#toolsmith search results
So 25 years after it arrived, wrapped separately, in the box with the power saw he bought, this was unwrapped by partner today, and is now in use. 😶 #Toolsmith
Bring security data to life with #gganimate in #toolsmith 137: Animate YouR Security Analysis, based on thomasp85's excellent work. Static visualization for security analysis is effective, but a time-based, animated visualization elevates the art. …
A new post for your hopeful stuck-at-home-looking-for-something-to-nerd-out-on reading pleasure. #toolsmith 143 now available, @SpectX: Log Parser for DFIR. bit.ly/SpectX4DFIR Thanks @lii5a for an offering well worth the effort. #SpectX4DFIR #BlueTeam #infosec #DataAnalytics
#Toolsmith Snapshot: Ad Blocking With The_Pi_Hole bit.ly/PiHole, a DNS sinkhole that protects your devices from unwanted content, without installing any client-side software. If you haven't given Pi-hole a try yet, please take the opportunity t…
Thrilled to share yampelo's Beagle with you via #toolsmith 138: bit.ly/BeagleDFIR. Beagle is a #DFIR #BlueTeam powerhouse that exemplifies the vitality of #graphs & #visualization. Beagle was presented BlackHatEvents Asia ToolsWatch & looks to be a…
holisticinfosec.io
Beagle: Graph transforms for DFIR data & logs
toolsmith #138 - Graphs for DFIR analysts
Participate in @KringleCon this holiday season? You may have discovered new tools or had a chance to try one that you hadn’t before. True for me with @eric_conrad’s DeepBlueCLI, a #PowerShell threat hunting module for Windows Event Logs. #toolsmith holisticinfosec.io/post/deepbluec…
holisticinfosec.io
DeepBlueCLI: Powershell Threat Hunting
toolsmith #141
Hunt, search, and extract Windows event log records with Chainsaw, now in #toolsmith 148. Experiments with an old #DFIR malware case, as well as APT Simulator. The saw is the law! @AlexKornitzer @FranticTyping @sigma_hq @cyb3rops holisticinfosec.io/post/chainsaw/
Emulate adversary behaviors on Linux with @redcanaryco's #ChainReactor, as seen in #toolsmith 142 holisticinfosec.io/post/chain-rea… Featuring top notch audit.rules for #auditd from @cyb3rops. Reactions, atoms, and quarks, oh my! #BlueTeam #RedTeam #AdversaryEmulation Enjoy and cheers!
holisticinfosec.io
Chain Reactor: Simulate Adversary Behaviors on Linux
toolsmith #142
Zircolite versus Defense Evasion & Nobellium FoggyWeb in #toolsmith 145: a SIGMA-based detection tool for EVTX & JSON. bit.ly/zircolite Includes work from @waggabat @cyb3rops @sbousseaden @MalwareRE @SwiftOnSecurity @markrussinovich @mxatone @MITREattack in one short post.
Since I last discussed @brimsecurity use with @Cyb3rWard0g & @Cyb3rPandaH's Mordor APT29 datasets in #toolsmith 144, @OliverRochford has been hard at work for Brim, exploring further & documenting his practice well. Check out medium.com/brim-securitys… & the prior post. Great work!
medium.com
Investigating Network traffic activity using Brim and Zeek
In the last article, I shared my favourite Brim ZQL queries to begin a threat hunting investigation in Zeek data. We covered pretty…
Where else can you find @brimsecurity @Mordor_Project @MITREattack & @AmonAmarthBand🤘in one place? #toolsmith 144, of course! Join me for To the Brim at the Gates of Mordor Pt. 1 where we search & analyze Mordor APT29 PCAPs with Brim bit.ly/BrimMordor1 #blueteam #dfir #epic
.@jayjacobs I made you something.😊EPSScall is an Exploit Prediction Scoring System app now in #toolsmith 147. An #RStats Shiny app to interact with the @FIRSTdotOrg EPSS API. Use of EPSS is vital: knowledge of vuln exploit contributes to org survivability holisticinfosec.io/post/epsscall
holisticinfosec.io
EPSScall - An Exploit Prediction Scoring System App
toolsmith #147: EPSScall - Shiny app for the EPSS API
Artisan toolsmiths sharpen and temper steel blades with community-sourced charcoal, combining traditional cooling methods and modern hardness testing for performance. #Toolsmith #EdgeTech
That's awesome @holisticinfosec ! Very very happy to see the @Mordor_Project helping during testing and validation 🙏 I am releasing a few more datasets (sec events & PCAPs) during @BlueTeamVillage weekend 😉🍻 Looking forward to #toolsmith 144!
