A new addition to the open source ecosystem, FlowIntel version 1.0, has been released! It's an open source case/task management tool with built-in integration with MISP and MISP modules.
#opensource#cti#threatintel#infosec
https://t.co/1Run6sBmlH
@cruciani_david
We are reviewing our @MISPProject warning lists and we are looking for a maintained list of hosts which are domain parking. Do you know someone doing such thing? or should we start to build one from scratch? #threatintelligence
First lightning talk, @cruciani_david setting the bar high by presenting his new typo squatting tool.
It’s his first conference talk, quite the feat to start by presenting such an awesome piece of work!
@udgover@circl_lu@ail_project@MISPProject For the moment there's no way to share the results but if you do the same research, you will get the same result as you got very quickly, because the result is store for 1 day.
We release a new public service to find potential typo-squatted domains.
https://t.co/WLopIGLEjT relying on our open source @ail_project typo-squatting library. You can select among algorithms, find the existing domains and download the results.
#infosec#threatintel
First release of AIL typo squatting library - a generic library in Python supporting various typo-squatting algorithms easily extendable usable in @ail_project and other projects.
By @cruciani_david from @circl_lu#cybersecurity#typosquatting
https://t.co/MO6WYwR7rA
First release v1.0 of factual rules, a new open source tool to build YARA rules for known installed software on operating systems. Then using the generated YARA rules against digital forensic acquisition to ease #DFIR.
https://t.co/OOGyQgay8v
#100DaysofYARA
git-vuln-finder v1.2 released including support for @githubarchive processing to analyse GitHub archive for potential vulnerabilities mentioned in commit logs. #opensource#infosec
https://t.co/wmYz8sncnR
Thanks to @cruciani_david for the https://t.co/eaByWJWxim support.
We imported 1.6 millions of Windows 10 hashes including some common software such as WinRAR,Putty in hashlookup. #DFIR
https://t.co/0Ybp4rVY4R
The import process uses https://t.co/OOGyQga0iX a WiP software to fingerprint installed software on Windows. by @cruciani_david