You can now add a timeline name in #openRelik before pushing it to #timesketch 🎊
@b1acktu1ip.bsky.social
anyone else saw the #checkmarx js file in .../MS_Foundry_Evaluation/Examples/langgraph_react_agent/mcpAddon.js?
Oh.. Ok. this is fine... thehackernews.com/2026/03/team...
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials
TeamPCP compromised 2 GitHub Actions post-March 19, 2026 breach, enabling credential theft and supply chain attacks.
thehackernews.com
This Trivy thing is going to be a big deal. thehackernews.com/2026/03/triv...
New version of OpenRelik (the #DFIR workflow engine) is out. New workflow UI, support for chords (task groups with callback), MCP server and much much more. Give it a try! Take a look at the new page for workers showcase, both official and community contributed: openrelik.org/workers/
OpenRelik Workers
openrelik.org
OpenRelik 0.7.0 just dropped with configurable storage providers for RW or RO locations, chords with callback tasks, DuckDB to support querying file based databases, MCP server to integrate directly with automated AI workflows, new workers + much more! Full changelog: openrelik.org/changelog #DFIR
Link for those who are interested. The good stuff starts around 32 minutes in: www.youtube.com/watch?v=9LjO...
How to Train Your AI Security Analyst w/ Eric & Whitney
YouTube video by Antisyphon Training
youtube.com
there is thor2ts utility on @nextron.bsky.social's github. Time to add #THOR findings to #Timesketch 🔥
Here are the slides/resources from our #SecurityFest talk on "Modernizing Incident Response Using Techniques that Scale" Talk: www.youtube.com/live/Znl7TBF...
Security Fest 2025 - Day 2
YouTube video by Security Fest
youtube.com
tried volatility3. as luck would have it, it didn't like the first 3 dumps. of course, spent hours trying this and that before checking github where the issue was already reported 😅 an older dump from another environment worked like a charm! ah, the struggles of an insecure junior..
got to present my recent experience with #openrelik, #hayabusa, #timesketch and #splunk4dfir to my team. Took the entire afternoon but psyched about integrating them into company workflows 🔥
discovered the -f option for #log2timeline 🤩 excluding some irrelevant, noisy log files reduced the timeline to 10% of its original size. still, 50K events but I'll take that
fear of asking "stupid" questions cost me hours trying to figure out why timesktech would not generate logon graphs. answer found in one of the @digitaldefenseinstitute.com's bash scripts: use .plaso files, not .csv files! logon analyzer takes the strings field from there. thank you DDI :)
tested #openrelik, #hayabusa, #timesketch and #splunk4dfir using #thedfirreport recent analyst case. was a lot fun! will definitely use those tools more now 🚀
A good story, for a change. The hard work that the crew and the folks who support them put into their jobs truly shows here. ❤️🚀❤️🚀 arstechnica.com/space/2025/0...
Starliner’s flight to the space station was far wilder than most of us thought
“Hey, this is a very precarious situation we’re in.”…
arstechnica.com
🚀📣 Das Programm für die Auftaktveranstaltung zum Tag der Raumfahrt am 28. März im Futurium (Berlin) ist da! Hier 👇kommt der Überblick. ℹ️ Anmeldung für das Futurium ist ab dem 15.03. möglich unter diesem Link: shorturl.at/aJjjh Wir freuen uns auf Sie! 🌌 #TagderRaumfahrt @astromatthias.bsky.social
Listen, I'm not going to pretend that I'm even remotely surprised, but I will tell you that this is a slap in the face to every person in the infosec community that has worked to track and thwart Russian APTs for the last several decades. www.theguardian.com/us-news/2025...
Trump administration retreats in fight against Russian cyber threats
Recent incidents indicate US is no longer characterizing Russia as a cybersecurity threat, marking a radical departure: ‘Putin is on the inside now’
theguardian.com
looks like #virustotal shows random comments now for unknown hashes when searching without login