scudette's profile picture. Digital Paleontologist, digging deeper

Mike Cohen

@scudette

Digital Paleontologist, digging deeper

It was awesome to be at the @AusCERT conference this year - What an amazing event and I learned so much! See you all next year!

At @AusCERT conference we presented "Sigma and Detection Engineering with @velocidex Velociraptor". Learn how to implement real time Sigma detection with forensic enhancements. Full presentation youtube.com/watch?v=3EBrpF… and slides docs.velociraptor.app/presentations/…

velocidex's tweet card. Auscert 2025 Detection Engineering Workshop

youtube.com

YouTube

Auscert 2025 Detection Engineering Workshop



Mike Cohen 已轉發

At @AusCERT conference we presented "Sigma and Detection Engineering with @velocidex Velociraptor". Learn how to implement real time Sigma detection with forensic enhancements. Full presentation youtube.com/watch?v=3EBrpF… and slides docs.velociraptor.app/presentations/…

velocidex's tweet card. Auscert 2025 Detection Engineering Workshop

youtube.com

YouTube

Auscert 2025 Detection Engineering Workshop


Mike Cohen 已轉發

Looking forward to speaking on a panel at the @rapid7 Take Command Summit. Register for free below as we talk about between pen testing, red teaming and the benefits of running regular security exercises. rapid7.brighttalk.com/?utm_source=re…


Mike Cohen 已轉發

Velociraptor release 0.73 is now available for testing! Read about all the cool new features here docs.velociraptor.app/blog/2024/2024… . An exciting new feature is built in timelining capability. Check the blog post here docs.velociraptor.app/blog/2024/2024…


Mike Cohen 已轉發

Great example of VQL automation!

For any velociraptor users - I have been messing around with plyara over the last week and created a few bulk yara artifacts using Yara-Forge - yarahq.github.io. Velociraptor artifacts: File - github.com/mgreen27/Detec… Process github.com/mgreen27/Detec…



Mike Cohen 已轉發

The incident started with a compromised server. When we extended the hunting to the entire network, we found traces of the "WayBack" campaign on a computer, which @yoroisecurity documented almost exactly three years ago [1]. We also found the exact same code as in the blog on…

malmoeb's tweet image. The incident started with a compromised server. When we extended the hunting to the entire network, we found traces of the "WayBack" campaign on a computer, which @yoroisecurity documented almost exactly three years ago [1].

We also found the exact same code as in the blog on…

I was so excited about the new 0.72 release of Velociraptor I just could not wait to make a quick video to show you all the new features! #velociraptor #dfir #digitalforensics Check it out here youtube.com/watch?v=FwmFYm…

scudette's tweet card. Velociraptor Release 0.72 Video Walkthrough

youtube.com

YouTube

Velociraptor Release 0.72 Video Walkthrough


Mike Cohen 已轉發

Version 0.7.2 of @velocidex is now fully available for download! Learn what's new 👉 r-7.co/3WliUVJ

rapid7's tweet image. Version 0.7.2 of @velocidex is now fully available for download! Learn what's new 👉 r-7.co/3WliUVJ
rapid7's tweet image. Version 0.7.2 of @velocidex is now fully available for download! Learn what's new 👉 r-7.co/3WliUVJ
rapid7's tweet image. Version 0.7.2 of @velocidex is now fully available for download! Learn what's new 👉 r-7.co/3WliUVJ

Only a few days left to secure your early bird for our Velociraptor training in Singapore. This is a rare opportunity to learn about Velociraptor and how to deploy it effectively, develop VQL artifacts and actively hunt for adversaries. blackhat.com/asia-24/traini…


Mike Cohen 已轉發

#100daysofyara targeting QuasarRAT via namespace strings observed in process memory and decompiled code. #R7Labs @velocidex Windows.Detection.Yara.Process only returns one hit per process here as I added some groupings to minimise any FPs github.com/rapid7/Rapid7-…

mgreen27's tweet image. #100daysofyara targeting QuasarRAT via namespace strings observed in process memory and decompiled code.  #R7Labs 

@velocidex  Windows.Detection.Yara.Process only returns one hit per process here as I added some groupings to minimise any FPs

github.com/rapid7/Rapid7-…
mgreen27's tweet image. #100daysofyara targeting QuasarRAT via namespace strings observed in process memory and decompiled code.  #R7Labs 

