Elektrine lite

← Feed

Alexandre Dulaunoy

adulau@infosec.exchange

<p>Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff.</p><p>The other side is at <span class="h-card" translate="no"><a href="https://paperbay.org/@a" class="u-url mention">@<span>a</span></a></span> (photography, art and free software at large)</p><p><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/opensource" class="mention hashtag" rel="tag">#<span>opensource</span></a> <a href="https://infosec.exchange/tags/threatintelligence" class="mention hashtag" rel="tag">#<span>threatintelligence</span></a> <a href="https://infosec.exchange/tags/fedi22" class="mention hashtag" rel="tag">#<span>fedi22</span></a> <a href="https://infosec.exchange/tags/threatintel" c

Posts

  • Post #4494778

    From a research paper to running open-source code in just a few days. We (with @cedric@fosstodon.org) have been experimenting in Vulnerability-Lookup with the concept of Local Exploit Hazard, based on the recent research paper “Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency” by Stephen Shaffer and Laura Cristiana Voicu. The idea addresses an important question in vulnerability management: Not simply “How dangerous is this vulnera...

  • Post #4493437

    Pretty cool idea from @nyanbinary@infosec.exchange - a bot to analyse fucked up references from the CVE records. @fuckeduprefs_bot@infosec.exchange Maybe we could imagine an archive bot at the same time to ensure that the references don&#39;t get lost. Just like archive.org or similar. Maybe something for @gcve@social.circl.lu to look into. #cve #vulnerability #gcve

  • Post #4382676

    A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster in the MISP Galaxy repository, and shared MISP Galaxy metadata. Graph rendering is performed by Pivotick. Source code: https://github.com/adulau/threat-actor-explorer/ Online (in-browser): https://foo.be/threat-actor-explorer/misp-threat-actor-explorer.html Discussions and feedback: https://discourse.ossbase.org/t/playing-with-a-threat-actor-explorer-b...

  • Post #4354786

    Have you seen any evidence of the famous « collect encrypt data and decrypt later » in incident response ? Until now, I haven’t. #pqc #crypto #cryptography #dfir

  • Post #4229585

    A new version of the BCP-11 &quot;Community Contribution Fragments for Existing CVE Records&quot; proposal has been published. https://discourse.ossbase.org/t/gcve-bcp-11-community-proposed-updates-to-existing-cve-records/1110/8#p-1495-gcve-bcp-11-community-contribution-fragments-for-existing-cve-records-1 This new version is a major refactoring of the originally proposed format. Feel free to comment, update or propose changes. An implementation will follow when the BCP-11 reach a more stab...

  • Post #4161728

    When I added the threat-actor @misp@misp-community.org galaxy type on Mar 4, 2016, I didn’t expect that, years later, vendors would still invent new names for already known threat actors, avoid using UUIDs, reuse similar names for different actors, and create confusing names by mixing tools or software used by the actors. That’s why we continue the tedious work of maintaining a proper threat-actor database, with relationships to other galaxies such as MITRE ATT&amp;CK, Malpedia, and more. Afte...

  • Post #4158864

    The Radio Image Framing Protocol (RIFP) 1.0 is an experimental, extensible standard for sending images over low-rate radio links. The default rifp-cpfsk-4800 profile uses binary continuous-phase FSK and can be deployed around 433.92 MHz where local regulation permits it. RIFP itself is not tied to 433 MHz or to FSK and can be used in any frequency bands. I&#39;m still exploring various low-cost options for a device that can receive and display images on an e-ink screen in emergency areas or si...

  • Post #4146316

    Pivotick is an open-source network graph library to facilitate pivoting. Version 1.4.0 has been released and also includes a security fix. Release notes https://github.com/Pivotick/Pivotick/releases/tag/v1.4.0 Documentation https://pivotick.github.io/Pivotick/ Vulnerability fixed in 1.4.0 https://vulnerability.circl.lu/vuln/gcve-1-2026-20151 Gallery https://pivotick.github.io/Pivotick/gallery.html #opensource #infovis #graph #networkgraph #visual

  • Post #4144158

    So finally Kimi-k3 is not really open-source https://huggingface.co/moonshotai/Kimi-K3/blob/main/LICENSE I&#39;m a bit disappointed. #kimi #ai #opensource

  • Post #4108882

    The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System initiative. The lab allows the GCVE community to explore promising concepts without immediately imposing the stability, compatibility, and operational requirements expected from the core GCVE infrastructure. Open to comments/ideas. #gcve #cve #cybersecurity https://discourse.ossbase.org/t/gcve-lab-proposal/1117 https://gcve.eu @gcve@social.circl.lu @gcv...

  • Post #4086133

    Wireshark for the web (webasm) Open, dissect and analyse .pcap / .pcapng capture files entirely in your web browser. Online - local in your browser https://stricaud.github.io/wpcapng/ Sourc code - https://github.com/stricaud/wpcapng #nids #pcap #networkanalysis #wireshark

  • Post #3882612

    I don’t like playing the futurologist, but after seeing AI companies warn EU institutions about the supposed risks of open-weight models, I suspect some are lobbying to regain control over genuine open source and open-weight AI. Don’t fall into the trap: the greater danger lies in opaque, proprietary models, not open-source ones. #opensource #ai #cybersecurity

  • Post #3741451

    @neal@social.gompa.me All is documented as BCP including IDs allocation https://gcve.eu/bcp/ If you have any question feel free. @bernardq@ehlo.exim.org

  • Post #3674646

    We are exploring some ambitious ideas around reducing external dependencies and relying more on our own libraries across MISP and related tooling. Over the past year, we have been working on a replacement network graph library for the new MISP interface and things are getting really interesting. Pivotick is already used in around ten open-source tools, including CTI Transmute, AIL Project, and Rulezet. It has also recently been integrated into the new MISP UI, OverMind. The library is, of course...

