I'm thrilled to announce Fibratus - a modern tool for the Windows kernel tracing and observability built in @golang . Fibratus is the fruit of a lot of development
and research during the past two years.
To discover more about Fibratus, head to https://t.co/UYkj94uzNG
One example: detecting files dropped over SMB and subsequently executed: a classic lateral movement pattern. The kernel callstack becomes the connective tissue between stages of execution, providing durable attribution that is more resistant to spoofing.
I've uncovered a novel approach to identifying attack patterns through kernel frame callstacks.
While the userspace callstack telemetry has been widely used by modern security vendors, the kernel thread return addresses remain an unexplored territory.
Fibratus now captures kernel return addresses and symbolizes them into module paths, exposing the exact drivers and kernel subsystems traversed during event execution. The result is a radically richer execution narrative that reveals context traditional telemetry cannot see
Hi all! I played Town Square from Kingdom Come: Deliverance
This is one of my favourite pieces from the game! ♥️
(Thank you for your support! )
@valtajan@WarhorseStudios@thisistommckay ;)
#kcd
🎉 Fibratus 3.0.0 has been released!
- Unprecedented performance gains and precision
- 50+ high quality rules (no AI slop ;)
- Improved telemetry and enrichment
Download: https://t.co/E9zxcoRdYs
Changelog: https://t.co/W7FqGdgrxA
🚀 Fibratus 2.4.0 is out!
I'm thrilled to announce the Fibratus 2.4.0 With over 100 commits, this release brings astonishing performance improvements, 24 new rules, threadpool telemetry and much more. Check the full change log
https://t.co/cDGpJcwOHU