Kostas
@kostastsale.bsky.social
๐ค 1350
๐ฅ 125
๐ 331
@thedfirreport.bsky.social
|
https://kostas.page
| Opinions are mine only! ๐ฌ๐ท๐จ๐ฆ
Here we go againโฆ F5 disclosed a serious intrusion by a sophisticated nation-state threat actor who gained long-term access and stole files from their development and knowledge systems. Likely potential source code and undisclosed ready to exploit. 1/
loading . . .
myF5
https://my.f5.com/manage/s/article/K000154696
about 4 hours ago
1
0
0
๐ฃ๐ฎ๐ฑ๐๐ถ๐๐ต ๐๐๐ฅ ๐ฏ๐ฒ๐ฐ๐ผ๐บ๐ฒ๐ ๐๐ต๐ฒ 21๐๐ ๐ฎ๐ฑ๐ฑ๐ถ๐๐ถ๐ผ๐ป ๐๐ผ ๐๐ต๐ฒ ๐๐๐ฅ ๐ง๐ฒ๐น๐ฒ๐บ๐ฒ๐๐ฟ๐ ๐๐ผ๐บ๐ฝ๐ฎ๐ฟ๐ถ๐๐ผ๐ป ๐ฅ Love seeing emerging vendors push this level of real-time telemetry, solid visibility through ETW, AMSI, and mini-filters. ๐ง๐ฟ๐ฎ๐ป๐๐ฝ๐ฎ๐ฟ๐ฒ๐ป๐ฐ๐ like this helps move the whole industry forward. Results:ย
www.edr-telemetry.com/windows
1 day ago
0
1
0
๐๐ฒ๐๐ฒ๐ฐ๐๐ถ๐ผ๐ป ๐ฆ๐๐ฟ๐ฒ๐ฎ๐บ ๐จ๐ฝ๐ฑ๐ฎ๐๐ฒ: Two highly requested features just went live ๐ 1. ๐๐ฒ๐ฒ๐ฝ ๐๐ถ๐ป๐ธ๐: share specific rules via hashtag#rule_id or full YAML 2. ๐๐ผ๐๐ป๐น๐ผ๐ฎ๐ฑ ๐ฅ๐๐น๐ฒ๐: export all rules matching your filters (gzip) 3. ๐๐ฑ๐ฑ๐ฒ๐ฑ "๐๐ณ๐ฆ๐ข๐ต๐ฆ ๐ณ๐ถ๐ญ๐ฆ๐ด ๐ธ๐ช๐ต๐ฉ ๐๐" functionality for both ๐ฌ๐ฎ๐ฟ๐ฎ and ๐ก๐ผ๐๐ฎ frameworks ... continue๐
3 days ago
1
3
0
I built this tool for myself. Shared a preview here a few days agoโฆ and wow. Didnโt expect such a strong response. Thanks everyone who reached out ๐ Because of that energy, I pushed harder and: โก๏ธ Polished the Sigma experience, now with Nova integrated โก๏ธ Built two playgrounds for hands-on learning
17 days ago
1
2
0
I've built this platform for myself to quickly search and create detection rules. Considering that we(the DE community) have amazing platforms like Sigconverter (
sigconverter.io
) and (detection fyi)
detection.fyi
, would anyone find value in having FREE access to this all-in-one platform?
20 days ago
2
6
0
The EDR Telemetry Project revealed what EDRs can see. โ Now, we show how they compare. Coming soon!
22 days ago
0
4
1
There is still time to register:
dfirlabs.thedfirreport.com/dfirchallenge
loading . . .
