codeyourweb's profile picture. Adversary Hunter && Threat Researcher - ♥infosec, code and mojitos - Opinions are mine

Jean-Pierre GARNIER

@codeyourweb

Adversary Hunter && Threat Researcher - ♥infosec, code and mojitos - Opinions are mine

Pinned

#Fastfinder v2.0.0 just released! cross-platform #DFIR #IOC / #YARA file finder. Now with triage mode, logger, enhanced UI and linux/windows builder to deploy this awesome scanner on every host (even with ciphered rules and config file) github.com/codeyourweb/fa…

codeyourweb's tweet image. #Fastfinder v2.0.0 just released! cross-platform #DFIR #IOC / #YARA file finder. Now with triage mode, logger, enhanced UI and linux/windows builder to deploy this awesome scanner on every host (even with ciphered rules and config file)
github.com/codeyourweb/fa…
codeyourweb's tweet image. #Fastfinder v2.0.0 just released! cross-platform #DFIR #IOC / #YARA file finder. Now with triage mode, logger, enhanced UI and linux/windows builder to deploy this awesome scanner on every host (even with ciphered rules and config file)
github.com/codeyourweb/fa…
codeyourweb's tweet image. #Fastfinder v2.0.0 just released! cross-platform #DFIR #IOC / #YARA file finder. Now with triage mode, logger, enhanced UI and linux/windows builder to deploy this awesome scanner on every host (even with ciphered rules and config file)
github.com/codeyourweb/fa…

Jean-Pierre GARNIER reposted

New blog post: Tear Down The Castle - Part 2 dfir.ch/posts/tear_dow… I analyzed 250 PingCastle Reports, grouping the findings along the categories I used for my 10 AD Commandments series. The number of affected domains is stated within each finding, i.e., in how many domains we…

malmoeb's tweet image. New blog post: Tear Down The Castle - Part 2
dfir.ch/posts/tear_dow…

I analyzed 250 PingCastle Reports, grouping the findings along the categories I used for my 10 AD Commandments series.

The number of affected domains is stated within each finding, i.e., in how many domains we…

Jean-Pierre GARNIER reposted

Many missed this on #BadSuccessor: it’s also a credential dumper. I wrote a simple PowerShell script that uses Rubeus to dump Kerberos keys and NTLM hashes for every principal-krbtgt, users, machines. no DCSync required, no code execution on DC.


And here's a little project to monitor network traffic and logging directly over endpoints interfaces. First proof-of-concept with local pcap and HTTP API forwarder (fully tested on #SEKOIA plaftform). github.com/codeyourweb/lp… #soc #cybersecurity #networksecurity


Jean-Pierre GARNIER reposted

Quel génie a fait ça ??? 🤣🤣🤣 #Ukraine #Russie #USA


Jean-Pierre GARNIER reposted

Microsoft has released its own document parser for LLM use! . . Introducing MarkItDown, a 100% open-source, one-stop solution for effortlessly converting any file to Markdown—perfect for text analysis, indexing, and more! Here’s what makes it special: ↳ Converts PDF, Word,…

akshay_pachaar's tweet image. Microsoft has released its own document parser for LLM use!
.
.
Introducing MarkItDown, a 100% open-source, one-stop solution for effortlessly converting any file to Markdown—perfect for text analysis, indexing, and more!

Here’s what makes it special:

↳ Converts PDF, Word,…

Jean-Pierre GARNIER reposted

Reviews are MOSTLY NEGATIVE - Gray Zone Warfare vid is up on yt #GZW #GrayZoneWarfare

Eroktic's tweet image. Reviews are MOSTLY NEGATIVE - Gray Zone Warfare
vid is up on yt #GZW #GrayZoneWarfare

Jean-Pierre GARNIER reposted

Kudos to @DragosInc for sharing details of a recent event. The adversary compromised a new employee's personal email address and impersonated them to get access. How would you protect against that?


Jean-Pierre GARNIER reposted

I remember a time when people here in Europe still had issues storing their corporate emails on US mail servers - nowadays you store the master keys to your company on their servers 🎵 … for the times they are a-changin'

Did you know that Microsoft recommends creating your Global Admin accounts in the cloud to protect Microsoft 365 from on-premises attacks? See aka.ms/protectm365 for all the details.

merill's tweet image. Did you know that Microsoft recommends creating your Global Admin accounts in the cloud to protect Microsoft 365 from on-premises attacks?

See aka.ms/protectm365 for all the details.


