing regularly after the reinstall. Let's dig in. 🕵️ #CyberSecurity
If you don't get an alert for w3wp.exe spawning powershell.exe, then you're doing it wrong How to test this? Try 1. copy %comspec% w3wp.exe 2. w3wp.exe /c powershell.exe This should trigger an alert rapid7.com/blog/post/2022…
Nice lolbin lsass dumping method seen as ImagePath of a service in the wild: rdrleakdiag.exe /p process_pid /o c:\evil /fullmemdmp /wait 1 Ref: lolbas-project.github.io/lolbas/Binarie…
BlueHive github.com/leeberg/BlueHi…
Windows Process Injection: Print Spooler modexp.wordpress.com/2019/03/07/pro…
Tales of a Blue Teamer: Detecting #PowerShell Empire Shenanigans with Sysinternals holdmybeersecurity.com/2019/02/27/sys…
New video blog post "tshark & Malware Analysis" videos.didierstevens.com/2021/02/15/tsh…
If you are on a Blue Team, or IT Team, and you aren't running BloodHound REGULARLY, you are doing yourself a disservice. As a CTO I would either get rid of AD, or have BloodHound statistics be a top KPI/OKR for my org.
REMnux now officially supports @ubuntu 20.04 (Focal) as its base OS, in addition to 16.04 (Bionic). Happy New Year!
Detection and Hunting of Golden SAML Attack sygnia.co/golden-saml-ad…
added to the EVTX repo a section that will host selfies of malwares employing at least 3 different TTPs (e.g. Persistence, Injection, UAC Bypass) at once: github.com/sbousseaden/EV…
We share relevant #GPO settings to improve readiness for analysis of lateral movements in a #cheatsheet: compass-security.com/fileadmin/Date…
Wondering how to detect Zerologon attack. Op log in evtx, dcsync.. too complicated to centralise. Maybe it's just a matter of identifying anomalies among the known. Just filtered wire data with NetServerReqChallenge and grouped by src host. Worked! Attacks were clearly identified

TinaElizabeth @Gd83lUkdS5LA4Zx
75 Followers 7K Following
Henry @eahernand
99 Followers 972 Following
Renzon @r3nzsec
4K Followers 901 Following IR/Forensics @Unit42_Intel | Co-Founder @guidemtraining | Contributor/Analyst @TheDFIRReport @XintraOrg | CTF member @_hackstreetboys
MRX @nanomite_de
107 Followers 582 Following
St0pp3r @_st0pp3r_
223 Followers 261 Following Detection Engineering · Threat Hunting · Incident Response
ilGiovam @g10v4Z
3 Followers 69 Following
Jason Jordaan 🇿�... @DFS_JasonJ
2K Followers 847 Following Digital Forensics, Incident Response, Cybercrime Investigation Specialist | Certified SANS Instructor | Former Cop | Alpha Nerd and Geek | WYSIWYG
Growth With Fahim @AhmedFa21656420
354 Followers 4K Following 📲Social Media Guru | 🕵️♀️B2B Lead Hunter | 📩Email Whisperer 🎯SEO Magician | 🎬YouTube Wizard | 🏅Link Builder 💬Direct Messaging Ninja for Business Growth
Sergey Senin @reverse__ex
32 Followers 697 Following Im a student of #BMSTU. Learn C\C++, also pentest. #redteam #blueteam love LSD :) and coffee ;) 24 y.o.
Charles White @CharlesWhiteCat
691 Followers 4K Following Curious cat. Interested in OSINT, security, hacking and bad ideas..
Greg Bailey @GRBail
742 Followers 2K Following Analyst @HuntressLabs | Instructor @SANSInstitute | neo-hippie | grateful dad | all around nice guy
ith4cker @ITh4cker
575 Followers 2K Following A forever beginner in ISR( Internet Security Research )😀 Perceive everything, for body and mind healing😁
Andres Tarasco Acuña @atarasco
1K Followers 184 Following Geek, Pentester, Entrepreneur, optimistic and CEO at Tarlogic. Tweets are my own -- https://t.co/C9RyWDgqyZ
carmelo @carmelo_fdz
5 Followers 300 Following
Pablo Gómez @paggm
14 Followers 245 Following
Viti Calvo @vitivitis
57 Followers 159 Following Dressed in black, with a lightsaber and some thoughts to share in security, systems, mobility, (music), networks, IT, and that kind of useless stuff.
