DCDataReaper's profile picture. #DFIR
I like Technology, Security, Memes, and the occasional Video Game.
29y/o Husband and father to our pets.
GCFE GCFA GASF GCFR

Daren Cook

@DCDataReaper

#DFIR I like Technology, Security, Memes, and the occasional Video Game. 29y/o Husband and father to our pets. GCFE GCFA GASF GCFR

Daren Cook đã đăng lại

Teaser: we're working on a new #YARA module to enhance in-memory matching, allowing detection engineers to craft more precise rules. Stay tuned

cyb3rops's tweet image. Teaser: we're working on a new #YARA module to enhance in-memory matching, allowing detection engineers to craft more precise rules. Stay tuned

Daren Cook đã đăng lại

So, the security of your employees' private Google accounts now determines the effectiveness of your MFA. I guess it's a good idea to routinely check their Google accounts on haveibeenpwned.com - haha bleepingcomputer.com/news/security/…

cyb3rops's tweet image. So, the security of your employees' private Google accounts now determines the effectiveness of your MFA. I guess it's a good idea to routinely check their Google accounts on haveibeenpwned.com - haha

bleepingcomputer.com/news/security/…

Daren Cook đã đăng lại

Some folks I met weren't familiar with our Sigma extension for VSCode

Our Sigma rule extension for @code got a major update by my team member @paulhagertheo It allows lookups of similar and related rules & uses a new web service to do that it's still new & only superficially tested - feedback & bug reports are welcome marketplace.visualstudio.com/items?itemName…

cyb3rops's tweet image. Our Sigma rule extension for @code got a major update by my team member @paulhagertheo 

It allows lookups of similar and related rules & uses a new web service to do that

it's still new & only superficially tested - feedback & bug reports are welcome

marketplace.visualstudio.com/items?itemName…
cyb3rops's tweet image. Our Sigma rule extension for @code got a major update by my team member @paulhagertheo 

It allows lookups of similar and related rules & uses a new web service to do that

it's still new & only superficially tested - feedback & bug reports are welcome

marketplace.visualstudio.com/items?itemName…
cyb3rops's tweet image. Our Sigma rule extension for @code got a major update by my team member @paulhagertheo 

It allows lookups of similar and related rules & uses a new web service to do that

it's still new & only superficially tested - feedback & bug reports are welcome

marketplace.visualstudio.com/items?itemName…
cyb3rops's tweet image. Our Sigma rule extension for @code got a major update by my team member @paulhagertheo 

It allows lookups of similar and related rules & uses a new web service to do that

it's still new & only superficially tested - feedback & bug reports are welcome

marketplace.visualstudio.com/items?itemName…


Daren Cook đã đăng lại

NEW VIDEO!! My Channel Was Deleted Last Night. youtu.be/yGXaAWbzl5A #sponsoredby @dbrand

LinusTech's tweet image. NEW VIDEO!! My Channel Was Deleted Last Night.
youtu.be/yGXaAWbzl5A

#sponsoredby @dbrand

Daren Cook đã đăng lại

Hey there 👋 Are you interested in: - Linux - Linux commands - Linux Tips - Shell Scripting - Bash Tips - Linux cheatsheets - Sysadmin - Tips for those who are unfamiliar with Linux - More Linux Stuff Follow us ✅ We share daily 📅 content that you won't want to miss.


Daren Cook đã đăng lại

Now through Dec 14th! Take $600 off any @SANSInstitute #DFIR course at #SANSCDI 👉sans.org/u/1nIh #FOR500✔️ #FOR508✔️ #FOR578✔️ #FOR509✔️ #FOR610✔️ #FOR710✔️ #FOR528✔️ Learn about the offer 👇 sans.org/u/1nH9

sansforensics's tweet image. Now through Dec 14th! Take $600 off any @SANSInstitute #DFIR course at #SANSCDI 👉sans.org/u/1nIh 
#FOR500✔️
#FOR508✔️
#FOR578✔️
#FOR509✔️
#FOR610✔️
#FOR710✔️
#FOR528✔️
Learn about the offer 👇
sans.org/u/1nH9

Daren Cook đã đăng lại

The #WindowsForensicAnalysis poster has been revised to support modern Windows investigations! Use it as a cheat sheet of WinXP - Windows 11 operating system artifacts & a means to discover important artifacts. Download now! 👉sans.org/u/1nNm @chadtilbury @4enzikat0r

sansforensics's tweet image. The #WindowsForensicAnalysis poster has been revised to support modern Windows investigations! Use it as a cheat sheet of WinXP - Windows 11 operating system artifacts & a means to discover important artifacts. 
Download now! 👉sans.org/u/1nNm
@chadtilbury  @4enzikat0r

This was a great first year and first conference for me, thank you to all who made it possible! #DFIRSummit

Thank you to all our speakers, advisory boards, summit chairs, attendees and everyone that made an awesome 15th #DFIRSummit 2022! See you all next year for our sweet 16th!

