Here's the blog post on my new tool:
https://t.co/glSVd0u7Rr
Unfurl takes a URL🔗 and expands ("unfurls") it to show all the data it contains. It's amazing how much can be hidden inside URLs!
Take it for a spin and tell me what interesting stuff you find🔗🌿#DFIR#Python
@GergelyOrosz FYI that link in the screenshot is acquired by the user tapping "Copy Link" button from the Twitter app on iPhone. That's what the parameter "s=46" means. It's safe to also drop that from the final URL.
Here's where I got the s-parameter table to look up:
https://t.co/h9Dl8IgW7e
With all the uncertainty @Twitter, I've seen more people talking about alternatives like #Mastodon.
Like tweets, Mastodon IDs have embedded timestamps in them, and Unfurl can parse them:
🔗https://t.co/y9enToHpgD
#DFIR#OSINT
@phillmoore@inversecos It doesn't. These files are in the SNSS format, which involves some serialization. AFAIK, there aren't any working open source parsers (https://t.co/6sy2D0awSd & https://t.co/YkynsKbaMH worked at least partially in the past) and I haven't taken a pass at parsing it myself yet.
We are reviewing our @MISPProject warning lists and we are looking for a maintained list of hosts which are domain parking. Do you know someone doing such thing? or should we start to build one from scratch? #threatintelligence
A key mindset to grasp as you transition from junior analyst to a more experienced level is that you won't have all the answers, but you can ask the right questions and know where to start looking for the answers.
Nice little tidbit here about decoding #LinkedIn profile ids from URLs, then using their sequential nature to estimate profile creation time.
I see an @unfurl_link update in the future! #DFIR#OSINT
All of the profiles listed in the article and this thread were created within days of each other.
jennie-biller-9b631120a
victor-sites-40139b20a
charolette-pare-93b3a220a
vivian-christy-b1246320a
maryann-robles-2924b620a
1/4
Apparently TikTok uses the same ID scheme for job postings as it does for videos? Random, but kind of interesting.🤷♂️
Example: https://t.co/rrNmFgHXCS
More info on TikTok timestamps: https://t.co/uNqtmNyqY4
#DFIR#TikTok#OSINT
Have a long URL to decode? Use https://t.co/5cY9yzMT3B. It decodes parameters & values in the URL. Ex: I used Amazon & ran a search, copied URL, pasted into Unfurl. It broke the URL down & revealed "qid" param (2) is a time stamp and a date (3).
#osint#cyber#tools
Of course I didn't know that when I started but, this guy @_RyanBenson has been doing a #DailyDFIR before I have even thought about it! If u re interested in #DFIR, definitely check out his hashtag! (7/8)