Just renewed my @malcat@infosec.exchange License because it's still my favourite Tool for doing DFIR stuff.
You should check out at least the free Lite Version: https://malcat.fr/
Remote
G0rb 
@g0rb@infosec.exchange
Failed Philosopher doing DFIR now. in love with the thrill of the thrunt <3
"Chaotisch neutral" (@HonkHase@chaos.social)
"Bester Faden-Jäger EU West" (@jrt@infosec.exchange)
"So ein Troll, ey" (@brahms@chaos.social)
"lol. lmao." (@gayint@infosec.exchange)
#DontEatMyHomies
#LowkeyLoki
#SparklyOpossum
#ThruntersAnonymous
Disclaimer:
Personal account. Opinions expressed are my own and not related in any way with my employer.
678 Followers
2770 Following
50 Posts
Joined November 01, 2022
Wanted Hashes:
Ego-Tooting:
ICQ:
396194810
Open post
Replying to @cR0w@infosec.exchange
@cR0w@infosec.exchange my Threat-Model does not allow for corpo infra.
Also, seriously don't connect private stuff to corpo devices.
5
5
2
0
Open post
I don't want to push anyone, but I'd definitely apply for it. SRLabs is doing cool research and rather thrilling projects like [REDACTED].
I can personally vouch for @LisaLobmeyer@infosec.exchange as the responsible team lead for this position and in general the people at SRLabs are pretty chill, top tier hackers.
https://security-research-labs.jobs.personio.de/job/2726007
PS: The only downside is, I'll be your colleague. But if you want to do some s*ck #threathunting and collect more CTI about threats like [REDACTED] and the incredible cool tooling of [REDACTED], then here's your chance.
#getfedihired #DFIR #advertising
6
1
7
0
Open post
6
0
0
0
Open post
Open post
I'm having a discussion with my lovely Partner at the moment and need statistical data:
If you would be called an infosec influencer, how would you feel about the memory of it?
I'm having a discussion with my lovely Partner at the moment and need statistical data: If you would be called an infosec influencer, how would you feel about the memory of it?
5
0
7
0
Open post
Replying to @cR0w@infosec.exchange
@cR0w@infosec.exchange I'm trying to improve my threat model so much, that I can do a job without computers and DFIR.
3
1
1
0
Open post
Es macht nen Unterschied ob man ein Land als Tourist oder als Reisender besucht.
3
0
0
0
Open post
Replying to @jerry@infosec.exchange
@jerry@infosec.exchange ah okay, so OpenAI doesn't monitor for abnormal outbound network traffic of critical systems. 
4
0
0
0
Open post
3
2
0
0
Open post
Replying to @flyingpenguin@infosec.exchange
@flyingpenguin@infosec.exchange as long as the NSA, CIA and Pentagon parking lot is constantly pinging out the serials from the cars tire pressure sensors, it's even playing ground.
2
1
0
0
Open post
Replying to @cR0w@infosec.exchange
@cR0w@infosec.exchange you totally underestimate the threat of me being bored + to much OSINT services.
2
1
0
0
Open post
Replying to @fluepke@chaos.social
@fluepke@chaos.social Shitposting is an Anagram of Top Insight
3
0
0
0
Open post
Replying to @cR0w@infosec.exchange
@cR0w@infosec.exchange Love it. So quantum edge devices will have dozens of open ports (one for every quantum entanglement / connected client). This means a corp with 5000 devices will now have 5000 "ports" to suck up ../ instead of one public facing.
2
1
0
0
Open post
Replying to @cR0w@infosec.exchange
1
0
0
0
Open post
Replying to @captainfutura@mastodon.social
@captainfutura@mastodon.social dann könnte man den kram auch direkt via paperless automatisiert wegsortieren 
2
1
0
0
Open post
Replying to @FritzAdalis@infosec.exchange
@FritzAdalis@infosec.exchange just for you 😅
http.html_hash:1670442135
1
0
0
0
Open post
Open post
Replying to @theorangetheme@en.osm.town
@theorangetheme@en.osm.town was an unsecured C2 Panel, just cleaned up a little bit.