DFIRSummit's tweet image. Thank you to all our speakers, advisory boards, summit chairs, attendees and everyone that made an awesome 15th #DFIRSummit 2022! See you all next year for our sweet 16th!


Daren Cook đã đăng lại

Released at the #DFIRSummit today: New to DFIR Field Manual featuring 10 ways to get started in #DFIR (Free download!) dfir.to/new2dfirmanual

hexplates's tweet image. Released at the #DFIRSummit today: New to DFIR Field Manual featuring 10 ways to get started in #DFIR (Free download!) dfir.to/new2dfirmanual

Daren Cook đã đăng lại

We are ready for tomorrow’s #DFIRSummit Are you?

sansforensics's tweet image. We are ready for tomorrow’s #DFIRSummit  Are you?

Join the SANS #DFIR community Live Online or in Austin, TX for #DFIRSummit this year. Enjoy top #DFIR talks, a #threathunting track, a DFIR solutions track, and incredible networking! #digitalforensics Register Today: sans.org/u/1kLd youtube.com/watch?v=BPLHpc…

sansforensics's tweet card. DFIR Summit 2022

youtube.com

YouTube

DFIR Summit 2022



Just passed my GCFE today, first cert for me and it won't be my last. Thanks again to @SANSInstitute @sansforensics and teacher @HeatherMahalik #FOR500


Daren Cook đã đăng lại

Windows security log quick reference for SOC Analysts #CyberSecurity

LetsDefendIO's tweet image. Windows security log quick reference for SOC Analysts

#CyberSecurity

Nowhere is safe apparently.

DCDataReaper's tweet image. Nowhere is safe apparently.

Daren Cook đã đăng lại

Today is the day - Noon to 5 p.m. EST! It's the @WWHackinFest Purple Team Roundup time, don't miss the opportunity to learn from this cast of presenters. You still have time to register: lnkd.in/g9KbAG_k

WWHackinFest's tweet image. Today is the day - Noon to 5 p.m. EST! It's the @WWHackinFest  Purple Team Roundup time, don't miss the opportunity to learn from this cast of presenters. You still have time to register: lnkd.in/g9KbAG_k

Daren Cook đã đăng lại

This report will be out tomorrow! You'll see mentions of #CobaltStrike, #Conti, #BazarLoader, AdFind, ShareFinder, Rclone, Process Hacker, RDP, AnyDesk, and more. cc: @Kostastsale @pigerlin @_pete_0

TheDFIRReport's tweet image. This report will be out tomorrow!

You'll see mentions of #CobaltStrike, #Conti, #BazarLoader, AdFind, ShareFinder, Rclone, Process Hacker, RDP, AnyDesk, and more.

cc: @Kostastsale @pigerlin @_pete_0
TheDFIRReport's tweet image. This report will be out tomorrow!

You'll see mentions of #CobaltStrike, #Conti, #BazarLoader, AdFind, ShareFinder, Rclone, Process Hacker, RDP, AnyDesk, and more.

cc: @Kostastsale @pigerlin @_pete_0
TheDFIRReport's tweet image. This report will be out tomorrow!

You'll see mentions of #CobaltStrike, #Conti, #BazarLoader, AdFind, ShareFinder, Rclone, Process Hacker, RDP, AnyDesk, and more.

cc: @Kostastsale @pigerlin @_pete_0
TheDFIRReport's tweet image. This report will be out tomorrow!

You'll see mentions of #CobaltStrike, #Conti, #BazarLoader, AdFind, ShareFinder, Rclone, Process Hacker, RDP, AnyDesk, and more.

cc: @Kostastsale @pigerlin @_pete_0

This one ends in #Conti ransomware. Report out in a few weeks! Thanks @James_inthe_box! C2, beacon config, ransomware files, artifacts, etc. available @ thedfirreport.com/services/



So should we consider Michael Myers an APT? #cybersecurity #CybersecurityAwarenessMonth


Daren Cook đã đăng lại

Reached out to employee trying to use unapproved tool for sensitive business data. Turns out they had the approved tool, but they've put in requests and its not on their new laptop and nobody was fixing it. Keep in kind how much noncompliance is actually IT's own fault.


Daren Cook đã đăng lại

If you haven't yet, as soon as possible run the following command on ALL of your AD CAs: certutil.exe -setreg CA\AuditFilter 127 This will enable all of the logging you will need to catch many of the attacks detailed in @harmj0y @tifkin_ 's awesome work

mubix's tweet image. If you haven't yet, as soon as possible run the following command on ALL of your AD CAs:

certutil.exe -setreg CA\AuditFilter 127

This will enable all of the logging you will need to catch many of the attacks detailed in @harmj0y @tifkin_ 's awesome work

Loading...

Something went wrong.


Something went wrong.