Luis GF @luisgf_2001
314 Followers 1K Following Ingeniero informático de vocación Dedicado a la seguridad informática, ah! y fotógrafo aficionado :-) y runner...y....
@[email protected]... @hacklego
522 Followers 169 Following Just here for #OSINT (@tracelabs BlackBadge x2), #Cryptography, #Privacy, #Anonymity, #Monero, #Bitcoin and #MegaDrive #Genesis. You can find me at @hackliza.
Blue Team Labs Online @BlueLabsOnline
9K Followers 7 Following A gamified scenario-based platform for security professionals to develop and showcase practical skills. Powered by @secblueteam
Unit 42 @Unit42_Intel
63K Followers 82 Following The latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.
Zach @svch0st
4K Followers 1K Following Everything DFIR @TheDFIRReport | @CuratedIntel | @XintraOrg https://t.co/ggakuKBS0S
Matthew @embee_research
14K Followers 2K Following Security Researcher, Creating and Sharing Educational Content.
Renzon @r3nzsec
4K Followers 901 Following IR/Forensics @Unit42_Intel | Co-Founder @guidemtraining | Contributor/Analyst @TheDFIRReport @XintraOrg | CTF member @_hackstreetboys
4n6lady @4n6lady
62K Followers 669 Following #DFIR & #BlueTeam | IR & Threat Detection | #OSINT enthusiast | waiting for HL3 | AWS CIRT - my views are my own
Kathryn Hedley @4enzikat0r
3K Followers 802 Following #DFIR & #DFIRFit geek, SANS Author/Instructor #FOR308, Instructor #FOR500. All opinions mine.
Phill Moore @phillmoore
9K Followers 3K Following This Week in 4n6 // ThinkDFIR // SANS // CyberCX (DFIR) https://t.co/vLyL2sxTuy I might not know much, but I do know how to Google Tweets are mine
St0pp3r @_st0pp3r_
223 Followers 261 Following Detection Engineering · Threat Hunting · Incident Response
ilGiovam @g10v4Z
3 Followers 69 Following
Frank McGovern - INAC... @FrankMcG
16K Followers 220 Following No longer active. Find me on LinkedIn and https://t.co/sNKTRQOIWi. Follow @BlueTeamCon. See pinned post. See you around. Touch grass. Be empathetic.
Stephan Berger @malmoeb
28K Followers 1K Following Head of Investigations @InfoGuardAG https://t.co/A5lnFAu7eX
Alh4zr3d @Alh4zr3d
24K Followers 276 Following Legal Criminal | Twitch cult leader | InfosecPrep founder | Lovecraft scholar | Soros mercenary | Spiritual cargo shorts wearer | Cthulhu fhtagn
DebugPrivilege @DebugPrivilege
40K Followers 2K Following Windows Nerd | Ex-MSFT | Microsoft MVP in Windows | Interested in Security, Debugging, and Windows Internals.
Insane Cyber @insanecyberinc
380 Followers 0 Following Accelerating Organizations' Detection/Response Capabilities to Counter Cyber Threats of Yesterday, Today, and Tomorrow
Jason Jordaan 🇿�... @DFS_JasonJ
2K Followers 847 Following Digital Forensics, Incident Response, Cybercrime Investigation Specialist | Certified SANS Instructor | Former Cop | Alpha Nerd and Geek | WYSIWYG
Coastline College @Coastline_OC
3K Followers 705 Following Coastline College has an international reputation as one of the nation's most innovative institutions.
The DFIR Report @TheDFIRReport
62K Followers 0 Following Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Services: https://t.co/XW613EKt2w
13Cubed @13CubedDFIR
7K Followers 0 Following The official Twitter account for 13Cubed. Follow @davisrichardg for my personal account.
DFIR Diva @DfirDiva
21K Followers 5K Following DFIR Analyst trying to learn all the things | DFIR Blog for Beginners | Founder @GetYourStart | https://t.co/7cHco4FjUS
Andrea Fortuna @andreafortunatw
765 Followers 867 Following "I don't know half of you half as well as I should like; and I like less than half of you half as well as you deserve." #cybersecurity #dfir #music #programming
David Cowen @HECFBlog
14K Followers 927 Following Co-Author SANS FOR509, Vice President @ https://t.co/whEvYHKz6R wrote some books a long time ago, fights fires in the cloud. Views expressed are my own.
Heather Mahalik Barnh... @HeatherMahalik
23K Followers 1K Following DFIR @cellebrite, Faculty Fellow & author @sansforensics #FOR585 #FOR500, wife, mama, researcher, USAF. Trust but validate. Thoughts are mine.
