Sajid Nawaz Khan 

150 Followers
476 Following
309 Posts
CTI, DFIR, Python Data Analysis. Oh, and food, films, museums, plants and kindness 🏳️‍🌈🇬🇧
GitHubhttps://github.com/ssnkhan
Keybasehttps://snkhan.keybase.pub/mastodon.html
LocationSheffield, United Kingdom

The release of ATT&CK v19, expected on 28 April 2026, will split the Defense Evasion tactic into two: Stealth, and Impair Defenses.

As a result of these updates, a number of sub-techniques within T1562 (Impair Defenses) will likely now be promoted to technique level. More details at:

https://medium.com/mitre-attack/defense-evasion-split-a-tale-of-two-tactics-5d533545fa32

Defense Evasion Split: A Tale of Two Tactics

By Allison Henao and Alice Koeninger

Medium
@ivory Running build 24177 on iPad, and the app clips into the status bar. Rotating to landscape and back fixes it momentarily, until the app is relaunched.
@TheDFIRReport Will this eventually be published as a Private Report? 🤲🏼

@tazwake Hi Taz, I’m guessing with this being an Electon app, it should theoretically be possible to compile it for Linux. Especially as some of the underlying libraries are already being used by the likes of Chainsaw and Hayabusa.

Edit: Looks like it uses Swift and some macOS specific frameworks including AppKit, so unlikely to compile without heavily modifying the code and rebuilding the UI.

I shall never tire of the Barbican.

#Barbican #CityofLondon #Brutalism #X100VI

If you’re a macOS user supporting with Windows digital forensics, you’ll love IRFlow Timeline:

“A high-performance native macOS application for DFIR timeline analysis. Built on Electron + SQLite to handle large files for forensic timelines (CSV, TSV, XLSX, EVTX, Plaso) without breaking a sweat. Inspired by Eric Zimmerman's Timeline Explorer for Windows.”

https://github.com/r3nzsec/irflow-timeline

/cc @taylorparizo @timb_machine @tazwake @4enzikat0r #DFIR

GitHub - r3nzsec/irflow-timeline: DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, and Plaso files with built-in process inspection, lateral movement tracking, and persistence detection.

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, and Plaso files with built-in process inspection, lateral movement tracking, and persistence detection. - r3nzsec/i...

GitHub

@teamcymru_S2 Hi, can you please include the publishing date on your blog posts please? e.g.,

https://www.team-cymru.com/post/tracking-orbs-on-singapores-telecommunications-networks

APT Attacks in Singapore Telecom: UNC3886 ORB Tracking Explained

APT attacks by UNC3886 target Singapore telecom using ORB networks. Learn practical ORB tracking techniques to uncover hidden infrastructure with Scout.

@Javvad They lose points for not including a clear publishing date on their blog posts. Can’t even see it in the source code / metadata.

@mkbhd Have you tried Acme Weather yet? Built by the original Dark Sky developers:

https://acmeweather.com/blog/introducing-acme-weather

Acme Weather

@maldr0id I can offer this.