Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @MaartenVDantzig
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @MaartenVDantzig
-
Maarten van Dantzig Retweeted
For all command line heroes out there. The Timesketch CLI tool is out. Search your forensic timelines from the comfort of your terminal or do timeline analysis from your scripts! https://timesketch.org/guides/user/cli-client/ …pic.twitter.com/PuwfYChpnE
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
RIFT Blog: Mining data from Cobalt Strike beacons, by
@YunZhengHu It includes the open-source release of our historical Beacon dataset (2018-2022) and Python library called dissect.cobaltstrike for dissecting and parsing Cobalt Strike related data. https://research.nccgroup.com/2022/03/25/mining-data-from-cobalt-strike-beacons/ …pic.twitter.com/C3QnSKJsXn
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
Folks are looking to Twitter for reliable information. Thing is, there are disinformation operations at play targeting... your retweet finger. Dubious claims & content abound. Videos are especially risky. Please exercise care. Don't be an unwitting amplifier.
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
New:
#Turla is one of the most skilled hacker groups operating.@FlorianFlade, Lea Frey and I've spent close to a year chasing down leads. We were able to identify, we think, two developers, their employers, and from there, their ties to the FSB. https://interaktiv.br.de/elite-hacker-fsb/en/index.html …pic.twitter.com/xqL9wKwDKf
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
Using Timesketch?

This is your chance to influence the project!
#DFIR#Timesketch#Community#Feedbackhttps://twitter.com/TimesketchProj/status/1485400586812260352 …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
Today, we're open sourcing a log4j JAR scanner. Throw it at a filesystem, detect vulnerable JARs, and even rewrite them in place. Includes a Go API to import the JAR parsing for other applications.https://github.com/google/log4jscanner …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
English version of the article:https://www.nrc.nl/nieuws/2021/11/10/american-spy-hacked-bookingcom-company-stayed-silent-a4065086 …
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Interesting story just published in the Netherlands: http://Booking.com was allegedly compromised by a (sloppy) US intelligence contractor in 2016, in order to target reservation details for hotels in the Middle East.https://www.nrc.nl/nieuws/2021/11/10/spion-andrew-zocht-bij-booking-uit-wie-naar-midden-oosten-reisde-2-a4065012 …
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted

Happy to share a new blog post connecting a few pieces: @virustotal +@TimesketchProj +@sigma_hq and DFTimewolf. How to use a new VT feature that allows Enterprise customers to download EVTX for a sandbox execution of submitted samples in DFIR.
https://osdfir.blogspot.com/2021/11/use-evtx-files-on-virustotal-part1.html …pic.twitter.com/3pMxHZz07B
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Common misconceptions about Windows EventLogs https://osdfir.blogspot.com/2021/10/common-misconceptions-about-windows.html … (by
@joachimmetz)Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Security professionals: hacking is bad Also security professionals: wow look at all this internal data from this hacked company
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
Sigma integration in Timesketch. Today we merged a feature to show Sigma rules in the UI. You also have the ability to search your timelines based on the generated query.
#DFIRpic.twitter.com/1SzdjumXMCShow this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
New blogpost out on Windows containers https://osdfir.blogspot.com/2021/07/windows-container-forensics.html …
#InfosecInfluencer#dfirThanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
Repeat after me: ransomware is not about perimeter security, it's about how they were able to spread internally after the perimeter breach.https://twitter.com/thepacketrat/status/1402690782440706056 …
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
The devil is in the (network) packets. Impressive investigation.https://twitter.com/IgorBog61650384/status/1374800036366848002 …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
I like the part where the attackers stolen the victim's EDR and ran it on their own infrastructure, resulting in SecureWorks being able to ID them.pic.twitter.com/vhOULmRFjG
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
[1/2] Thrilled to be presenting at 𝗧𝗶𝗺𝗲𝘀𝗸𝗲𝘁𝗰𝗵 𝗦𝘂𝗺𝗺𝗶𝘁 𝟮𝟬𝟮𝟭 on Mar 10th!
Registration's open and 𝗳𝗿𝗲𝗲: https://forms.gle/1D23n4SkoCPay1eDA …
If you're a 𝗗𝗙𝗜𝗥 ninja
or a complete newbie
and want to hear the latest on Timesketch 
, or learn aboutShow this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
I'm excited to share our research in which we show that a 0-Day attributed to the Chinese APT31 was actually caught by the APT and replicated from Equation Group's 0-Day exploit for the same vulnerability. Here are some of the highlights — A long thread >>https://research.checkpoint.com/2021/the-story-of-jian …
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
One of my few tweets in English, but with a pretty good reason
. Hackchallenges, the website I made in 2019 where kids can learn about cyber security by playing CTFs is now available in English: https://hackchallengesforkids.com Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Maarten van Dantzig Retweeted
New blog post from TAG with details of a North Korean campaign targeting security researchers working on vulnerability research and development. https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/ … Stay safe out there everyone!
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

on Timesketch
: