Ryan Benson @_RyanBenson
I do digital forensics and work on open source DFIR tools @Google. I kinda like web browsers, too. Not on Twitter often anymore, reach me at ryan 'at' https://t.co/Zcq6BJG4xC dfir.blog SF Bay Area Joined April 2009-
Tweets1K
-
Followers4K
-
Following264
-
Likes845
@GergelyOrosz FYI that link in the screenshot is acquired by the user tapping "Copy Link" button from the Twitter app on iPhone. That's what the parameter "s=46" means. It's safe to also drop that from the final URL. Here's where I got the s-parameter table to look up: dfir.blog/unfurl-parsing…
@KevinPagano3 thanks, I'll take a look and get them added
With all the uncertainty @twitter, I've seen more people talking about alternatives like #Mastodon. Like tweets, Mastodon IDs have embedded timestamps in them, and Unfurl can parse them: 🔗dfir.blog/unfurl/?url=ht… #DFIR #OSINT
@phillmoore @inversecos It doesn't. These files are in the SNSS format, which involves some serialization. AFAIK, there aren't any working open source parsers (github.com/cclgroupltd/cc… & github.com/JRBANCEL/Chrom… worked at least partially in the past) and I haven't taken a pass at parsing it myself yet.
We are reviewing our @MISPProject warning lists and we are looking for a maintained list of hosts which are domain parking. Do you know someone doing such thing? or should we start to build one from scratch? #threatintelligence
A key mindset to grasp as you transition from junior analyst to a more experienced level is that you won't have all the answers, but you can ask the right questions and know where to start looking for the answers.
@WebBreacher Double-click any node and it copies the text to clipboard. I need to make that feature more visible, sorry.
Nice little tidbit here about decoding #LinkedIn profile ids from URLs, then using their sequential nature to estimate profile creation time. I see an @unfurl_link update in the future! #DFIR #OSINT
All of the profiles listed in the article and this thread were created within days of each other. jennie-biller-9b631120a victor-sites-40139b20a charolette-pare-93b3a220a vivian-christy-b1246320a maryann-robles-2924b620a 1/4
Apparently TikTok uses the same ID scheme for job postings as it does for videos? Random, but kind of interesting.🤷♂️ Example: dfir.blog/unfurl/?url=ht… More info on TikTok timestamps: dfir.blog/tinkering-with… #DFIR #TikTok #OSINT
@WebBreacher Ha, thanks 😉. I updated the logo at least for dark mode, other components will take more time.
Have a long URL to decode? Use dfir.blog/unfurl/. It decodes parameters & values in the URL. Ex: I used Amazon & ran a search, copied URL, pasted into Unfurl. It broke the URL down & revealed "qid" param (2) is a time stamp and a date (3). #osint #cyber #tools
@WebBreacher Thanks! Glad you like it. And after seeing your screenshot, I'll make the logo look better in dark mode ;)
If you want a refresher on the benefits of allowlisting vs denylisting, just ask a 5 year old to stop doing something.
forked @_RyanBenson's awesome unfurl tool and patched the library so it can easily be used in a Jupyter Notebook :) #python github.com/Droogy/unfurl_…
@WHInspector If you're interested in browser forensics, check out hindsig.ht
Hey, thanks! Your #DailyOSINT looks really interesting too!
Of course I didn't know that when I started but, this guy @_RyanBenson has been doing a #DailyDFIR before I have even thought about it! If u re interested in #DFIR, definitely check out his hashtag! (7/8)
Florian Roth ⚡️ @cyb3rops
222K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
4n6lady @4n6lady
63K Followers 660 Following #DFIR & #BlueTeam | IR & Threat Detection | #OSINT enthusiast | waiting for HL3 | AWS CIRT - my views are my own
Chris Sanders 🔎 �... @chrissanders88
36K Followers 488 Following Ed.D. | Founder @networkdefense @RuralTechFund | Former @Mandiant, DoD | Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM
Stephan Berger @malmoeb
29K Followers 1K Following Head of Investigations @InfoGuardAG https://t.co/A5lnFAu7eX
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Heather Mahalik Barnh... @HeatherMahalik
23K Followers 1K Following DFIR, Faculty Fellow & author, #FOR585 #FOR500, wife, mama, researcher, USAF. Trust but validate. Thoughts are mine.