I’m using the Mordor APT29 dataset (@Cyb3rWard0g, @Cyb3rPandaH) to put the @brimsecurity desktop client though it’s paces for #toolsmith 144. Nothing like honing your hunting fu to pull out of a funk. Thanks for the awesome, all! mordordatasets.com/introduction.h…
I’m using the Mordor APT29 dataset (@Cyb3rWard0g, @Cyb3rPandaH) to put the @brimsecurity desktop client though it’s paces for #toolsmith 144. Nothing like honing your hunting fu to pull out of a funk. Thanks for the awesome, all! mordordatasets.com/introduction.h…
The old Bell Labs term for @erickhydrick's "plumber" was "toolsmith" hydrick.net/2020/11/30/roc… #toolsmith #focusonthefundamentals #fundamentalsmatter #beaplumber #noninjasneedapply #rockstaryeahright See also: antipaucity.com/2014/06/25/who…
toolsmith snapshot: r-cyber with rud.is holisticinfosec.io/post/toolsmith… #toolsmith
Check out Vintage camera! Available for the next about 22 hours via @Teespring: tspr.ng/c/new-vintage-… #toolsmith
A quick #toolsmith snapshot posted re: @spectx query, courtesy of Raido, to detect possible bots & automated queries bit.ly/spectx-ip Stand by for a full treatment on @brimsecurity in a few weeks after I wrap up this school quarter, Ch 2 of my dissertation nearly finished!
Artisan toolsmiths sharpen and temper steel blades with community-sourced charcoal, combining traditional cooling methods and modern hardness testing for performance. #Toolsmith #EdgeTech
The 150th issue of #toolsmith, a 16+ year milestone, is a deep dive into the @CISSMaryland Cyber Attacks Database, with exploratory data analysis and forecasting methods, with a lean towards #visualization holisticinfosec.io/post/eda-cissm… Useful #rstats for #blueteam sec & data analysts.
Hunt, search, and extract Windows event log records with Chainsaw, now in #toolsmith 148. Experiments with an old #DFIR malware case, as well as APT Simulator. The saw is the law! @AlexKornitzer @FranticTyping @sigma_hq @cyb3rops holisticinfosec.io/post/chainsaw/
.@jayjacobs I made you something.😊EPSScall is an Exploit Prediction Scoring System app now in #toolsmith 147. An #RStats Shiny app to interact with the @FIRSTdotOrg EPSS API. Use of EPSS is vital: knowledge of vuln exploit contributes to org survivability holisticinfosec.io/post/epsscall
holisticinfosec.io
EPSScall - An Exploit Prediction Scoring System App
toolsmith #147: EPSScall - Shiny app for the EPSS API
A supervised learning approach to Living off the Land (LotL) attack classification, in #toolsmith 146. LotL reverse shells, file uploads & coin miners, classified bad via #MachineLearning from @AdobeSecurity's Security Intelligence. #security #DataScience tinyurl.com/lotlclassifier
Zircolite versus Defense Evasion & Nobellium FoggyWeb in #toolsmith 145: a SIGMA-based detection tool for EVTX & JSON. bit.ly/zircolite Includes work from @waggabat @cyb3rops @sbousseaden @MalwareRE @SwiftOnSecurity @markrussinovich @mxatone @MITREattack in one short post.