  • Post #3667218

    We started rulezet project after identifying a clear gap in open source tooling for detection rules management: the ability to operate synchronised instances while still allowing each organisation to maintain its own autonomous rule repository. Rulezet addresses this need as an open source platform for managing, sharing, and synchronising detection rules. Each organisation can run its own standalone instance and decide independently which other instances, communities, or repositories it wants t...

  • Post #3604689

    Looking at the current distributed.net statistics on the current RC5-72 brute force, this actually puts some key-size discussions into perspective. #cryptography #crypto #symmetric #cybersecurity

  • Post #3604375

    We just released cve-search v6.0.1 - it is a security and maintenance release. All users are strongly encouraged to upgrade. Thanks to @oh2fih@infosec.exchange for the remediation fix and release support. Thanks to George Chen for the report about the security vulnerability. #cve #gcve #cybersecurity 🔗 https://github.com/cve-search/cve-search/releases/tag/v6.0.1

  • Post #3581119

    « Once an organisation accepts that the difficult software will be bought elsewhere, internal teams slowly lose the habit of building. Procurement becomes a substitute for strategy. Legal review becomes a substitute for leadership. Risk management becomes a substitute for execution. » https://foo.be/2026/06/Sovereignty-Is-Engineered-Not-Procured.html #sovereignty #europe #opensource

  • Post #3535557

    An idea for next year workshop @passthesaltcon@infosec.exchange - open source license for developers? It could be a nice opportunity because it seems to be a never ending learning process. #opensource

  • Post #3531566

    @aristot73@infosec.exchange I&#39;m not into this kind of sport. But here, it might be different ;-) Should we expect the harbor of Antwerp to be bombed soon. @bert_hubert@mastodon.nl

  • Post #3106563

    Yesterday, in our very warm office, an interesting discussion emerged: there was no dedicated taxonomy for evaluating Cyber Threat Intelligence (CTI) in MISP. So, we created one called: cti-evaluation 🔗 https://www.misp-project.org/taxonomies.html#_cti_evaluation My colleagues Théo Geffe and Christian Studer then took it one step further by implementing it in CTI-transmute. From discussion to a first implementation and tests in less than 48 hours, not too bad! Feedback on the taxonomy is m...

  • Post #3106562

    I still don’t understand standards committees composed of people who have never implemented software. They design a standard without ever confronting the realities of implementation, then wonder why no one adopts it. #openstandard #standard

  • Post #3106561

    The synthetic exercise world format now includes a nice map. So no one can blame us when you conduct an exercise: everything is fictional ;-) Yes, we’ve had cases like this during threat intelligence exercises. All Synthetic Exercise World - Self-contained fictional world dataset for cyber exercises and standards documents are available at https://github.com/MISP/Synthetic-Exercise-World-Format #cti #cyberexercise #exercise #threatintelligence #opensource

  • Post #3106560

    IETF I-D updated - Programming Methodology Framework aka PMF This update includes &quot;Swearwords and Software Engineering&quot; #update #computerscience #methodology #programming 🔗 https://datatracker.ietf.org/doc/draft-dulaunoy-programming-methodology-framework/

  • Post #3106559

    I’m wondering why @dnsoarc is limiting potential new contributions to their project just because they are AI-assisted. Many valuable tools support development today, including code review and security review. The copyright argument feels similar to the one behind CLAs: an unsuccessful attempt to control the origin of the code, or even the author’s ability to re-implement a specific idea with or without external tools. #ai #opensource #copyright https://codeberg.org/DNS-OARC#artificial-intel...

  • Post #3106558

    Not sure I’m allowed to leak this yet, but the new MISP dashboard is kind of crazy. We didn’t just refresh the old one, we rewrote it completely, and it comes with a whole set of new features and capabilities that change the game quite a bit. #misp #cti #dashboard #opensource @misp

  • Post #3106557

    What’s the difference between an API and an agent? An API is consistent, deterministic, and scoped. An agent is probabilistic, non-deterministic, and occasionally chaotic. An agent adds some spice to your life. Will you choose the boring, predictable life or the cool, chaotic one? #ai #ia

  • Post #2579516

    I’m still completely lost with logic of JA4+ patent licensing and actual incompatibility with the copyleft-license. So it seems to be a patent-based license and really risky to implement if you want to keep your actual software open source. Did someone explore alternatives to avoid this? and especially other format which are open source friendly? #ja4 #ja3 #jarm #cti #opensource #patent #cti #threatintel #cybersecurity 🔗 https://github.com/FoxIO-LLC/ja4/blob/main/License%20FAQ.md

  • Post #2579515

    This kernel vulnerability looks interesting to look at. crypto: caam - fix overflow on long hmac keys VLAI Severity -&amp;gt; High (confidence: 0.9638) https://vulnerability.circl.lu/vuln/CVE-2026-43330 #kernel #cybersecurity

  • Post #2579514

    The Synthetic Exercise World Format provides fictional countries, companies, sectors, and threat actors with structured metadata for neutral CTI examples, exercises, interoperability tests, and standards documentation without referencing real-world sensitive entities. I just released version 1.0. #cti #opensource #misp #cybersecurity #threatintelligence #threatintel 🔗 GitHub - https://github.com/MISP/Synthetic-Exercise-World-Format