
Chad Tilbury
@chadtilbury
Digital forensics and incident response. Ex-AFOSI, Mandiant, and CrowdStrike. SANS Institute Fellow and co-author of #FOR500 and #FOR508 courses.
ID: 119530615
https://www.forensicmethods.com/ 03-03-2010 22:56:26
4,4K Tweet
22,22K Followers
602 Following


After watching Josh's talk at the DFIRSummit, he released the excellent blog too! #DFIR




The team at Trend Micro has a nice write up on #cryptojacking threat actors using a recent #Confluence #vulnerability for initial access. ⚠️ If you find a crypto minner running, figure out how the threat actor got in, not just simply remove the minner. 🔗 trendmicro.com/en_us/research…


If you're interested in getting into #Linux #logging and evidence collection, this is an excellent write-up from Kostas that compares #EVTX logs on Windows with #Auditd, #SysMon for Linux, and native Linux logging. #DFIR #LinuxForensics #SIEM #CSIRT kostas-ts.medium.com/telemetry-on-l…







ChromeKatz: Dump cookies and credentials directly from Chrome/Edge process memory. Credential manager creds in plain text with no need to access on disk database! Similarly, CookieKatz dumps decrypted cookies (including incognito mode). github.com/Meckazin/Chrom… (via Spiros Fraganastasis)

💡 Join Certified Instructor Simon Vernon , September 19, as he guides you through configuring, scaling, and securing your logging setup with Azure’s latest feature. 🗓️ 10:00 am ET / 14:00 UTC ⌛️Register now: buff.ly/4fRprPk #SANSCloudAce #CloudSecurity

Cracking OneDrive's Personal Vault by Brian Maloney malwaremaloney.blogspot.com/2024/09/cracki… >> Great explanation and step-by-step instructions!