holisticinfosec.io
Zircolite vs Defense Evasion & Nobellium FoggyWeb
toolsmith #145: a standalone SIGMA-based detection tool for EVTX and JSON
Check out Vintage camera! Available for the next about 22 hours via @Teespring: tspr.ng/c/new-vintage-… #toolsmith
#toolsmith favorite SpectX has launched support for analyzing Windows Events (.evtx files) to investigate incidents and find suspicious activity on Windows systems. #BlueTeam #DFIR #ThreatHunting spectx.com/articles/analy…
A #toolsmith snapshot utilizing @Icemoonhsv's Sim for #AdversaryEmulation is available for your review & consideration. A ton of potential for Sim in #detection testing scenarios for #blueteam #DFIR #DART and others. Well done, Hope. bit.ly/sim4emu
Seeking an escape from the chaos of U.S. national news I posted a long overdue #toolsmith snapshot of @mhgeay's Gordon for cyber reputation checks via threat & risk information about IOCs such as IP addresses, hashes & domains. bit.ly/GordonIOC #BlueTeam #DFIR #SolarWinds
The old Bell Labs term for @erickhydrick's "plumber" was "toolsmith" hydrick.net/2020/11/30/roc… #toolsmith #focusonthefundamentals #fundamentalsmatter #beaplumber #noninjasneedapply #rockstaryeahright See also: antipaucity.com/2014/06/25/who…
#toolsmith snapshot: Sooty, a SOC Analyst's All-in-One Tool to help speed up SOC workflow. I've been using it regularly as I'm currently in a daily hunt work load, and find it quite useful to speed up initial triage. #SOC #BlueTeam #DFIR #Sooty bit.ly/Sooty4SOC
Cybersecurity - Mitre ATT&ACK. Discover the best articles of the week: 16.10.2020 buff.ly/3k4ak7P #toolsmith #cybersecurity #ransomware
Since I last discussed @brimsecurity use with @Cyb3rWard0g & @Cyb3rPandaH's Mordor APT29 datasets in #toolsmith 144, @OliverRochford has been hard at work for Brim, exploring further & documenting his practice well. Check out medium.com/brim-securitys… & the prior post. Great work!
medium.com
Investigating Network traffic activity using Brim and Zeek
In the last article, I shared my favourite Brim ZQL queries to begin a threat hunting investigation in Zeek data. We covered pretty…
Where else can you find @brimsecurity @Mordor_Project @MITREattack & @AmonAmarthBand🤘in one place? #toolsmith 144, of course! Join me for To the Brim at the Gates of Mordor Pt. 1 where we search & analyze Mordor APT29 PCAPs with Brim bit.ly/BrimMordor1 #blueteam #dfir #epic
That's awesome @holisticinfosec ! Very very happy to see the @Mordor_Project helping during testing and validation 🙏 I am releasing a few more datasets (sec events & PCAPs) during @BlueTeamVillage weekend 😉🍻 Looking forward to #toolsmith 144!
I’m using the Mordor APT29 dataset (@Cyb3rWard0g, @Cyb3rPandaH) to put the @brimsecurity desktop client though it’s paces for #toolsmith 144. Nothing like honing your hunting fu to pull out of a funk. Thanks for the awesome, all! mordordatasets.com/introduction.h…
I’m using the Mordor APT29 dataset (@Cyb3rWard0g, @Cyb3rPandaH) to put the @brimsecurity desktop client though it’s paces for #toolsmith 144. Nothing like honing your hunting fu to pull out of a funk. Thanks for the awesome, all! mordordatasets.com/introduction.h…
Now in #toolsmith: Faraday IPE - When Tinfoil Won’t Work for Pentesting bit.ly/1M5Hc9u @fede_k @faradaysec
I'm a few days late, but #SET on my screen again while I watch Mr. Robot makes me so happy, @HackingDave #toolsmith
Close race, we have a winner! @joshsokol's @simpleriskfree voted Best of #toolsmith's 10 yrs. I'll donate to charity of his choice in honor.
