Chad Tilbury (@chadtilbury) 's Twitter Profile
Chad Tilbury

@chadtilbury

Digital forensics and incident response. Ex-AFOSI, Mandiant, and CrowdStrike. SANS Institute Fellow and co-author of #FOR500 and #FOR508 courses.

ID: 119530615

linkhttps://www.forensicmethods.com/ calendar_today03-03-2010 22:56:26

4,4K Tweet

22,22K Followers

602 Following

Phill Moore (@phillmoore) 's Twitter Profile Photo

Has anyone looked into how Windows approaches the creation of .URL files in the Recents folders instead of .LNK files? I only recently looked into it and havent really figured out the way they consistently get created #DFIR

Grzegorz Tworek (@0gtweet) 's Twitter Profile Photo

Finally releasing the tool! The Offline SAM Editor is here for IT pros, researchers, and security enthusiasts who want to access and edit SAM databases from offline OS disks. Source code included. Get your access: payments.gtworek.com/buy/54d82b09-4…

Josh Lemon (@joshlemon) 's Twitter Profile Photo

The team at Trend Micro has a nice write up on #cryptojacking threat actors using a recent #Confluence #vulnerability for initial access. ⚠️ If you find a crypto minner running, figure out how the threat actor got in, not just simply remove the minner. 🔗 trendmicro.com/en_us/research…

The team at <a href="/TrendMicro/">Trend Micro</a> has a nice write up on #cryptojacking threat actors using a recent #Confluence #vulnerability for initial access. 
⚠️ If you find a crypto minner running, figure out how the threat actor got in, not just simply remove the minner.
🔗 trendmicro.com/en_us/research…
Josh Lemon (@joshlemon) 's Twitter Profile Photo

If you're interested in getting into #Linux #logging and evidence collection, this is an excellent write-up from Kostas that compares #EVTX logs on Windows with #Auditd, #SysMon for Linux, and native Linux logging. #DFIR #LinuxForensics #SIEM #CSIRT kostas-ts.medium.com/telemetry-on-l…

If you're interested in getting into #Linux #logging and evidence collection, this is an excellent write-up from <a href="/Kostastsale/">Kostas</a> that compares #EVTX logs on Windows with #Auditd, #SysMon for Linux, and native Linux logging.

#DFIR #LinuxForensics #SIEM #CSIRT
kostas-ts.medium.com/telemetry-on-l…
Chad Tilbury (@chadtilbury) 's Twitter Profile Photo

Microsoft formally deprecates the 39-year-old Windows Control Panel arstechnica.com/gadgets/2024/0… >> That is some history!

Kathryn Hedley (@4enzikat0r) 's Twitter Profile Photo

🚨 #DFIR Tool Update Alert 🚨 I’ve updated my script that parses USB Connection artifacts from a mounted Windows volume, to include EID 1006 events from the Windows-Partition-Diagnostic log Includes connect/disconnect times, VSNs & filesystem type github.com/khyrenz/parseu…

Chad Tilbury (@chadtilbury) 's Twitter Profile Photo

Great research into OneDrive private vault data. Crazy that it is stored as a vhdx! I'm always happy to see Microsoft reusing existing formats.

Rob T. Lee (@robtlee) 's Twitter Profile Photo

Still time to register for the SANS AI SUMMIT - workshops today! Talks and lightning talks tomorrow! sans.org/cyber-security…

Still time to register for the SANS AI SUMMIT - workshops today!  Talks and lightning talks tomorrow!  sans.org/cyber-security…
Chad Tilbury (@chadtilbury) 's Twitter Profile Photo

ChromeKatz: Dump cookies and credentials directly from Chrome/Edge process memory. Credential manager creds in plain text with no need to access on disk database! Similarly, CookieKatz dumps decrypted cookies (including incognito mode). github.com/Meckazin/Chrom… (via Spiros Fraganastasis)

SANS Cloud Security (@sanscloudsec) 's Twitter Profile Photo

💡 Join Certified Instructor Simon Vernon , September 19, as he guides you through configuring, scaling, and securing your logging setup with Azure’s latest feature. 🗓️ 10:00 am ET / 14:00 UTC ⌛️Register now: buff.ly/4fRprPk #SANSCloudAce #CloudSecurity

Chad Tilbury (@chadtilbury) 's Twitter Profile Photo

Cracking OneDrive's Personal Vault by Brian Maloney malwaremaloney.blogspot.com/2024/09/cracki… >> Great explanation and step-by-step instructions!

Arsenal Recon (@arsenalrecon) 's Twitter Profile Photo

Anastasia recently added a new Linux disk images section, five more mobile extractions, & one more Windows disk image to our “Publicly-Accessible Disk Images & Mobile Extractions Grid for DFIR” available at ArsenalRecon.com/insights/publi…. Check it out! #DFIR

Anastasia recently added a new Linux disk images section, five more mobile extractions, &amp; one more Windows disk image to our “Publicly-Accessible Disk Images &amp; Mobile Extractions Grid for DFIR” available at ArsenalRecon.com/insights/publi…. Check it out! #DFIR
Chad Tilbury (@chadtilbury) 's Twitter Profile Photo

Location, Location, Location by Ian Whiffin. How does iOS Location Services work? How can we test the reliability of the location data it provides? dfir.pubpub.org/pub/4fkeiv34/r… >> Excellent overview of Cell Siting, WiFi Crowd Sourcing, Bluetooth, and GPS information.

Chad Tilbury (@chadtilbury) 's Twitter Profile Photo

SANS Institute Paller Scholarship applications are open until January 2025. The mission of the program is to identify exceptionally talented international students (non-US citizens) committed to making the world a safer place through cybersecurity. sans.edu/paller-cyberse…