I had a great experience at #FTSCon on Monday. Both the speakers and the audience are such high caliber that an interesting discussion can be had at any point during the day. The information presented is useful for folks in any technical aspect of cybersecurity, not just DFIR folks. If you can, you should try to attend it next year.
Here are a few of the projects I enjoyed learning about this time around:
Thorium Malware Pipeline: https://github.com/cisagov/thorium
CTADL Static Taint Analysis Tool: https://github.com/sandialabs/ctadl
MinusOne, a deobfuscation engine for scripting languages: https://github.com/airbus-cert/minusone
EPIC Erebus for PCIe and DMA attack research: https://www.crowdsupply.com/securinghw/epic-erebus
GitHub - cisagov/thorium: A scalable file analysis and data generation platform that allows users to easily orchestrate arbitrary docker/vm/shell tools at scale.
A scalable file analysis and data generation platform that allows users to easily orchestrate arbitrary docker/vm/shell tools at scale. - cisagov/thorium