24 days ago
0
1
0
๐ข Excited to share that ๐๐ข๐ญ๐๐๐๐๐ง๐๐๐ซ ๐๐๐ (GravityZone Business Security Enterprise) is now part of the ๐๐๐ ๐๐๐ฅ๐๐ฆ๐๐ญ๐ซ๐ฒ ๐๐ซ๐จ๐ฃ๐๐๐ญ ๐๐๐ฆ๐ข๐ฅ๐ฒ. Bitdefender has introduced improvements to its telemetry control, no longer requiring a data retention license to change what telemetry is being sent.... ๐
24 days ago
1
1
0
๐ ๐๐๐-๐ญ๐๐ฅ๐๐ฆ๐๐ญ๐ซ๐ฒ ๐๐ซ๐จ๐ฃ๐๐๐ญ ๐๐ฉ๐๐๐ญ๐ - ๐๐ข๐ง๐๐จ๐ฐ๐ฌ The Windows table just got an update with 3 new sub-categories: โก๏ธ VSS Deletion โก๏ธ Win32 API Telemetry โก๏ธ JA3/JA3s Coverage isnโt uniform, and some are pending response from the vendors. Thatโs fine. Iโd rather show the uncertainty than pretend otherwise.
30 days ago
1
0
1
Turns out this npm compromise was a bit of a nothing burger. But imagine if the threat actors had been careful and methodical. Imagine they stayed quiet and blended in... With the access they had, they couldโve done far worse. This time we got lucky. Next time, maybe not. Or maybe... ๐
about 1 month ago
1
2
0
๐ก๐ฒ๐๐ฒ๐ฟ ๐๐ต๐ผ๐๐ด๐ต๐ ๐๐ต๐ถ๐ ๐ฝ๐ฟ๐ผ๐ท๐ฒ๐ฐ๐ ๐๐ผ๐๐น๐ฑ ๐ฟ๐ฒ๐ฎ๐ฐ๐ต ๐๐ต๐ถ๐ ๐ธ๐ถ๐ป๐ฑ ๐ผ๐ณ ๐๐ฐ๐ฎ๐น๐ฒ. Especially not as an independent, non-corporate platform focused purely on technical content. Started as a small side effort to compare EDR telemetry and support hunting workflows. Now itโs here.... ๐ 1/x
loading . . .
EDR Telemetry Project - Home
EDR Telemetry Project - Exploring telemetry capabilities of EDR solutions
https://edr-telemetry.com/
about 1 month ago
1
3
1
Every pixel of this graphic is a lie. It insults the people actually fighting threats daily and rewards the companies that canโt even catch a cold. Absolute cancer for the industryโฆ Pay up or get shoved in the โloserโ box. Embarrassing trash.
about 1 month ago
1
1
0
๐จ New lab just went live: Specterโs Domain Heist Pulled straight from a recent intrusion we worked on. 20 challenges in total. Difficulty is hard, but weโve added hints along the way so youโre never stuck. Each question pushes you deeper through the intrusion lifecycle. Hope youโll like it! Links๐
add a skeleton here at some point
about 1 month ago
0
2
0
Creating Images for our next DFIR Labs has never been easier thanks to Google Gemini ๐ New Lab is dropping ๐
about 2 months ago
0
2
1
โEDR bypassed! Victory!โ โฆnot really. You just lit yourself up. Telemetry stacks, correlations build, and now every move screams suspicious. EDR isnโt blind. You just canโt see the flags
about 2 months ago
0
1
0
Trump is giving a press conference every day, he seems to love talking to reporters. Where does he find the time to get anything done? ๐
about 2 months ago
0
1
0
Here is a cool Linux technique:
www.trellix.com/blogs/resear...
Execution isnโt coming from a binary or a script. Itโs coming from the filename itself. ๐๐ฒ๐ฟ๐ฒโ๐ ๐ต๐ผ๐ ๐ถ๐ ๐๐ผ๐ฟ๐ธ๐: โก๏ธ Attacker crafts a malicious filename with embedded logic. โก๏ธ Normal system enumeration commands (ls, cat, find) interact
about 2 months ago
2
2
1
๐๐๐ฅ ๐ง๐ฒ๐น๐ฒ๐บ๐ฒ๐๐ฟ๐ ๐ถ๐ ๐ด๐ฟ๐ผ๐๐ถ๐ป๐ด ๐ฎ๐ด๐ฎ๐ถ๐ป ๐ Weโve been holding back on telemetry additions as we didnโt want early adopters to get an unfair scoring boost.To solve that, instead of delaying additions, new fields will now show up as โ๐ฃ๐๐ฌโ and wonโt affect scores until at least 75% ๐ผ๐ณ ๐๐ฒ๐ป๐ฑ๐ผ๐ฟ๐ ๐๐๐ฝ๐ฝ๐ผ๐ฟ๐ ๐๐ต๐ฒ๐บ. 1/x
loading . . .
