It's a big day for the #DIFR Discord, we officially released v1 of our community book today, free for the masses! Many thanks to @bunsofwrath12 for organizing and pushing things forward as well as to the other authors and contributors!
leanpub.com/TheHitchhikersGu…
I can't believe it needs to be said, but defcon is not the place you go to get up and brag that you do/ know how to do illegal shenanigans.
You will earn zero cred, you will be judged as an opsec risk, and you're low hanging fruit for feds.
Most orgs are in the “Nope, never” state when it comes to change. This is why I shifted to Incident Response. If the org won’t put in the work “left of boom”, then I’ll see you on the right!
Not sufficient. “UsePAM yes” effectively overrides “PasswordAuthentication no” and “UsePAM no” is a bad idea. You need to disable password auth in your PAM stack too.
90% of my Twitter DMs are asking me about how to start getting into Malware development. Well, I love answering them but it's easier to write a small thread about it so here we go.
1/12
We’re currently at 151 endorsements. We need to get to 500. The only way to do this is to break out of my direct and second degree network. Please share as widely as you can. You’d think it’d be easy to gather 500 out of 150k members. It is not. <3
Alright, ISC2 Members of the world ... I'm doing this again. While the site will be updated over the next few days with more details, I need to collect 500 endorsements of my petition before end of August. I'd be grateful for your support. RT=<3 be-represented.org/
There is no ‘teacher shortage’. There are thousands of qualified experiences teachers who are no longer teaching. There’s a shortage of respect and proper compensation for teachers allowing them to actually teach.
If you have not yet played with MemProcFS, now is the time! These new updates will rapidly accelerate hunting through memory forensic artifacts. If you like it, please support the project, provide feature requests, and send a big thank you to @UlfFrisk! #DFIR
MemProcFS v5 released! Super fast Memory Forensics & Analysis in easy-to-use virtual file system!
Forensic updates (incl. csv file support) and major API updates.
github.com/ufrisk/MemProcFS
Do you link to people on LinkedIn that you've never actually met? Suppose one of them asked for a 30 min Zoom call for career advice-- would you take that meeting at a mutually convenient time?
Are you having trouble writing the right #kql queries for your incident response process. Then check out the #DFIR section for queries on email compromise, malicious files, persistence and more.
github.com/Bert-JanP/Hunting…
Linux: "Everything is a file."
"Everything? Directories?"
Linux: "File."
"Sockets? Devices?"
Linux: "Yup, Files."
"My constant worry that I'll never be good enough?"
Linux: "2 files actually."