Kostas(@Kostastsale) 's Twitter Profileg
Kostas

@Kostastsale

@TheDFIRReport member | Tweeting and following mostly #ThreatIntel,#malware,#IR & #Threat_Hunting. Opinions are mine only! 🇬🇷🇨🇦

ID:833742073002127362

linkhttps://github.com/tsale calendar_today20-02-2017 18:16:15

4,6K Tweets

16,1K Followers

369 Following

Kostas(@Kostastsale) 's Twitter Profile Photo

The never-dying is back, and aside from our report on it, I feel like there needs to be a further explanation on the undergoing efforts of stopping it. Enjoy the video and our new report 🙃

account_circle
Samir(@SBousseaden) 's Twitter Profile Photo

~2k samples, top abused processes via malicious LNK files, make sure susp cmd.exe and powershell.exe are properly covered

~2k samples, top abused processes via malicious LNK files, make sure susp cmd.exe and powershell.exe are properly covered
account_circle
Kostas(@Kostastsale) 's Twitter Profile Photo

Nice thread on AsyncRat showcasing current capabilities and hunting for default configuration attributes👏

account_circle
ςεяβεяμs - мαℓωαяε яεsεαяςнεя(@c3rb3ru5d3d53c) 's Twitter Profile Photo

NEW VIDEO 📽️ Theory - Intro to and

Not sure what a packer is? 🤔

Let me show you! 🥳🎉

✅ Packer Heuristics
✅ Common Injection Techniques
✅ Relocation Table
✅ Analysis Considerations
✅ Commercial Packers

Enjoy! 😘

youtube.com/watch?v=6aik01…

account_circle
Kostas(@Kostastsale) 's Twitter Profile Photo

Checkout our reporting The DFIR Report for related intrusion cases:

thedfirreport.com/category/icedi…

and follow the below amazing folks to stay on top of all the changes related to IcedID:

James
Myrtus
Max_Malyutin
proxylife
Joseph Roosen
Kelsey
Brad

account_circle
Kostas(@Kostastsale) 's Twitter Profile Photo

This is another pretty neat LOLBin. Nice find.

I added a sigma rule to my repo to cover this method.

github.com/tsale/Sigma_ru…

This is another pretty neat LOLBin. Nice find. I added a sigma rule to my repo to cover this method. github.com/tsale/Sigma_ru…
account_circle