Good tutorial from @HackingTutors re: Dynamic Malware Analysis Tools hackingtutorials.org/malware-analys… #toolsmith #DFIR #malware cc @cyb3rops
Now in #toolsmith 140, @EricRZimmerman’s #KAPE vs @Mandiant ’s Commando, a #blueteam vs #redteam vignette. KAPE=brilliant, the love it receives is worthy. bit.ly/KAPE-TS. Endless opportunities to come in behind #RedTeam & clean up their rainbow unicorn skittles doodie
As a longtime @PwnieExpress supporter (#toolsmith), thrilled to see #PwnPhone on #MrRobot. Congrats, well deserved.
Compiled & testing @_vivami's #SauronEye for a little #toolsmith feature. It's fast & capable as Vincent says it is. github.com/vivami/SauronE… This is a great tool for scraping drives & shares for sensitive unstructured data, because no one ever leaves passwords in cleartext files
In the midst of writing #toolsmith on @KevTheHermit's VolUtility when much to my pleasure...this. Well played, sir.
Thrilled to share @yampelo's Beagle with you via #toolsmith 138: bit.ly/BeagleDFIR. Beagle is a #DFIR #BlueTeam powerhouse that exemplifies the vitality of #graphs & #visualization. Beagle was presented @BlackHatEvents Asia @ToolsWatch & looks to be a real game changer. Go!
Bring security data to life with #gganimate in #toolsmith 137: Animate YouR Security Analysis, based on thomasp85's excellent work. Static visualization for security analysis is effective, but a time-based, animated visualization elevates the art. …
#Toolsmith Snapshot: Ad Blocking With @The_Pi_Hole bit.ly/PiHole, a DNS sinkhole that protects your devices from unwanted content, without installing any client-side software. If you haven't given Pi-hole a try yet, please take the opportunity to do so. #RaspberryPi
Bring security data to life with #gganimate in #toolsmith 137: Animate YouR Security Analysis, based on @thomasp85's excellent work. Static visualization for security analysis is effective, but a time-based, animated visualization elevates the art. bit.ly/animatedata #rstats
A new post for your hopeful stuck-at-home-looking-for-something-to-nerd-out-on reading pleasure. #toolsmith 143 now available, @SpectX: Log Parser for DFIR. bit.ly/SpectX4DFIR Thanks @lii5a for an offering well worth the effort. #SpectX4DFIR #BlueTeam #infosec #DataAnalytics
HolisticInfoSec: #toolsmith #114: #WireEdit & Deep Packet Modification from@holisticinfosec buff.ly/1U7lDdw
So 25 years after it arrived, wrapped separately, in the box with the power saw he bought, this was unwrapped by partner today, and is now in use. 😶 #Toolsmith
#Toolsmith Snapshot: Ad Blocking With The_Pi_Hole bit.ly/PiHole, a DNS sinkhole that protects your devices from unwanted content, without installing any client-side software. If you haven't given Pi-hole a try yet, please take the opportunity t…
Thrilled to share yampelo's Beagle with you via #toolsmith 138: bit.ly/BeagleDFIR. Beagle is a #DFIR #BlueTeam powerhouse that exemplifies the vitality of #graphs & #visualization. Beagle was presented BlackHatEvents Asia ToolsWatch & looks to be a…
holisticinfosec.io
Beagle: Graph transforms for DFIR data & logs
toolsmith #138 - Graphs for DFIR analysts
Something went wrong.
Something went wrong.
United States Trends
- 1. Purdy 22.6K posts
- 2. #WWERaw 44.5K posts
- 3. Panthers 28.2K posts
- 4. Mac Jones 4,335 posts
- 5. Penta 6,716 posts
- 6. 49ers 30.3K posts
- 7. Jaycee Horn 2,191 posts
- 8. Gunther 12.2K posts
- 9. #KeepPounding 4,500 posts
- 10. Canales 10.5K posts
- 11. Melo 17.1K posts
- 12. #FTTB 4,080 posts
- 13. Niners 4,294 posts
- 14. #RawOnNetflix 1,699 posts
- 15. #MondayNightFootball N/A
- 16. Mark Kelly 158K posts
- 17. Kittle 3,110 posts
- 18. 3 INTs 2,030 posts
- 19. Joe Buck N/A
- 20. Rico Dowdle 1,127 posts