Chad Tilbury @chadtilbury
22K Followers 598 Following Digital forensics and incident response. Ex-AFOSI, Mandiant, and CrowdStrike. SANS Institute Fellow and co-author of #FOR500 and #FOR508 courses.
gabsmashh @gabsmashh
109K Followers 3K Following security strategist | 2L JD Candidate | NYU alum | UMGC adjunct professor | DVC-YR USCG AUX
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Kevin 🤖🕵️🍺 @KevinPagano3
4K Followers 590 Following 🕵🏼♂️ @stark4n6 🎴 Shiny cardboard collector 🍺 Resident beer drinker
Eric Capuano - Bsky: ... @eric_capuano
11K Followers 3K Following Co-Founder @recon_infosec | SANS DFIR Instructor | IANS Faculty | https://t.co/yUXCSu2Yso | ⬡ ❤ @shortxstack
Phill Moore @phillmoore
9K Followers 3K Following This Week in 4n6 // ThinkDFIR https://t.co/vLyL2sgQsy I might not know much, but I do know how to Google Tweets are mine
Nicole Beckwith @NicoleBeckwith
42K Followers 7K Following Sr. Director, Security Engineering and Operations @cribl_io
DFIR Diva @DfirDiva
22K Followers 5K Following DFIR Analyst trying to learn all the things | DFIR Blog for Beginners | Founder @GetYourStart | https://t.co/7cHco4FjUS
Ryan "Chaps" Chapman @rj_chap
8K Followers 3K Following Threat Hunter. DFIR & Malware Analyst. @sansforensics Author (FOR528) & Instructor (FOR610). Husband & father. Retro gamer too! Comments = own.
Nasreddine Benchercha... @nas_bench
12K Followers 1K Following Detection @Splunk & @cisco | previously @nextronsystems | @sigma_hq & @magicswordio maintainer | Eternal Learner
DFIR Training @DFIRTraining
18K Followers 415 Following The official DFIR Training account and most complete #DFIR online resource. Managed by @Brett_Shavers.
Nick Carr @ItsReallyNick
39K Followers 3K Following Tech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
z3r0Fl0w @Fl0w3rr0r
2 Followers 2K Following
Brooks McMillin @AISecBrooks
15 Followers 313 Following
Rikz Mondia @_huntsmansec
717 Followers 598 Following Cyber Threat Engineer @ LevelBlue | eJPT | (ISC)² Certified in Cybersecurity | Bug Bounty Hunter | UNIT7000 | SneakBytes |
Shivkumar Ahirwar @Shiv_KhareA8866
0 Followers 44 Following
YATA AI | DECODE AI F... @YATA_GenAI
780 Followers 5K Following Is it Real or AI? 🪞 YATA AI constantly learns scam tactics to neutralize deepfakes. Our forensics outsmart fraud with instant, high-precision reports.
Teddy Chan @teddyscs
2 Followers 3K Following
Yuu @sumaka0322
0 Followers 963 Following
Lorsek @Lorsek915
51 Followers 2K Following
EsmS @esms29
0 Followers 64 Following
Joshua Punkhead @Toranzamu20000
0 Followers 15 Following Redline 8 Champion Always behind the wheel of the infamous Trans Am. Racing for freedom. Living for love. Driving for the thrill
Captain Pug @PugCaptain
1 Followers 7 Following
anmol @anmolescape
48 Followers 5K Following the dao is a path of desolation. ai x code x marketing.
FarKingdom @FarKingdom97017
0 Followers 240 Following
L², PhD @L_Lgde
833 Followers 3K Following DFIR, CTI & Malware Researcher | Head of CSIRT — ex-ANSSI Focus: Chinese APTs, Russia-linked actors, cybercrime | PhD (International Law)
