Phalgun @Fal_Forensics
DFIR {Speaker | Researcher | Nerd} Joined April 2023-
Tweets16
-
Followers19
-
Following98
-
Likes44
VeloCON REWIND! Phalgun Kulkarni and Kostya Ilioukevitch of AON show off a new Velociraptor plugin that goes deeper into a broader set of lateral movement artifacts to better detect threat actor movement during investigations. youtube.com/watch?v=WS6yzw…
📺 SANS #DFIRSummit Talks are live! ️ 🗣Featured Experts: Shane McCulley, Senior Software Developer, Aon & Kimberly Stone, Director, Aon 👏 Windows Registry Forensics: There’s Always Something New ➡️ Watch Now: youtu.be/HO0TbQHfYwg
FYI - if you have been exploited by CVE-2023-22515, be aware webshells may have been installed! The admin rights allow uploading of plugins which can be used to drop webshells. #DFIR #confluence
The threat actor from September has a fairly unique shell which hijacks TomCat servlets dynamically via the confluence plugin. This lets them use their webshell on any page, including the login page. #DFIR
📺 SANS #DFIRSummit Talks are live! 🗣Featured Experts: Phalgun Kulkarni, DFIR Consultant, Aon & Julia Paluch, DFIR Consultant, Aon 👏 Windows Search Index: The Forensic Artifact You’ve Been Searching For ➡️ Watch Now: youtu.be/X4WTcRdIDAM
Excited to share that Julia Paluch, Kostya Ilioukevitch, and mine presentations won 2 "Best Presentation" awards at #VeloCon2023. Thank you to everyone who attended and made it such a successful event. #Velociraptor #DFIR #StrozFriedberg #Aon
👨💻 #ScatteredSpider #UNC3944 has been targeting organizations across multiple sectors. The latest target being #MGMResorts. 🕵♂️ #StrozFriedberg has responded to multiple incidents involving this threat actor. We've published a client advisory that provides details into attacker techniques, recommendations and countermeasures. Link: aon.com/cyber-solution… 📄 Here are some highlights from the report: 1. A common thread across several investigations has been the utilization of social engineering tactics to gain access to privileged accounts. 2. This threat actor has demonstrated a significant level of knowledge and skillset when operating within an organization's cloud environment. 3. This threat actor has been observed sending personalized and threatening messages over email, phone, and SMS to gain attention from victim organizations. In some instances, they have contacted the media to add pressure and extract payment from companies. 4. This threat actor has been observed deploying ransomware on ESXi servers. This threat actor has loosely affiliated itself with the #ALPHV or #BlackCat ransomware group in some instances and has used the ransomware group’s negotiations and leak site infrastructure to post information about victim organizations. This is a group that is very skilled and persistent. Please review the recommendations in our report to better protect your organization from this threat. #StrozFriedberg #DFIR #IncidentResponse #CyberSecurity
🕵️♂️My colleagues @Fal_Forensics and Kostya gave an excellent talk on lateral movement at #VeloCon2023 today. 🚀 They also released a Velociraptor plugin that processes multiple lateral movement artifacts and gives you a normalized output. 👨💻 Check it out here: GitHub.com/strozfriedberg… #StrozFriedberg #DFIR #IncidentResponse
I will be presenting alongside my colleague Julia at #VeloCON2023 about how you can utilize Velociraptor to parse an amazing Windows forensic artifact, Windows Search Index, at scale and enhance #DFIR investigations. #Velociraptor #digitalforensics #incidentresponse
Hey folks! I'll be going on a conference tour in the next couple of months and presenting some research at the following cons: - BSides ABQ (Sept 8-9) - BSides KC (Oct 6-7) - BSides Bloomington (Oct 13-14) I'm honored to speak at these locations to represent Aon's Testing services team, particularly our red team, and really looking forward to seeing my old Depth Security crew in my favorite city (KC) in October. :) I made a 4-minute teaser video regarding my research ("DUALITY") - it can be found here: youtube.com/watch?v=LKXOZs… You can find the talk's abstract in BSides Bloomington's schedule here: bsidesbloomington.org/schedule There is a blog post coming soon as well. tl;dr - we're simultaneously backdooring multiple DLLs on the fly with custom logic for init access and persistence (to keep each infected DLL alive) via a pipelines, C2 scripts, and a somewhat custom shellcode compilation (carefully written C->ASM) methodology. I'm hoping to take DLL proxying / sideloading to the next level, or at least provide an interesting alternative. My LinkedIn: linkedin.com/in/faisaltamee…
Had an awesome time presenting Windows Search Index research with my colleague Julia Paluch as #sans #DFIRSummit
And that is all for this year's #DFIRSummit. We would like to thank our attendees, advisory board and speakers for making the 16th DFIR Summit a success! We will see you next year 8/22-23 in #SALTLAKECITY! #DFIR
A few more days left for #Sans #DFIRSummit. Join me and Julia for an amazing journey where we talk about a not so famous but very important artifact "Windows Search Index," and learn how W.S.I can enhance your #DFIR investigations. We also showcase an awesome tool to parse W.S.I
Join us at #DFIRSummit when Phalgun Kulkarni and Julia Paluch discuss how the Windows Search Index can be used as a source of evidence in DFIR investigations. Register here: sans.org/u/1pkc #DFIR #IR #IncidentResponse
Join us at #DFIRSummit when Shane McCulley and Kimberly dive deep into Shellbags and uncommon extension blocks, and dispel some dangerous myths about what they say about user behavior. Register here: sans.org/u/1pkc #DFIR #IR #IncidentResponse
Join us at #DFIRSummit when Phalgun Kulkarni and Julia Paluch discuss how the Windows Search Index can be used as a source of evidence in DFIR investigations. Register here: sans.org/u/1pkc #DFIR #IR #IncidentResponse
Recently, Julia Paluch and I worked on researching the Windows Search Index artifact. I'm excited to share our research in our latest blog: aon.com/cyber-solution… We also release "SIDR" tool which parses the WSI at scale: github.com/strozfriedberg… #DFIR #Windows11 #SIDR #Aon
FedWatchPro🇺🇸 @Oupranoom9000
52 Followers 2K Following 15-30% Monthly | 2 High-Conviction Stocks.Short-Term Gains: 15-20% in Days/Weeks.DM "JOIN" for WhatsApp Alerts. Live Trade Signals • Market Analysis
