Frederic Baguelin (@udgover) 's Twitter Profile
Frederic Baguelin

@udgover

DFIR, programming, open source. @botconf orga commitee

ID: 398770468

calendar_today26-10-2011 14:35:26

3,3K Tweet

1,1K Followers

1,1K Following

Christophe Tafani-Dereeper (@christophetd) 's Twitter Profile Photo

New research study! We've analyzed the cloud security posture of thousands of environments across AWS, Azure, and Google Cloud datadoghq.com/state-of-cloud… 🧵

Thomas Roccia 🤘 (@fr0gger_) 's Twitter Profile Photo

#100DaysofYara Day 8: Introducing Yara Toolkit, an online app for all things Yara! 🚀 (It's not really day 8, I spent my weekend on it 😅) Since we're still early in the challenge, I thought it might be useful for some of you to have a dedicated portal, so I created Yara Toolkit

#100DaysofYara Day 8: Introducing Yara Toolkit, an online app for all things Yara! 🚀 (It's not really day 8, I spent my weekend on it 😅)

Since we're still early in the challenge, I thought it might be useful for some of you to have a dedicated portal, so I created Yara Toolkit
fwd:cloudsec (@fwdcloudsec) 's Twitter Profile Photo

We’re excited to announce the European version of the conference: fwd:cloudsec Europe! It will take place on the 17th of September 2024 in Brussels, Belgium. CFP and registration will open in Spring, stay tuned!

We’re excited to announce the European version of the conference: fwd:cloudsec Europe! 

It will take place on the 17th of September 2024 in Brussels, Belgium. CFP and registration will open in Spring, stay tuned!
Frederic Baguelin (@udgover) 's Twitter Profile Photo

Thanks to open source tools and datasets, plotting IP addresses by countries on fancy choropleth map is super easy! - Jupyter notebook with plotly or folium - Alexandre Dulaunoy @[email protected]'s GeoOpen mmdb - BlockList.de ssh ip dataset Run in the cloud thanks to Binder Team mybinder.org/v2/gh/udgover/…

Thanks to open source tools and datasets, plotting IP addresses by countries on fancy choropleth map is super easy!

- Jupyter notebook with plotly or folium
- <a href="/adulau/">Alexandre Dulaunoy @adulau@infosec.exchange</a>'s GeoOpen mmdb
- <a href="/blocklist/">BlockList.de</a> ssh ip dataset

Run in the cloud thanks to <a href="/mybinderteam/">Binder Team</a>

mybinder.org/v2/gh/udgover/…
Thomas Roccia 🤘 (@fr0gger_) 's Twitter Profile Photo

🚀 Today at the InfoSec Jupyterthon conference! I released the Jupyter Universe project 🌌 - a community-driven search engine that catalogs infosec notebooks! Now, finding a notebook for a specific usecase just got easier! A thread! 🧵 #infosec #python #jupyter #notebook 👉 pic.x.com/03AaVxwr9h

Nick Frichette (@frichette_n) 's Twitter Profile Photo

New from Datadog Security Research! Here's the story of how tracking SNS enumeration activity across multiple customer environments led to the takedown of a phishing site that was impersonating the French government. securitylabs.datadoghq.com/articles/tales…

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

Verified! The first #Docker escape at #Pwn2Own involved two bugs, including a UAF. The team from STAR Labs SG did great work in the demonstration and earned $60,000 and 6 Master of Pwn points. #P2OVancouver

Verified! The first #Docker escape at #Pwn2Own involved two bugs, including a UAF. The team from STAR Labs SG did great work in the demonstration and earned $60,000 and 6 Master of Pwn points. #P2OVancouver
Frederic Baguelin (@udgover) 's Twitter Profile Photo

Bonjour Assurance Maladie quelle est votre définition de "momentanément" ? Jours, semaines, mois ? Votre service en ligne de renouvellement de carte vitale ne fonctionne pas depuis le début de l'année... Et non, je ne souhaite pas effectuer la démarche par courier.