Jean-Pierre GARNIER reposted

Priorities


Jean-Pierre GARNIER reposted

[Android] Une trentaine de "Privacy Friendly Apps" proposées par @SECUSOResearch qui : - are Open Source (GPLv3) and their source code can be viewed an Github by anybody - used minimal permissions - do not neither tracking mechanisms nor advertisement secuso.aifb.kit.edu/english/105.php

framaka's tweet image. [Android] Une trentaine de "Privacy Friendly Apps" proposées par @SECUSOResearch qui :
- are Open Source (GPLv3) and their source code can be viewed an Github by anybody
- used minimal permissions
- do not neither tracking mechanisms nor advertisement
secuso.aifb.kit.edu/english/105.php

Jean-Pierre GARNIER reposted

Unable to extract credentials via DPAPI or Mimikatz? Don't worry. Microsoft got your back. Just use 'rundll32 keymgr.dll, KRShowKeyMgr' to extract all the stored passwords on the host, be it a target server, FTP or chrome's HTTP creds, microsoft has you covered. #redteam

NinjaParanoid's tweet image. Unable to extract credentials via DPAPI or Mimikatz? Don't worry. Microsoft got your back. Just use 'rundll32 keymgr.dll, KRShowKeyMgr' to extract all the stored passwords on the host, be it a target server, FTP or chrome's HTTP creds, microsoft has you covered. #redteam

Jean-Pierre GARNIER reposted

Possibly #Lazarus related #maldoc: "LMCO_Senior Systems Engineer_BR09.doc" virustotal.com/gui/file/8e2fb… CnCs: https://monitorr.jamdown[.]co[.]nz/assets/data/css/custom.php http://13.88.245[.]250/admin/install/custom.php http://mantis.binarysemantics[.]com/extra/map/map.php


Jean-Pierre GARNIER reposted

GitHub - claroty/arya: Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA. github.com/claroty/arya


Jean-Pierre GARNIER reposted

New: North Korea has taken a page out of China's cyber playbook to reorganize and consolidate its threat groups within the government - making them “extremely mobile now that they’ve consolidated.” Here's a first look at their new org structure 👇 mandiant.com/resources/mapp…

Mandiant's tweet image. New: North Korea has taken a page out of China's cyber playbook to reorganize and consolidate its threat groups within the government - making them “extremely mobile now that they’ve consolidated.” Here's a first look at their new org structure 👇
mandiant.com/resources/mapp…

Jean-Pierre GARNIER reposted

The 2022 Threat Detection Report is out! Join us in counting down the most prevalent threats we encountered in our customers' environments last year. We'll reveal a new threat every hour in this thread (Or just download the report & see them all now) redcanary.com/resources/guid…


Jean-Pierre GARNIER reposted

#Lazarus #APT #maldoc: JD.docx 854903e0b284ef78322082de46dcd160 Remote template: https://pvacek[.]cz/wp-content/plugins/akismet/control/en/en.jpg

h2jazi's tweet image. #Lazarus #APT #maldoc:

JD.docx
854903e0b284ef78322082de46dcd160

Remote template:
https://pvacek[.]cz/wp-content/plugins/akismet/control/en/en.jpg

Jean-Pierre GARNIER reposted

Our statement in regard to the warning of German Federal Office for Information Security (BSI) Unser Statement zur Warnung des Bundesministeriums für Sicherheit in der Informationstechnik (BSI)

kaspersky's tweet image. Our statement in regard to the warning of German Federal Office for Information Security (BSI)

Unser Statement zur Warnung des Bundesministeriums für Sicherheit in der Informationstechnik (BSI)
kaspersky's tweet image. Our statement in regard to the warning of German Federal Office for Information Security (BSI)

Unser Statement zur Warnung des Bundesministeriums für Sicherheit in der Informationstechnik (BSI)
kaspersky's tweet image. Our statement in regard to the warning of German Federal Office for Information Security (BSI)

Unser Statement zur Warnung des Bundesministeriums für Sicherheit in der Informationstechnik (BSI)
kaspersky's tweet image. Our statement in regard to the warning of German Federal Office for Information Security (BSI)

Unser Statement zur Warnung des Bundesministeriums für Sicherheit in der Informationstechnik (BSI)

Jean-Pierre GARNIER reposted

[détournement d'IA] Pour le choix de la photo d'avatar, il suffit d'aller sur ce genre de sites : this-person-does-not-exist.com/fr

framaka's tweet image. [détournement d'IA] Pour le choix de la photo d'avatar, il suffit d'aller sur ce genre de sites : 
this-person-does-not-exist.com/fr

Jean-Pierre GARNIER reposted

A list in #python can contain itself as an element!

nedbat's tweet image. A list in #python can contain itself as an element!

Loading...

Something went wrong.


Something went wrong.