Sarah Edwards 👩�... @iamevltwin
20K Followers 2K Following Apple 4N6 Nerd, Head of DFIR @IsMyPhoneHacked, Author/Instructor @sansforensics FOR518 Mac/iOS DFIR. Opinions are mine. RT ≠ Endorse
Kevin 🤖🕵️🍺 @KevinPagano3
3K Followers 570 Following 🕵🏼♂️ @stark4n6 🎴 Shiny cardboard collector 🍺 Resident beer drinker
Chad Tilbury @chadtilbury
22K Followers 600 Following Digital forensics and incident response. Ex-AFOSI, Mandiant, and CrowdStrike. SANS Institute Fellow and co-author of #FOR500 and #FOR508 courses.
Rob T. Lee @robtlee
26K Followers 1K Following Chief AI Officer, Chief of Research, @SANSInstitute | Cybersecurity Expert & Threat Hunter | Godfather of DFIR | Technical Advisor to US Govt
Andrew Rathbun @bunsofwrath12
3K Followers 706 Following Husband, Father, #DFIR @ Unit 42, Digital Forensics Discord Admin, AboutDFIR Contributor, Author, #USMC Veteran, Former LE, NHL Fan, Dark Mode, Animals, Music
Lenny Zeltser @lennyzeltser
50K Followers 2K Following Advances cybersecurity. Grows tech businesses. Fights malware. // CISO at @AxoniusInc. Author and Faculty Fellow at @SANSInstitute. Creator of @REMnux.
Tyler Hudak @SecShoggoth
7K Followers 958 Following Reverse Engineering, IR, InfoSec. Also huge RPG guy. Elder of the Internet. Tweets and opinions are my own and not the views of my employer.
Ryan Benson @_RyanBenson
4K Followers 267 Following I do digital forensics and work on open source DFIR tools @Google. I kinda like web browsers, too. Not on Twitter often anymore, reach me at ryan 'at' https://t.co/Zcq6BJG4xC
Ali Hadi | B!n@ry @binaryz0ne
33K Followers 565 Following DFIR and Adversary Simulation | DFIR @ ProtonMail
🥝🏳️🌈 Be... @gentilkiwi
62K Followers 286 Following A kiwi coding mimikatz & kekeo github: https://t.co/eS3LVgU6i0 Head of security services @banquedefrance Tweets are my own and not the views of my employer
Joshua Wright @joswr1ght
27K Followers 561 Following Hacker for @counterhacksec and SANS Faculty Fellow. Pirata informático. Photography at https://t.co/Qbh3jsScLb. He/him.
Greg Bailey @GRBail
742 Followers 2K Following Analyst @HuntressLabs | Instructor @SANSInstitute | neo-hippie | grateful dad | all around nice guy
Andres Tarasco Acuña @atarasco
1K Followers 184 Following Geek, Pentester, Entrepreneur, optimistic and CEO at Tarlogic. Tweets are my own -- https://t.co/C9RyWDgqyZ
carmelo @carmelo_fdz
5 Followers 300 Following
Pablo Gómez @paggm
14 Followers 245 Following
SANS Institute, EMEA @SANSEMEA
37K Followers 15K Following The most trusted source for cybersecurity training, certification and research. To view upcoming events and course information visit our website.
Jess Garcia @j3ssgarcia
4K Followers 370 Following Founder of One eSecurity | Senior SANS Instructor | DFIR & Cybersecurity Researcher
Eric Zimmerman @EricRZimmerman
19K Followers 892 Following KAPE, EZTools, forensics, X-Ways. Certified SANS instructor. FFL Please consider supporting me: https://t.co/pIjxED3CMx
Brian Carrier @carrier4n6
9K Followers 107 Following CEO at Sleuth Kit Labs. Builds incident response (Cyber Triage) and Digital Forensics software (Autopsy and @sleuthkit)
Florian Hansemann @CyberWarship
84K Followers 47 Following Father, Founder @HanseSecure, Pentesting, Student, ExploitDev, Redteaming, InfoSec & CyberCyber; -- Mastodon: https://t.co/KFSKYUN98M
Web Security Academy @WebSecAcademy
130K Followers 36 Following Free web security training from @PortSwigger
Pedro Sánchez Corder... @ConexionInversa
4K Followers 38 Following Specialized in DFIR and Threat Hunting. He collaborated in IR with the security forces and Spanish companies. I have NATO Secret clearance.