Chris DiSalle

@chrisdfir.updatex64.zip

Technical Lead, Incident Response @ Cisco Talos DFIR, drums, and the simple things

While there are some awesome methods to detect web shells with Yara, sometimes structured data can help solve the case. In this oversimplified example, I go over how you can use two artifacts with Velociraptor to help you find evil on your Linux server. #dfir #blueteam #cybersecurity

Hunting Linux Web Shells with Velociraptor

Linux forensics can be tricky, especially when investigating subtle threats like web shells. Unlike Windows, which provides tools like the Master File Table ($MFT) for metadata-rich investigations, Li...

linkedin.com

While there are some awesome methods to detect web shells with Yara, sometimes structured data can help solve the case. In this oversimplified example, I go over how you can use two artifacts with Velociraptor to help you find evil on your Linux server. #dfir #blueteam #cybersecurity

Hunting Linux Web Shells with Velociraptor

Linux forensics can be tricky, especially when investigating subtle threats like web shells. Unlike Windows, which provides tools like the Master File Table ($MFT) for metadata-rich investigations, Li...

linkedin.com

Russian spies—likely Russia's GRU intelligence agency—used a new trick to hack a victim in Washington, DC: They remotely infected another network in a building across the street, hijacked a laptop there, then breached the target organization via its Wifi. www.wired.com/story/russia...

Russian Spies Jumped From One Network to Another Via Wi-Fi in an Unprecedented Hack

In a first, Russia's APT28 hacking group appears to have remotely breached the Wi-Fi of an espionage target by hijacking a laptop in another building across the street.

wired.com

Topics covered with the kids: - What is cybersecurity? (high level) - How does the Internet work? - Underwater sea cable map - How technology can be used for bad - Stranger danger - Password security hands-on - Don't click random things #cybersecurity #education #teachin

Bild
Chris DiSalle@chrisdfir.updatex64.zip · 2y ago

Speaking at the elementary school teach-in tomorrow. Building a small cyber army one class room at a time. It's the long game... #cybersecurity

Hey #infosec and #cybersecurity folks. I have a couple thinky questions I'd like to get perspective on: - What makes a "good" cybersecurity partner in this day and age? - What services or capabilities are table stakes for you? always curious what you folks are seeing or would like to see

Random Monday thoughts… As most of us have come here to find a safe haven from extremism, I feel it’s important not to use this sanctuary to intentionally sow further division. Paraphrasing Ram Dass, “individualism leads to war, anger, insecurity, and fear.”

This git is full of resources for event logs/auditing. Covers everything from tool configs to audit cheatsheets to event attack chains and data samples. In #DFIR visibility is key. This is a solid resource for those responding to an incident or trying to prevent one. #grc github.com/stuhli/aweso...

GitHub - stuhli/awesome-event-ids: Collection of Event ID ressources useful for Digital Forensics and Incident Response

Collection of Event ID ressources useful for Digital Forensics and Incident Response - stuhli/awesome-event-ids

github.com

Vulnerabilities from 2021 still haunt orgs. When I respond to attacks where these have been exploited I commonly hear "We were just about to upgrade that server next quarter." Yesterday's threats may still present risks today. Focus on asset and vulnerability management.. among other things.

Chris Wysopal@weld.bsky.social · 2y ago

3 years later log4j vuln is #8 most exploited. The hype was justified. Also, why are people still using vulnerable versions and still not updating? www.cisa.gov/news-events/...