tmechen @tmechen_
176 Followers 359 Following 👨🏼💻 | he/him | #IFG-Ultra | macht (noch) nicht was mit Holz
Oto içerik @xxxxxxxsoru
0 Followers 2 Following Burda paylaşılan içerikler otomatik olarak çekilmektedir.
Mirror Mirror @Mirror11Mirror1
0 Followers 341 Following
RyanDFIR @RyanDFIR
0 Followers 1 Following
ORTISTE @OrtIstee
30 Followers 704 Following
Oséas Freitas Rosa @rfsaeso
0 Followers 35 Following
sf-shane @sfshane1
2 Followers 46 Following
Hiperion @Hiperio71312600
26 Followers 996 Following
Rishabh @RishabhIndia18
94 Followers 2K Following #YOUNG #ACTIVE #STAND AGAINST CORRUPTION #VOICE OF POOR NEEDY PEOPLE.. ✌🏻#BORN FOR MY COUNTRY #DIE FOR MY COUNTRY.. 🇮🇳
Investigators @CornerstoneORPI
290 Followers 1K Following When its all about the information, verification is ALL. Since 2014. #PrivateInvestigator #OSINT #SOCMINT #DesktopInvestigation https://t.co/MsqEKMaFiA
Bittu_Vamshi_ @BittuVamshi1
73 Followers 1K Following
M Yep @myepe90
1 Followers 112 Following
OSINTech @OSINTech_
265 Followers 1K Following Sociopathic cat lover. Investigative Journalism, OSINT activities & Investigations
IDeepSearch @IDeepSearch
703 Followers 591 Following #IDeepSearch concept. #SOCMINT #OSINT #HUMINT information gathering, consulting, training. #PublicSourcesIntelligence #BackgroundChecks #EmploymentScreening
Stickman76 @Stickman00076
13 Followers 458 Following
JD Keeling @JDKeelingIII
81 Followers 1K Following
romcom @RomComOG
0 Followers 51 Following
Tursse @TursseJN6
21 Followers 828 Following
Manidip @Manidipofficial
91 Followers 637 Following Advance Schema Coder. Semantically interlinked Schema that actually moves the needle on the SERP. Get ready to stand out from the rest. DM me NOW!
Shina Mashiro @ShiinaaM
382 Followers 4K Following
0xW43L @GhnimiWael
656 Followers 4K Following CTI Researcher | SRT Member @synack | Former-Red/Blue-Teamer | OSEP | CRTO | eWAPTx | arcX | ICTTF | DANTE ... Hunt threats, secure systems, learn always.
Harry Stein @mrharrystein
20 Followers 62 Following I love Jesus and my family. I enjoy my work as a DIFR investigator, network/performance expert, and experience in operating systems and software development.
Andy Morales @Andy2002a
65 Followers 273 Following
4n6lady @4n6lady
63K Followers 660 Following #DFIR & #BlueTeam | IR & Threat Detection | #OSINT enthusiast | waiting for HL3 | AWS CIRT - my views are my own
Chris Sanders 🔎 �... @chrissanders88
36K Followers 488 Following Ed.D. | Founder @networkdefense @RuralTechFund | Former @Mandiant, DoD | Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM
Heather Mahalik Barnh... @HeatherMahalik
23K Followers 1K Following DFIR, Faculty Fellow & author, #FOR585 #FOR500, wife, mama, researcher, USAF. Trust but validate. Thoughts are mine.
Chad Tilbury @chadtilbury
22K Followers 598 Following Digital forensics and incident response. Ex-AFOSI, Mandiant, and CrowdStrike. SANS Institute Fellow and co-author of #FOR500 and #FOR508 courses.
The DFIR Report @TheDFIRReport
68K Followers 0 Following Real Intrusions by Real Attackers, the Truth Behind the Intrusion
Kevin 🤖🕵️🍺 @KevinPagano3
4K Followers 590 Following 🕵🏼♂️ @stark4n6 🎴 Shiny cardboard collector 🍺 Resident beer drinker
Phill Moore @phillmoore
9K Followers 3K Following This Week in 4n6 // ThinkDFIR https://t.co/vLyL2sgQsy I might not know much, but I do know how to Google Tweets are mine
DFIR Training @DFIRTraining
18K Followers 415 Following The official DFIR Training account and most complete #DFIR online resource. Managed by @Brett_Shavers.