lynchan @lynchan79
54 Followers 3K Following
Toughth @Toughth367442
16 Followers 322 Following Improve sales effectiveness, build teamwork & develop leadership at every level.
Chapin Bryce @chapindb
546 Followers 822 Following DFIR, skiing, & aviation nerd. Co-author of Learning Python for Forensics & Python Forensics Cookbook.
Robin Chataut, PhD @robinchataut
109 Followers 501 Following Assistant Professor of Cybersecurity and Computer Science @QuinnipiacU, alum: @UNTsocial, @IOE_Pulchowk 🇳🇵🇺🇸 @ManUtd fan ⚽️ , Cricket fan🏏
Daniel Stein @_danstein
276 Followers 1K Following You can't be common, the common man goes nowhere; you have to be uncommon | Security
Jon Stewart @codeslack
902 Followers 284 Following The other Jon Stewart, not the one you miss. https : // bsky . app / profile / codeslack . bsky . social Github: jonstewart
Ed Michael @EdXlg123
682 Followers 650 Following DF/IR Director at Unit 42. Retired LEO, IACIS Incident Forensic Response Trainer, World of Warcraft gamer, and lifter of things
modest t @modestt8
0 Followers 103 Following
Faisal Tameesh @primal0xF7
315 Followers 179 Following Hacker Private Pilot (ASEL, IR) Jiu Jitsu Opinions here are my own.
Heidi Wachs @hlwachs
368 Followers 551 Following Cybersecurity. Privacy. Information Governance. Jersey Girl. Tweets my own.
™ @c0ntrol_z
334 Followers 1K Following DFIR | My views are my own and do not reflect those of my employer.
Kim Stone @k_a_stone
113 Followers 157 Following Occasional twittering. Mostly code and food. @[email protected]
John Ailes @JohnAiles6
54 Followers 297 Following
Mitch Green @Mitch9reen
792 Followers 953 Following #DFIR & #InfoSec shenanigans. Opinions are my own. RT’s are not endorsements.
Linux Inside: The Ide... @tecmint
136K Followers 19 Following Tecmint - Linux, AI & Open-Source Made Simple 🐧🚀 Follow us for: - Easy Linux Tips and Tutorials 💡 - The Latest on Open-Source & AI 📰 - Fun Linux & AI 🤣
Jonathan Rajewski @jtrajewski
3K Followers 1K Following Digital Forensics & Incident Response, Expert Witness, @TEDx Speaker. Husband & Dad. Views are my own not my employer.
Arsenal Consulting @ArsenalArmed
2K Followers 2K Following We are digital forensics consultants and software developers well-known for stepping into the breach when others have failed. #DFIR!
Tsurugi Linux @tsurugi_linux
5K Followers 7 Following Official Twitter account of TSURUGI Linux.TSURUGI is a free Linux distro designed for DFIR, OSINT investigations,malware analysis and computer vision activities
Charles Iszard @IszardC
71 Followers 76 Following DFIR VP at Aon / Stroz Friedberg | Former Consultant at Cisco Talos & SecureWorks | Fabricator of stuff | Views are my own
Carly @CarlyBattaile
15 Followers 0 Following
Anuj Soni @asoni
3K Followers 359 Following Malware Reverse Engineer. Instructor & Author. Occasional YouTuber.
Jared Barnhart @bizzybarney
1K Followers 433 Following Father, forensic analyst, DI Specialist @Cellebrite. Opinions are mine.