Bonjour <a href="/Assur_Maladie/">Assurance Maladie</a> quelle est votre définition de "momentanément" ? Jours, semaines, mois ? Votre service en ligne de renouvellement de carte vitale ne fonctionne pas depuis le début de l'année... Et non, je ne souhaite pas effectuer la démarche par courier.
blasty (@bl4sty) 's Twitter Profile Photo

some people asked for the code .. so I decided to quickly refactor my scrappy paramiko script and turned it into an ssh agent implementation that works with a vanilla openssh client that has a single line patched out. github.com/blasty/JiaTans…

some people asked for the code .. so I decided to quickly refactor my scrappy paramiko script and turned it into an ssh agent implementation that works with a vanilla openssh client that has a single line patched out. github.com/blasty/JiaTans…
tomchop (@tomchop_) 's Twitter Profile Photo

📢 #Yeti is now part of the ODFIR infrastructure automation project! It's never been easier to connect it to a Timesketch instance and enrich all your sketches with juicy forensics intelligence ✨ More details here 👇🏻 osdfir.blogspot.com/2024/04/welcom… #DFIR #CTI #Timesketch

Nick Frichette (@frichette_n) 's Twitter Profile Photo

In case you missed it, check out our latest AWS vulnerability! We uncovered two scenarios in which the AWS Amplify service was exposing IAM roles to takeover! Anyone in the world could have gotten access to a victim AWS account through these methods! securitylabs.datadoghq.com/articles/ampli…

Kunai Project (@kunai_project@infosec.exchange) (@kunai_project) 's Twitter Profile Photo

🔧 JIT: A new Kunai release is available before my talk/workshop at Pass the SALT Conference 2024 ! It includes bug fixes, probes enhancements and perf improvements for a tailored #threathunting experience on #linux systems. Check it out: github.com/kunai-project/…

Thanat0s (@__thanat0s__) 's Twitter Profile Photo

Hey, cannot update yet ? Wanna avoid CVE-2024-6387 #regreSSHion exploits. Update your fail2ban to spot the exploit. It is very very noisy.... add ^ssh_dispatch_run_fatal: Connection from <HOST> port to cmdfailre parameter in sshd.conf filter.

@onyphe.io (@onyphe) 's Twitter Profile Photo

❓Ever wanted to have an IP geolocation database with 2 locations, one physical for the device and one logical from whois data? 👉We provide a free MMDB file for download and a brand new Website for lookups & even a free API access: geolocus.io

Thomas Roccia 🤘 (@fr0gger_) 's Twitter Profile Photo

🤓 I built an #MCP for NOVA so you can use it as a guardrail for your AI system. NOVA is a prompt pattern matching framework. It is primarily used for prompt hunting, similarly to how you use YARA for hunting files. But NOVA can also be used as a guardrail to prevent malicious

Who said what? (@g0njxa) 's Twitter Profile Photo

Bearhost (aka UNDERGROUND and recently VOODOO SERVERS), alledgelly the "biggest bulletproof hosting" has decided to do an exit scam after several years of service, leaving a "farewell note" in forums and shutting down servers suddenly with no further reasons Spamhaus abuse.ch

Bearhost (aka UNDERGROUND and recently VOODOO SERVERS), alledgelly the "biggest bulletproof hosting" has decided to do an exit scam after several years of service, leaving a "farewell note" in forums and shutting down servers suddenly with no further reasons

<a href="/spamhaus/">Spamhaus</a> <a href="/abuse_ch/">abuse.ch</a>
Pass the SALT Conference (@passthesaltcon) 's Twitter Profile Photo

After #HW, let's dive into our #DFIR/TI session🥰: - tomchop will speak about #OpenRelik a new collaborative IR invest portal 🚀 - Frederic Baguelin & Matt Muir will introduce us to their e2e malwares processing workflow using FLOSS - and we'll be able to practice #MISP as analysts

After #HW, let's dive into our #DFIR/TI session🥰:

- <a href="/tomchop_/">tomchop</a> will speak about #OpenRelik a new collaborative IR invest portal 🚀

- <a href="/udgover/">Frederic Baguelin</a> &amp; <a href="/_mattmuir/">Matt Muir</a> will introduce us to their e2e malwares processing workflow using FLOSS 

- and we'll be able to practice #MISP as analysts