Chris DiSalle  

371 Followers
265 Following
93 Posts

Nerdy shit and good vibes.
Technical Lead, Incident Response @ Cisco Talos Intelligence Group

#hacking, #dfir, #redteam, #blueteam, #coding, #3dprinting, #vanlife, #camping

Twitterhttps://twitter.com/chrisdfir
LinkedInhttps://www.linkedin.com/in/chrisdisalle
GitHubhttps://github.com/chrisdfir
Come swing by the booth and say hey If you are headed to #RSAC next week. Be prepared for nerdy discussions.

#DFIR #Threathunting Tip

When performing analysis to hunt for a specific MITRE ATT&CK technique, gathering information on potential tools, commands, and arguments in advance can be highly beneficial. One method that produces quick wins is to search that technique on GitHub where you can find basic detection logic from Red Canary, SIGMA, Swimlane, etc.


- Search all repositories on GitHub for technique (e.g. T1083)
- Switch search to ‘Code’ and Language to ‘Markdown’
- Sort by ‘Recently indexed’
- Review and integrate top findings into hunt
- Profit

@bsidesorlando Lunch break! What a conference!

2023 Snort Calendars are here! #infosec #cybersecurity

"Want a copy? NEED a copy? Simply fill out our short survey here. Calendars will begin shipping after December 1, 2022. U.S. shipping only, available while supplies last."
Source: https://blog.talosintelligence.com/threat-source-newsletter-nov-17-2022/

Survey link: https://ciscocx.qualtrics.com/jfe/form/SV_8CYvpkAudw91ltk

Threat Source newsletter (Nov. 17, 2022): Hot off the press! The Snort 2023 Calendar is here

The Snort 2023 calendar is finally here, and y’all, it’s a good one. Packed full of classic memes and punny Snorties, the calendar is sure to delight all year long.

Cisco Talos Blog

A couple more #Artemis shots from Orlando

#Artemis1 #Moon #NASA #SLS

My view of #artemis from Central Florida

#Artemis1 #Moon #NASA #SLS

Following #infosec hashtags for the win
Happy #mondog!!
Just an old boy and his birthday cake toy. The bestest boy is now 12. #NotACat #dog #birthday