1
0
0
0
Open post
Replying to @jfslowik@infosec.exchange
@jfslowik@infosec.exchange small related Funfact: https://beta.shodan.io/host/214.3.115.13
1
0
0
0
Open post
Replying to @p3m@mastodon.social
@p3m@mastodon.social sure. Also something I regularly use. Malcat is my first tool if I need a quick overview and write some Yara Signatures, afterwards it's Ghidra vor Radare2
0
1
0
0
Open post
Open post
Replying to @flyingpenguin@infosec.exchange
@flyingpenguin@infosec.exchange wow, you are awesome 
0
0
0
0
Open post
Bin ja etwas überrascht das Leute verwundert sind wenn bei nem NATO-Gipfel bei dem die Rüstungsindustrie ein inhärentes Thema ist, Leute irritiert sind wenn sie nen Revolver geschenkt bekommen.
0
0
0
0
Open post
Replying to @dirksche@social.tchncs.de
@dirksche@social.tchncs.de ouh, located near nuremberg atm. But I'm in Stuttgart sometimes.
0
0
0
0
Open post
Wie inkompetent kann man sein?
https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
0
0
0
0
Open post
Replying to @a_watch@bewegung.social
@a_watch@bewegung.social stimmt schon, sind immerhin 0,00000014 Maskendeals.
0
0
0
0
Open post
Replying to @Viss@mastodon.social
@Viss@mastodon.social why the f*ck do they need AI for 17k log lines? Throwing AI at an Incident and calling it "forenaics" is the laziest incident response I've ever seen.
0
3
0
0
Open post
Open post
Replying to @cR0w@infosec.exchange
@cR0w@infosec.exchange if I quit doing forensics, I'll start with tactical tarot incident response.
0
1
0
0
Open post
0
0
0
0
Open post
I believe their is at least one APT Operator followong me on Mastodon.
#WhoKnows #GottaKeepThemOnTheirToes 
0
1
0
0
Open post
Apple: "Yeah, we got so much issues with spyware we introduced an optional hardened security mode for our devices."
Also Apple: "Btw you can't easily change the Name of the Wifi-Hotspot. We want everybody to know that you are here using an iPhone for Marketing reasons."
0
0
0
0
Open post
Replying to @quinn@social.circl.lu
@quinn@social.circl.lu noooo, just drop that 17k logs Ingo an other AI Model. Problem solved. 
0
0
0
0
Open post
Replying to @afeinman@wandering.shop
@Viss@mastodon.social @cR0w@infosec.exchange @afeinman@wandering.shop the difference is, grep is deterministic and has a proven track record.
0
1
0
0
Open post
Replying to @darfplatypus@infosec.exchange
@LisaLobmeyer@infosec.exchange @srlabs@infosec.exchange @darfplatypus@infosec.exchange after carefully considering your infosec-shitposting skills I come to the conclusion that you should apply so we can hunt [REDACTED] together and do some dope research on them.
0
0
0
0
Open post
Replying to @kinghaunst@sueden.social
@kinghaunst@sueden.social jap, basically das selbe Problem das die Consulting-Branche hat.
0
0
0
0
Open post
Replying to @g0rb@infosec.exchange
Took some time... Feeling a little bit sleepy
0
0
0
0
Open post
Replying to @cR0w@infosec.exchange
@cR0w@infosec.exchange wasn't a CISA KEV yesterday, and they still have till 4th of August to patch.
0
1
0
0
Open post
Replying to @g0rb@infosec.exchange
Evidence of Shitpost:
0
0
0
0
Open post
Replying to @mikemacapple@mstdn.social
@mikemacapple@mstdn.social ja, aber denk doch mal an den armen Merz der diese Stimmung aushalten muss
0
0
0
0
Open post
Replying to @dirksche@social.tchncs.de
@dirksche@social.tchncs.de we should definitely drink one together. Your profile looks like person I would have fun and feel comfortable drinking beer with.
0
1
0
0
Open post
Replying to @g0rb@infosec.exchange
@Viss@mastodon.social I would love to have incidents with 17k of log entries. A normal Plaso/Log2Timeline output has easily more than 2 Million lines and even they can be easily analyzed with Klogg as an log viewer. The hell you can even use grep for such pathetic stuff and their first idea is "Frontier AI Model"?
Exactly that's the reason why companies get (more or less) independent, external forensics. If you can't defend your environment to a certain degree (and honestly, nobody hates on you when you get pwned by nation state threat actors) then you are far away from the skill level needed for good digital forensics.
0
0
0
0
Open post
0
1
0
0
Open post
Replying to @jonathankoren@sfba.social
@Viss@mastodon.social @jonathankoren@sfba.social I'm pretty sure that you can handle 90% of incidents with the compute power of an 8GB RaspberryPi 5.
0
0
0
0
Open post
Replying to @geheimorga@chaos.social
@geheimorga@chaos.social ist fremdgehen dann DLL-Sideloading?
0
0
0
0