Nick Carr @ItsReallyNick
39K Followers 3K Following Tech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
Steve YARA Synapse Mi... @stvemillertime
18K Followers 1K Following AI threat intelligence @google writing & sharing on adversary tradecraft, malware, threat detection, AI-nexus intel and all things #yara
Kathryn Hedley @4enzikat0r
3K Followers 786 Following #DFIR & #DFIRFit geek, SANS Author/Instructor #FOR308, Instructor #FOR500. All opinions mine.
Devon @aboutdfir
3K Followers 141 Following Custodian of Private Histories | Keynote Speaker | Creator of https://t.co/sgaC8FxjAE | Author of Diving In: An Incident Responder’s Journey 📖
Matt Linton @0xMatt
7K Followers 770 Following #DFIR with a lot of focus on the IR part. Cellist, NASA Alum, Parrot lover, USAR & EMS do-er. BlueSky is @amuse.bsky.social
Susie Dent @susie_dent
1.0M Followers 814 Following That woman in Dictionary Corner. @susiedent.bsky.social
Battle Programmer Yuu @netspooky
21K Followers 1K Following knuck if you buck 日本語/español OK (he/they) @tmpout @binarygolf @[email protected] (fedi) @ https://t.co/mZ77OEN0DV (bsky)
ArcPoint Forensics @Contact_APF
433 Followers 22 Following Learn more about ArcPoint Forensic @ https://t.co/3AN6LcEnyf. And don't forget to sign up for updates on our website to stay up to date with the latest news.
Ed Michael @EdXlg123
682 Followers 650 Following DF/IR Director at Unit 42. Retired LEO, IACIS Incident Forensic Response Trainer, World of Warcraft gamer, and lifter of things
White Hat Inspector @WHInspector
13K Followers 191 Following #OSINT, Geolocation, Cyber Security | #DailyOSINT | Support: https://t.co/bk2qdJDuxd | TraceLabs CTF Black Badge | https://t.co/i6jwJugpSj
Andrea Fortuna @andreafortunatw
764 Followers 860 Following "I don't know half of you half as well as I should like; and I like less than half of you half as well as you deserve." #cybersecurity #dfir #music #programming
msticpy @msticpy
836 Followers 20 Following #msticpy is an open source library for InfoSec investigation and hunting in #Jupyter Notebooks and #Python.
Sarah Yoder @sarah__yoder
2K Followers 352 Following Incident Response @Mandiant. Former MITRE ATT&CKer.
DFIRDetective @DFIRDetective
1K Followers 744 Following Cassie | Summit/Conference Link Collector | Tech Enthusiast | #GCFE #GCTI #DFIR #OSINT | #LEO to #Cyber
SecuriTeeStar @SecuriTeeStar
444 Followers 457 Following FITS TO FLATTER ALL | Just Say No to the Unisex Tee | Hacker/InfoSec Apparel | Support the movement https://t.co/7Apr4GoKiO
Duane @duanehoward
177 Followers 341 Following Security Engineer, D&R @Google. Excelling at mediocrity, I run, make beer and then drink it. 🍻 Opinions are my own. pcap or it didn't happen.
