π™½π™΄πšƒπšπ™΄πš‚π™΄π™²

@netresec.com

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #PolarProxy, #FlowCarp, #CapLoader and RawCap. Website: https://www.netresec.com/ Mastodon: @netresec@infosec.exchange

New release of CapLoader πŸ«† JA3/JA4/SNI extraction from multi-segment TLS handshakes 🚨 Alerts on IOCs from RΓΆsti (rosti.​dev) πŸ‘€ OSINT lookup on BGP.​Tools/IPinfo/Netify/ScanMalware πŸ“¦οΈ Extracts packets from more encapsulation protocols netresec.com?b=265c041

CapLoader 2.1.0 Released

CapLoader has been updated to version 2.1.0. The new release comes with better JA3/JA4 extraction and integration of additional threat-intel and OSINT services. We have also added support for more enc...

netresec.com

πŸ” A major phishing-as-a-service platform disrupted. Tycoon2FA enabled large-scale account compromise by bypassing MFA protections. Through Europol’s Cyber Intelligence Extension Programme, industry intelligence was turned into operational results. Read more here: https://ow.ly/GECE50YoZIO

Bild

I'm interested in getting in touch with anyone who was involved in the WANK/OILZ worm outbreak at NASA/CERN/DoE in 1989. I've talked to a few folks, but there are still blanks in this story - if you were part of that please ping me.

✨ DFRWS EU 2026 Workshops Led by Erik Hjelmvik (Netresec, Sweden), the session is designed for practitioners and researchers working with network and memory forensics in real-world investigations. πŸ“ Workshop Dates 23–24 March 2026 πŸ“ Details here: πŸ‘‰ buff.ly/oT8OtbE

✨ DFRWS EU 2026 Workshops

Hands-on Analysis of Network Packets Carved from Memory & PCAP Analysis of Unencrypted Tor Traffic

Led by Erik Hjelmvik (Netresec, Sweden), the session is designed for practitioners and researchers working with network and memory forensics in real-world investigations.

πŸ“ Workshop Dates 23–24 March 2026 
Details here: πŸ‘‰ https://buff.ly/oT8OtbE

Erik Hjelmvik will run a hands-on network forensic workshop at the upcoming Digital Forensics Research Conference in Sweden. Participants will get the chance to analyze: πŸ”ͺ Packets carved from memory dumps πŸ§… Unencrypted Tor traffic dfrws.org/dfrws-eu-202...

DFRWS EU 2026 Workshop – Hands-on Analysis of Network Packets Carved from Memory & PCAP Analysis of Unencrypted Tor Traffic - DFRWS

dfrws.org

Post nicht verfΓΌgbar.

CN #APT targeting attendees of a diabetes conference in Singapore in December attd.z23.web.core[.]windows[.]net/ATTD-ASIA-2025.zip (live link, careful!) ATTD-ASIA-2025.lnk a12357ff6c0f7b021f32b0c9cd3d01c4 ATTD-ASIA-2025.zip a8082a80cef9ccee9d7a35f5366e3afb gzv.msi 32e7dcbd26b6455974d5b2c52c3ca421 🐴

Bild

I love the idea of calculating the decay rate of an IOC. It's not always strictly mathematical, because it also relies on threat actors' choices about how they use the IOCs, but as an estimate and for decision making, this seems promising. Also, I really like @netresec.com's ASCII art Pyramid. πŸ˜€

π™½π™΄πšƒπšπ™΄πš‚π™΄π™²@netresec.com Β· 9mo ago

Monitoring for too many old indicators not only costs money, it can even inhibit detection of real intrusions. πŸ“† Include "last seen" date when publishing IOCs ❌ Prune old IOCs πŸ“œ Prioritize long lived IOCs over short lived ones netresec.com?b=25Be9dd

Monitoring for too many old indicators not only costs money, it can even inhibit detection of real intrusions. πŸ“† Include "last seen" date when publishing IOCs ❌ Prune old IOCs πŸ“œ Prioritize long lived IOCs over short lived ones netresec.com?b=25Be9dd

Optimizing IOC Retention Time

Are you importing indicators of compromise (IOC) in the form of domain names and IP addresses into your SIEM, NDR or IDS? If so, have you considered for how long you should keep looking for those IOCs...

netresec.com