EDR Telemetry Project - Home
EDR Telemetry Project - Exploring telemetry capabilities of EDR solutions
https://www.edr-telemetry.com/
about 2 months ago
1
2
1
reposted by
Kostas
Phill Moore
about 2 months ago
Week 34 - 2025
#DFIR
thisweekin4n6.com/2025/08/24/w...
loading . . .
Week 34 โ 2025
Learn Scattered Spiderโs Updated TTPs & How to Defend Against ThemIn this webinar, Permisoโs CTO and Head of P0 Labs Threat Research will discuss:- How Scattered Spiderโs methods have evolved oโฆ
https://thisweekin4n6.com/2025/08/24/week-34-2025/
0
8
5
Imagine burning billions in AI, Copilot this and Copilot that... But somehow, indexing Group Policy settings and adding a damn search box has been out of scope since Windows 2000...pfff
about 2 months ago
0
1
0
๐๐๐ ๐ฏ๐ข๐ฌ๐ข๐๐ข๐ฅ๐ข๐ญ๐ฒ ๐จ๐ง ๐๐ข๐ง๐ฎ๐ฑ ๐ข๐ฌ ๐ฐ๐๐๐ค๐๐ซ ๐ญ๐ก๐๐ง ๐ฆ๐จ๐ฌ๐ญ ๐ฉ๐๐จ๐ฉ๐ฅ๐ ๐ญ๐ก๐ข๐ง๐ค... After reading this excellent write-up on RingReaper Malware (
www.picussecurity.com/resource/blo...
), I double-checked against our own EDR Telemetry project and the gap in collecting eBPF telemetry is obvious, even more for...๐
loading . . .
RingReaper Linux Malware: EDR Evasion Tactics and Technical Analysis
Analysis of RingReaper malwareโs tactics and techniques, revealing its io_uring-based evasion methods targeting Linux environments.
https://www.picussecurity.com/resource/blog/ringreaper-linux-malware-edr-evasion-tactics-and-technical-analysis
about 2 months ago
1
5
1
reposted by
Kostas
UK_Daniel_Card
2 months ago
what a load of nonsense! Public wifi is reasonably safe! Airports are even more because they have more CCTV than you can imagine and armed police. people get pwn3d via phishing and malware/infostealers....
#WIFI
#Insanity
add a skeleton here at some point
4
49
15
Another day, another loader becoming a full-on ransomware dropper ๐ ๐ข First public attribution of Bumblebee โก๏ธ Akira ransomware โก๏ธ ๐๐ฎ๐ฆ๐๐ฅ๐๐๐๐ โ ๐๐๐๐ฉ๐ญ๐ ๐2 โ ๐๐ค๐ข๐ซ๐ ๐ซ๐๐ง๐ฌ๐จ๐ฆ๐ฐ๐๐ซ๐ - Starts with Bing malvertising โช๏ธ Moves through custom loader (AdaptX) โช๏ธ Ends in Akira Ransomware 1/2
2 months ago
2
1
1
1/2 This is a small way to fix a big issue! I compiled these best practices after repeatedly spotting the same JS flaws in client apps, all of which were AI-generated. If you're coding with AI-powered IDEs like Cursor, Windsurf, Claude Code, etc., add this into your global rules file.
3 months ago
1
1
0
๐๐ ๐ต๐ฒ๐น๐ฝ๐. ๐๐๐ ๐๐ผ๐ ๐ต๐ฎ๐๐ฒ ๐๐ผ ๐ฒ๐ฎ๐ฟ๐ป ๐๐ต๐ฒ ๐ฟ๐ถ๐ด๐ต๐ ๐๐ผ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ฒ!! Iโve spent years doing threat intel the hard way. Pivoting through VirusTotal, Censys, Shodan, pulling open tabs until I ran out of memory. You chase one IP, it leads to a domain, that domain to a TLS Cert, and back again. 1/X
loading . . .