Sergio Caltagirone - ... @cnoanalysis
16K Followers 1K Following President @AcademyThreat & Tech Director @GblEmancipation; Fmr @Dragosinc, @Microsoft & @NSAGov He/Him NOW AT https://t.co/ZWCsxBUFeG
Philippe Lagadec @decalage2
5K Followers 1K Following Author of oletools, olefile, ViperMonkey, ExeFilter, Balbuzard. #DFIR, #malware analysis, maldocs, file formats, #Python. @[email protected]
Josh Lemon @joshlemon
2K Followers 1K Following Chief DIFR at @SoteriaSec_io | @SANSInstitute Principal Instructor | Digital Forensics & Incident Response geek
HACKTORIA || OSINT CT... @hacktoria
16K Followers 74 Following Monthly Story Driven OSINT Capture the Flag Events 📡 #osint
unfurl🌿 @unfurl_link
56 Followers 2 Following Explore URLs using a building block approach to understand all they contain. #opensource #Python #DFIR #OSINT
Chris xorrior@infosec... @xorrior
11K Followers 1K Following @[email protected] Husband | Father | Pentester | Red Teamer | macOS security | Manager - Red Team @Zoom https://t.co/af3c0fgU2v
Brian Maloney @bmmaloney97
3K Followers 622 Following "Distrust and caution are the parents of security." - Benjamin Franklin
Kevin Holvoet @digihash
2K Followers 850 Following Cyber Threat Research Lead @CCB_Belgium/@CCBalert | #FOR578: #CTI @SANSInstitute instructor | @CuratedIntel | loves to try new things: food, beer whisky, etc.
⚛️ Marcin Siedlar... @siedlmar
2K Followers 1K Following Manager | 🇨🇳 Mission @Google GTIG | Technical attribution of cyber threats | RooCon 🇦🇺
theincidentalchewtoy @4n6chewtoy
171 Followers 22 Following Forensics – One Byte at a Time He used to byte, now its just a nibble🐕
Catalin Cimpanu @campuscodi
106K Followers 2K Following Cybersecurity reporter. I'm mostly active on BlueSky and Mastodon.
Alexandre Dulaunoy @a... @adulau
8K Followers 7K Following Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. @[email protected]
The SEINT, PhD @SEINT_pl
5K Followers 386 Following SEINT - Social Engineering and INTelligence | #OSINT & #OPSEC trainer at @securitum_com | OSINT series author on https://t.co/1T5aJXFCGO | @[email protected]
Ryan Tomcik @heferyzan
1K Followers 1K Following DE/TH @GoogleCloud @Mandiant Threat Defense | Google in the streets, Mandiant in the tweets | Thruntito ergo sum
Aaron Stephens @x04steve
3K Followers 532 Following
Jitters/Mudkip @umudkip
337 Followers 992 Following Infosec, good conversation, being an adorable Mudkip
Arman Gungor @armangungor
395 Followers 32 Following Digital forensics & software development. Contributes to @meridian & @MetaspikeHQ blogs. Tweets about #DFIR #InfoSec
Daniel Bardenstein @bardenstein
415 Followers 358 Following CTO, co-founder @ManifestCyber. Former @CISAGov, @DefenseDigital. Fellow @AspenPolicyHub. Leading @0x4Sight. Hack the Planet. Views are my own.
Will Harris @parityzero
4K Followers 803 Following Chrome Security gnome. I work on the sandbox and local data protection on Windows. @parityzero.99 on signal. Opinions here are my own!
DFIRScience @DFIRScience
4K Followers 2K Following 🕵️Digital forensics, incident response, and information security research, software, and tutorials.
Forensics Reformatted... @4n6reformatted
453 Followers 195 Following Forensics Reformatted is a Digital Forensics podcast by former Chewing the FAT hosts, Firmsky (Adam Firman) @firmsky & Cobbers (Phil Cobley) @cobbers_uk
DFIRderps @DFIRderps
66 Followers 39 Following DFIR derps, disasters and downright dirty encounters. DM me if you want to share your own DFIR derps anonymously or with credit.
Jonathan Greig @jonathan_greig
55 Followers 563 Following
Timesketch @TimesketchProj
626 Followers 0 Following Timesketch is an open-source tool for collaborative forensic timeline analysis. https://t.co/RDJ1gmHtWi
Shahar Ben-Hador @Sbenhador
61 Followers 132 Following Co-Founder @BlastRadius_AI. ex @Exabeam, @Imperva. Love solving hard problems practically. Opinions are my own.
Andy Greenberg (@agre... @a_greenberg
72K Followers 1K Following WIRED writer, author of SANDWORM and now TRACERS IN THE DARK: The Global Hunt for the Crime Lords of Cryptocurrency. Andy.01 on Signal. [email protected]





