@velocidex  Windows.Detection.Yara.Process only returns one hit per process here as I added some groupings to minimise any FPs

github.com/rapid7/Rapid7-…

Mike Cohen 已轉發

Another #100daysofyara post - #R7Labs Source a couple of samples: bazaar.abuse.ch/browse/tag/Soc… Running @velocidex Windows.Detection.Yara.Process in should detect on a running final payloads. I have focused on simple network connection & config filename strings.…

mgreen27's tweet image. Another #100daysofyara post - #R7Labs

Source a couple of samples:
bazaar.abuse.ch/browse/tag/Soc…

Running @velocidex  Windows.Detection.Yara.Process in should detect on a running final payloads. I have focused on simple network connection & config filename strings.…
mgreen27's tweet image. Another #100daysofyara post - #R7Labs

Source a couple of samples:
bazaar.abuse.ch/browse/tag/Soc…

Running @velocidex  Windows.Detection.Yara.Process in should detect on a running final payloads. I have focused on simple network connection & config filename strings.…

Mike Cohen 已轉發

Thought I would make some posts for #100daysofyara. Not sure how often i'll post but good chance to test some triage workflow and build some pratical Velociraptor rules for automation :) In the example below I grabbed a NanoCore sample from MalwareBazaar -…

mgreen27's tweet image. Thought I would make some posts for #100daysofyara. Not sure how often i'll post but good chance to test some triage workflow and build some pratical Velociraptor rules for automation :)

In the example below I grabbed a NanoCore sample from MalwareBazaar -…
mgreen27's tweet image. Thought I would make some posts for #100daysofyara. Not sure how often i'll post but good chance to test some triage workflow and build some pratical Velociraptor rules for automation :)

In the example below I grabbed a NanoCore sample from MalwareBazaar -…

Mike Cohen 已轉發

We're incredibly thankful to our wonderful community of contributors, testers and enthusiasts! Without you, Velociraptor wouldn't be what it is. To all of you, your family and friends, HAPPY THANKSGIVING!

velocidex's tweet image. We're incredibly thankful to our wonderful community of contributors, testers and enthusiasts!  Without you, Velociraptor wouldn't be what it is.

To all of you, your family and friends, HAPPY THANKSGIVING!

Mike Cohen 已轉發

Want a sneak peek at the upcoming Velociraptor v0.7.1? With awesome new capabilities like built in Sigma integration and enhanced notebook functionality, you will want to download the release candidate today and test it out. Be sure to log any bugs or issues through GitHub.…


Mike Cohen 已轉發

Sharing out my workshop from DEATHcon. mgreen27.notion.site/mgreen27/Veloc… Fun to showcase some of the similar workflows I do day to day. @Velocidex #dfir DEATHcon was put on by @rpargman @olafhartong @th3cyF0x its a really unique event - thank you!


Mike Cohen 已轉發

Pushed out a Velociraptor artifact to scope some of the items in the SysAid post exploitation activity. docs.velociraptor.app/exchange/artif… @velocidex

⚠️ On November 8, SysAid disclosed CVE-2023-47426, a zero-day path traversal vulnerability affecting on-premise SysAid servers. Microsoft warns that exploitation is likely to result in ransomware deployment and/or data exfiltration. Read more in our blog: bit.ly/3QA4gFI



Mike Cohen 已轉發

If you missed VeloCon23, all talks are available on YouTube and the website. docs.velociraptor.app/presentations/… #dfir #cybersecurity #rapid7


Mike Cohen 已轉發

While there are many great articles that discuss logs to be sent to a SIEM, many don't mention filtering on the endpoint during investigations. This is an area in which @velocidex excels. 🦖🚀 #FastForensicsBeforeFullSendIt #LogManagementMusts #SaveTheSIEM #SplunkCostBoss


Mike Cohen 已轉發

If you like us here, you'll LOVE us on Discord. Come join the smartest and most lively #DFIR community on the planet. discord.com/invite/YAU3vRE

velocidex's tweet image. If you like us here, you'll LOVE us on Discord.  Come join the smartest and most lively #DFIR community on the planet. 

discord.com/invite/YAU3vRE

Loading...

Something went wrong.


Something went wrong.