Avid MMORPG'er by night, Insane IT Security Advocate! All around DFIR/SecOps curmudgeon
My tweets are my own!
MASTADON: @[email protected]
Post.: fvt___
Introducing Threat Hunting Labs.
A training platform focused on realistic intrusion investigations.
Start from an alert, analyze real telemetry, and work through structured investigation paths.
Built for threat hunters, incident responders, and detection engineers.
More details:
https://t.co/zuEenae7Yt
⚠️️️ 𝗡𝗲𝘄 𝗦𝘁𝗮𝗴𝗲𝗿 𝗟𝗲𝗮𝗱𝗶𝗻𝗴 𝘁𝗼 𝗥𝗔𝗧 𝗗𝗲𝗽𝗹𝗼𝘆𝗺𝗲𝗻𝘁: 𝗗𝗲𝘁𝗲𝗰𝘁 𝗜𝘁 𝗘𝗮𝗿𝗹𝘆
We caught #RUTSSTAGER, a malware that stores a DLL in the Windows registry in hexadecimal form, hiding the payload and delaying detection. In the observed chain, the stager delivered #OrcusRAT, followed by a supporting binary that maintains persistence, uses PowerShell for system checks, and restarts the RAT process.
✅ In the #ANYRUN Sandbox, behavioral analysis and file system monitoring exposed the full execution chain. Process synchronization events revealed coordination between the stager and its payload, helping confirm multi-stage malware activity early.
👾 See the analysis session and collect #IOCs to speed up detection and response: https://t.co/AgSQLN94OT
🔍 Pivot from indicators and subscribe to Query Updates to proactively track evolving attacks: https://t.co/04yUe6PFqu
👨💻 Learn how #ANYRUN Sandbox helps SOCs detect complex threats and contain incidents faster: https://t.co/2a8Kcqr16V
#ExploreWithANYRUN
📄 Need a handy reference for your forensic investigations? Our #SIFT Cheat Sheet is designed for #DFIR analysts with essential tools and techniques on the SANS #Linux SIFT Workstation
Download your copy: https://t.co/TrvtgCAUYY
💡 A Practical Look at AWS Threat Hunting
https://t.co/jBHps7f7Ea
AWS environments generate massive telemetry. The challenge isn’t collecting logs, it’s turning one suspicious signal into context.
This is our practical workflow:
1) Start with VPC Flow Logs, GuardDuty, or CloudTrail.
2) Enrich the IP/domain using our platform.
3) Pivot to related domains, certs, hashes, C2s.
4) Map the campaign, not just the alert.
5) Feed findings back into detection.
Effective AWS threat hunting starts with a signal and expands from there.
#AWS #ThreatHunting #CyberSecurity
We analyzed a DPRK-linked Contagious Interview intrusion where fake job lures abused npm install for C2 using trusted packages. A modular toolset (OtterCookie, InvisibleFerret, Tsunami) enabled cross-platform access and data theft targeting wallets, creds, and docs.
Seeing identity attack paths is one thing. Eliminating them safely is another.
@ChannelInsider breaks down BloodHound Scentry and how it helps teams operationalize Identity APM faster. ⤵️ https://t.co/qPyUF7RWqO
New advisory was just published! 🚨
Three new post auth vulnerabilities have been found in ISPConfig. These vulnerabilities allow attackers who have either Reseller or Client accounts to escalate to root level access.
The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World
This book explores how intelligence and cyber-security analysts can uncover hidden links between threat actor infrastructure and ongoing investigations by pivoting on both classic and unconventional indicators — many of which are often overlooked.
The material is grounded in empirical, field-tested strategies used in cyber-security, digital forensics, cyber threat intelligence, and intelligence analysis more broadly.
Our goal is to provide analysts with a practical toolkit of analytical methods, supported by real-world examples, to enhance investigative workflows without locking them into a single mindset, strict model, or overly rigid technical strategy.
Instead, the book encourages creative exploration, data-driven reasoning, and the use of diverse data points — from traditional IOCs to subtle metadata traces — as part of a flexible and repeatable analytical process.
#threathunting
https://t.co/IiXTV6p2yY
TokenFlare is now public 🔥
Serverless AiTM phishing for Entra ID - deploys in <60 seconds on Cloudflare's free tier.
Dropped it at @BSidesLondon last Saturday. The room's reaction told me we cooked.
blog: https://t.co/nmmxsV2cGb
repo: https://t.co/50p7GEEt2R
Demo 👇
Wow, Wow, Wow, Wow, Wow, Wow, Wow, Wow, Wow!
Thank you to everyone who made a donation at #BSidesLDN2025 on Saturday, all donations have now been paid to @CR_UK and the total is currently £8128.
If you still wish to donate, you can! Visit: https://t.co/Av9Wubv3yc
#FuckCancer
The OFFICIAL Proton VPN CLI is now available on:
✅ Arch (btw)
✅ Debian
✅ Ubuntu
✅ Fedora
Next, we're adding features to let you specify P2P, TOR, and Secure Core for your connection, and the ability to see all countries/cities.
Here's a quick demo and how to install it 👇
There have been many posts asking about whether the #BSidesLDN2025 talks were recorded.
Yes they were!
They will be available on our YouTube channel https://t.co/4zJnObuKDR…
Please subscribe, we only upload once a year, and you’ll be notified when the videos are available!
#Sharenting 👶📱Et si on réfléchissait avant de publier ? En France, 53 % des parents ont déjà partagé des photos ou vidéos de leurs enfants en ligne.
📺Du 11 au 17 décembre 2025, découvrez notre vidéo de sensibilisation diffusée sur les antennes de @Francetele.