The Real STEM Sadie �... @stem_sadie
649 Followers 392 Following Cryptanalyst, DFIR, & OSINT | cat mom | meme-maker | blogger | public speaker | #Neurodiversity in #CyberSecurity | #HAE #PANDAS #FND | opinions==mine
Faisal Tameesh @primal0xF7
315 Followers 179 Following Hacker Private Pilot (ASEL, IR) Jiu Jitsu Opinions here are my own.
Devon @aboutdfir
3K Followers 141 Following Custodian of Private Histories | Keynote Speaker | Creator of https://t.co/sgaC8FxjAE | Author of Diving In: An Incident Responder’s Journey 📖
mjcardow @mjcardow
25 Followers 71 Following
Sergey Gorbov @shellnax
12 Followers 28 Following
Heidi Wachs @hlwachs
368 Followers 551 Following Cybersecurity. Privacy. Information Governance. Jersey Girl. Tweets my own.
Kim Stone @k_a_stone
113 Followers 157 Following Occasional twittering. Mostly code and food. @[email protected]
John Ailes @JohnAiles6
54 Followers 297 Following
X-Ways Forensics Prac... @XWaysGuide
5K Followers 7 Following There is no better reference for X-Ways Forensics practitioners than this guide. #DFIR #xwaysforensics
DFIRSummit @DFIRSummit
5K Followers 35 Following
Windows Forensic Envi... @WindowsFE
5K Followers 5 Following Forensically boot evidence machines with a Windows Forensics Operating System! Now boots into ARM devices. #DFIR
DFRWS @DFRWS
5K Followers 154 Following The Digital Forensics Research Conference is dedicated to the sharing of knowledge and ideas about digital forensics research.
13Cubed @13CubedDFIR
8K Followers 0 Following The official account for 13Cubed. Follow @davisrichardg for my personal account.
Lawrence Abrams @LawrenceAbrams
18K Followers 833 Following Ransomware, Online Security, and Malware. Owner, Editor in Chief of @bleepincomputer. DM on Signal: LawrenceA.11 * https://t.co/LXVRoICs8Z
Volexity @Volexity
8K Followers 7 Following Volexity is a cybersecurity firm founded by the pioneers of memory forensics. Volexity delivers solutions & services to governments & organizations worldwide.
Ovie @ovie
2K Followers 313 Following
Robert M. Lee @RobertMLee
75K Followers 397 Following Co-Founder & CEO @DragosInc | SANS #FOR578 & #ICS515 course author & Faculty Fellow |@_LittleBobby_ writer | NSA & USAF Veteran
Josh Lemon @joshlemon
2K Followers 1K Following Chief DIFR at @SoteriaSec_io | @SANSInstitute Principal Instructor | Digital Forensics & Incident Response geek
Jason Jordaan 🇿�... @DFS_JasonJ
2K Followers 834 Following Digital Forensics, Incident Response, Cybercrime Investigation Specialist | Certified SANS Instructor | Former Cop | Alpha Nerd and Geek | WYSIWYG
Magnet Forensics @MagnetForensics
17K Followers 984 Following Official Twitter feed for Magnet Forensics, a global leader in solutions for digital investigations since 2009.
BleepingComputer @BleepinComputer
256K Followers 205 Following Breaking cybersecurity and technology news, guides, and tutorials that help you get the most from your computer. DMs are open, so send us those tips!
Malwarebytes @Malwarebytes
90K Followers 1K Following All-in-one cybersecurity that's always by your side. Need support? @SupportMWB
Ali Hadi | B!n@ry @binaryz0ne
35K Followers 571 Following DFIR and Adversary Simulation | All posts reflect the views and interests of the person behind this account only |
eForensics Magazine @eForensics_Mag
16K Followers 814 Following eForensics Magazine, professional writing directed to experts in digital forensics
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Cellebrite @Cellebrite
19K Followers 2K Following Cellebrite's mission is to protect communities, nations and businesses as a global leader in AI-powered digital investigative and intelligence solutions.
DigitalForensicsMag @DFMag
15K Followers 2K Following Digital Forensics Magazine covers Digital Investigations including: Digital Forensics, Incident Response & Cyber Security. With News, Blog & Feature Articles.
Forensic Focus @ForensicFocus
19K Followers 480 Following Leading digital forensics and DFIR news, analysis and discussion. Join us at https://t.co/UMDF1v9X9hMac Forensics @MacForensics
7K Followers 78 Following Digital forensics with a focus on Mac forensic investigation. #eDiscovery #ComputerForensics
HTCIA @HTCIA
7K Followers 2K Following Official account of the High Technology Crime Investigation Association.
David Cowen @HECFBlog
14K Followers 918 Following Co-Author SANS FOR509, Vice President @ https://t.co/whEvYHKz6R wrote some books a long time ago, fights fires in the cloud. Views expressed are my own.
Brian Carrier @carrier4n6
9K Followers 106 Following CEO at Sleuth Kit Labs. Builds incident response (Cyber Triage) and Digital Forensics software (Autopsy and @sleuthkit)
ElcomSoft @ElcomSoft
11K Followers 2K Following ElcomSoft's Official Twitter. Password recovery, mobile & cloud forensics.
Andrew Case @attrc
28K Followers 5K Following @Volatility Core developer, Dir. of Research @Volexity, @lsucyber, The Art Of Memory Forensics Co-Author