This prompt is designed to facilitate research, expansion, and enrichment of various IoCs for threat intelligence collection.
This prompt is designed to facilitate research, expansion, and enrichment of various IoCs for threat intelligence collection. - IOC_enrichment.md
https://gist.github.com/tsale/049f42413158c77f64bda4031c8fc044
3 months ago
1
4
0
๐ข Weโve been cooking this for a while! The new Pro Tier is here ๐ Built these features with real investigations in mind. Iโve been using the Timeliner myself. Just drop in unstructured logs (even loosely formatted ones with a date) and it does the heavy lifting. Absolute time-saver. Take a look ๐
add a skeleton here at some point
3 months ago
0
0
0
reposted by
Kostas
malmoeb.bsky.social
3 months ago
What I learnt today: When NetScan is executed with the โCheck for write accessโ option enabled, a โdelete[.]meโ file is created then deleted on discovered shares.[1] Thanks, TheDFIRReport - this is exactly what we are seeing in a recent case. I owe you one ๐ป [1]
thedfirreport.com/2025/02/24/c...
loading . . .
Confluence Exploit Leads to LockBit Ransomware
Key Takeaways The intrusion began with the exploitation of CVE-2023-22527 on an exposed Windows Confluence server, ultimately leading to the deployment of LockBit ransomware across the environment.โฆ
https://thedfirreport.com/2025/02/24/confluence-exploit-leads-to-lockbit-ransomware/
0
3
2
๐น๐ง๐ต๐ฒ ๐๐ฝ๐ฒ๐ฒ๐ฑ ๐ฎ๐ ๐๐ต๐ถ๐ฐ๐ต ๐๐ถ๐น๐ฒ๐๐ถ๐ ๐๐ฒ๐ป๐ ๐ณ๐ฟ๐ผ๐บ "๐บ๐ฎ๐๐ฏ๐ฒ ๐๐ถ๐ฎ๐ฏ๐น๐ฒ" ๐๐ผ ๐ผ๐ฝ๐ฒ๐ฟ๐ฎ๐๐ถ๐ผ๐ป๐ฎ๐น ๐ถ๐ ๐๐ถ๐น๐ฑ! In our latest case, we saw FileFix used to deploy an obfuscated PHP RAT variant of Interlock with ๐๐ฎ๐ป๐ฑ๐-๐ข๐ป-๐๐ฒ๐๐ฏ๐ผ๐ฎ๐ฟ๐ฑ activity shortly after in victim environments. 1/2
add a skeleton here at some point
3 months ago
1
2
1
๐ ๐๐ง๐จ๐ญ๐ก๐๐ซ ๐ฌ๐ฎ๐๐๐๐ฌ๐ฌ ๐ฌ๐ญ๐จ๐ซ๐ฒ ๐๐ซ๐จ๐ฆ ๐ญ๐ก๐ ๐๐ ๐๐ ๐๐๐ฉ๐จ๐ซ๐ญ ๐๐๐๐ฌ One of our users just crushed the HTB CDSA exam after using DFIR Labs as final prep. Theyโd already gone through Sherlocks, BTLO, and CyberDefenders, but called our lab the closest to the exam environment.... ๐
3 months ago
1
3
0
Catching up on the Elastic vs Shellter drama. Hereโs the gist: ๐งต
loading . . .
