If you work with event logs, here are 2 GREAT utilities:
Parse an EVTX file into JSO: https://t.co/QkIzsJJIx7
Query a JSON stream: https://t.co/IRTOOTIe61
Combined with Sysmon and some built-in logs, there is a lot of power at your fingertips 💪
Last week at the DFRWS US Conference I gave a 4 hour workshop titled "Velociraptor – Digging deeper", where I cover examples of forensic analysis and hunting with Velociraptor.
#dfir#veociraptor
https://t.co/cq2qKnEhEi
Just finished my first conference talk in more than two years at @BsidesTLV, and while the slides and recording will come later.
For now, I'm back to writing technical blogs as well.
Take a look at how we catch Process DoppelDerpaGhost bamboozles!
https://t.co/0bsAsY5gYB
Kicked off my "MalDev for Dummies" workshop successfully yesterday, which means the repo is now public! Slides, exercises, example code and resources to get you started on your malware development journey. C# and Nim supported for now. Enjoy!!
https://t.co/Z8aQ41QvHQ
Here is the companion report to our SANS Ransomware Summit 2022 talk:
Can You Detect This?
https://t.co/7oZKEnCT6S
Great job @_pete_0 & @yatinwad!!🥳
Slides: https://t.co/01J2KOCc6b
Recording: Coming soon
#RansomwareSummit
#Sysmon event simulation utility which can be used for testing detections and correlation rules by Blue teams. (by @ScarredMonk)
https://t.co/RNv3NxOn1Z
New release: #mal_unpack (0.9.4): https://t.co/OCcdgd5AiO + the (experimental) companion driver (0.1.1.17): https://t.co/CDbx7iLXiq - check it out & share your opinions!