Taking SHELLTER: a commercial evasion framework abused in-the-wild โ Elastic Security Labs
Elastic Security Labs detected the recent emergence of infostealers using an illicitly acquired version of the commercial evasion framework, SHELLTER, to deploy post-exploitation payloads.
https://www.elastic.co/security-labs/taking-shellter?linkId=836491490
3 months ago
1
1
0
AI isnโt a mind reader! If you want it to build something useful, you need to know what you're asking for. You don't have to be a software engineer, but basic understanding of AI is very important for explaining goals and interpreting responses.
add a skeleton here at some point
3 months ago
1
2
0
reposted by
Kostas
The DFIR Report
4 months ago
A New DFIR Lab is out: The Hive Ransomware Fail ๐ A domain is under siege, can you trace the threat actor's steps? Sharpen your triage and lateral movement skills in this hands-on investigation. โก๏ธDifficulty: Easy 1/2
1
4
1
๐๐ ๐๐น๐ผ๐ฝ, ๐บ๐ฒ๐ฒ๐ ๐๐ต๐ฒ ๐๐ผ๐ฟ๐น๐ฑ - ๐ช๐ผ๐ฟ๐น๐ฑ, ๐บ๐ฒ๐ฒ๐ ๐๐ต๐ฒ ๐๐ ๐๐น๐ผ๐ฝ! Auto-generated doesnโt have to mean auto-garbage folks, PLEASE don't use rules like this PLEASE ๐ซ
4 months ago
0
1
0
๐ซ
loading . . .
4 months ago
0
1
0
Street legal. Leash optional. Both looking handsome AF ๐
4 months ago
0
2
0
I felt that ๐๐
loading . . .
4 months ago
0
1
0
DFIR Labs Subscriptions are live ๐ At $๐๐.๐๐/๐ฆ๐จ๐ง๐ญ๐ก, weโre offering something weโre truly proud of, not just great training, but a model thatโs sustainable and community-focused. /1
add a skeleton here at some point
4 months ago
1
5
2
I frequently talk with folks who feel overwhelmed during IR, regardless of how prepared they think they are. The reality is: ๐ฃ๏ธ"๐๐ช๐ฎ ๐ญ๐ข๐ฃ๐ด ๐ฅ๐ฐ๐ฏโ๐ต ๐ฑ๐ณ๐ฆ๐ฑ ๐บ๐ฐ๐ถ ๐ง๐ฐ๐ณ ๐ต๐ฉ๐ฆ ๐ฏ๐ฐ๐ช๐ด๐ฆ ๐ฐ๐ง ๐ณ๐ฆ๐ข๐ญ-๐ธ๐ฐ๐ณ๐ญ๐ฅ ๐ช๐ฏ๐ค๐ช๐ฅ๐ฆ๐ฏ๐ต๐ด" Youโre not alone if you're feeling overwhelmed.... 1/2
4 months ago
1
3
0
reposted by
Kostas
๐ Fancy4n6 ๐ฆ
4 months ago
WMI can be abused for stealthy persistence. ๐ Check registry: HKLM\SOFTWARE\Microsoft\Wbem\CIMOM Investigate: __EventFilter __EventConsumer __FilterToConsumerBinding
#DFIR
#LearningDFIR
#ThreatHunting
1
2
1
๐๏ธ New episode just dropped! Had the pleasure of hosting another "DFIR Discussions" episode and chatting with these amazing folks! Honestly, one of the best convos weโve had, not just on the report, but on a ton of things we donโt always get to say out loud.
add a skeleton here at some point
4 months ago
1
2
0
4 months ago
0
4
0
/1 Someone in our Discord server asked a question that we get a lot ๐ โ๐๐ค๐ฌ ๐๐ค ๐ฎ๐ค๐ช ๐๐๐ฉ๐ช๐๐ก๐ก๐ฎ ๐ฅ๐ง๐๐๐ฉ๐๐๐ ๐๐ค๐ง ๐จ๐ค๐ข๐๐ฉ๐๐๐ฃ๐ ๐ก๐๐ ๐ ๐ฉ๐๐๐จ?โ Theyโd just wrapped their first CTF, landed towards the bottom of the scoreboard, not where they wanted to be. But that curiosity? Thatโs exactly where growth starts.
4 months ago
1
0
0
/1 ๐ง ๐๐๐ก๐ข๐ง๐ ๐ญ๐ก๐ ๐๐๐ฅ๐๐ฆ๐๐ญ๐ซ๐ฒ: ๐๐ก๐ฒ ๐๐ก๐๐ฌ๐ ๐๐๐ญ๐๐ ๐จ๐ซ๐ข๐๐ฌ? Over the past year, Iโve received a lot of questions about how we decide which telemetry categories and subcategories are included in the EDR Telemetry Project.
4 months ago
1
1
1
This is why weโre here for, itโs finally happening ๐ Weโve been waiting this since January. The girls are fighting!!!
4 months ago
1
4
0
1/ ๐๏ธ Had an awesome convo with Amy Tom on the Letโs SOC About It podcast! We dove into telemetry (of course), talked through some of the messy realities folks deal with in the field, and how better visibility can really change the game for defenders.
loading . . .
What Is the EDR Telemetry Project?
YouTube video by D3 Security
https://www.youtube.com/watch?v=D2eAe_Go2Ug
4 months ago
1
0
0
/1 ๐จ ๐๐๐ ๐ค๐ข๐๐ค๐ฌ ๐จ๐๐ ๐ข๐ง ๐ฅ๐๐ฌ๐ฌ ๐ญ๐ก๐๐ง 48๐ก - ๐๐ง๐ ๐ญ๐ก๐ข๐ฌ ๐จ๐ง๐โ๐ฌ ๐๐ข๐ . One of the most involved cases weโve ever made available to the public. Youโll be diving into an intrusion that hit 18 hosts, including: โก๏ธ Domain Controllers โก๏ธ Backup Servers โก๏ธ Hypervisors โก๏ธ RDP Servers (Guess the initial access gonna be? ๐)
4 months ago
1
0
2
A small tip for anyone that doesn't know about dogs: If you often go for a jog in the neighbourhood and you see a dog, don't run and lock eyes with the dog while approaching. Keep running while ignoring the dog. If youโฆโฆ
5 months ago
1
1
0
/1 I donโt know how many folks will show up Sunday, but weโre gonna have a blast. Weโll kick things off with a short presentation covering the basics of intrusion analysis and the investigative mindset. Then itโs straight into DFIR Labs where youโll walk through a real intrusion step by step.
5 months ago
1
2
2
1/ ๐จ New report alert, Another Confluence Bites the Dust This is ๐ผ๐ป๐ฒ ๐ผ๐ณ ๐๐ต๐ฒ ๐น๐ฎ๐ฟ๐ด๐ฒ๐๐ ๐ฎ๐ป๐ฑ ๐บ๐ผ๐๐ ๐ฑ๐ฒ๐๐ฎ๐ถ๐น๐ฒ๐ฑ ๐ฟ๐ฒ๐ฝ๐ผ๐ฟ๐๐ ๐๐ฒโ๐๐ฒ ๐ฝ๐๐ฏ๐น๐ถ๐๐ต๐ฒ๐ฑ ๐๐ต๐ถ๐ ๐๐ฒ๐ฎ๐ฟ, and it's packed with practical insights and tradecraft you can actually hunt for.
add a skeleton here at some point
5 months ago
1
2
1
Thatโs a great post. Iโm also a big supporter of the below sentiments that many folks in security are struggling to grasp: โ๐ ๐ฐ๐ถ ๐ฆ๐น๐ช๐ด๐ต ๐ต๐ฐ ๐ฆ๐ฏ๐ข๐ฃ๐ญ๐ฆ ๐ฃ๐ถ๐ด๐ช๐ฏ๐ฆ๐ด๐ดโ & โ๐๐บ๐ด๐ต๐ฆ๐ฎ๐ด ๐ฎ๐ถ๐ด๐ต ๐ธ๐ข๐ญ๐ฌ ๐ข ๐ญ๐ช๐ฏ๐ฆ ๐ฃ๐ฆ๐ต๐ธ๐ฆ๐ฆ๐ฏ ๐ด๐ฆ๐ค๐ถ๐ณ๐ช๐ต๐บ ๐ข๐ฏ๐ฅ ๐ถ๐ด๐ข๐ฃ๐ช๐ญ๐ช๐ต๐บโ
add a skeleton here at some point
5 months ago
1
4
0
Load more
feeds!
log in