tomchop

@tomchop@infosec.exchange
1.1K Followers
412 Following
120 Posts
Digital Forensics & Incident Response 
@ Google by day; threat intel and malware analysis by night. CertSG alumn. #BlueTeam #DFIR #CTI • Views are my own • he/him
Keybasehttps://tomchop.keybase.pub/mastodon.html
GitHubhttps://github.com/tomchop

Please feel free to use (and tell us when you do! we love hearing about people's use-cases), file lots of bugs, and feel free to contribute: guides, documentation, even cool screenshots, everything is welcome.

We are looking forward to integrating formats such as https://dfiq.org, shipping tighter integrations with DFIR platform tools like
@TimesketchProj,
@TurbiniaProj and CTI platforms like @MISPProject
(and hopefully many more!)

Home - DFIQ (Digital Forensics Investigative Questions)

139 commits to the frontend SPA
The changes in the codebase have been massive (remember, it's only 2 people working on this): 480 commits to the API server
This version marks the start of a focus shift away from classic CTI and towards a platform for DFIR teams wishing to integrate CTI in their pipelines for incident response, threat hunting, and detection, and to be able to collate "forensics intelligence" to share with other teams.

This has been years in the making, literally.
@sebdraven
and I are happy to announce the release of #Yeti 2.0 ✨ 🍰 (after we promised an EOM release at
@hack_lu
last month 😅)

Website: https://yeti-platform.io
Release: https://github.com/yeti-platform/yeti/releases/tag/2.0

#DFIR #CTI #infosec #cybersec

mini-🧵👇🏼

Welcome to the Yeti documentation site!

@Sebdraven @hack_lu We're also running a workshop about it two days later. https://pretalx.com/hack-lu-2023/talk/7G8EKN/, in case you wanna see all this in action!
Full Stack Forensics with FOSS hack.lu

- Introduction - What to expect of the workshop - Quick tour / install / configuration - Timesketch - Yeti - Adding some forensics intelligence to Yeti - Your first forensic analysis with Timesketch! - Adding threat intelligence to the mix Optional (if time permits) - dfTimewolf - Configuring all these tools to work together, triggering a first analysis using dfTimewolf. - Tweaking Timesketch analyzers

I haven't had time to talk about it, but @Sebdraven and I are giving a talk this week at @hack_lu about some cool new changes coming to Yeti: https://pretalx.com/hack-lu-2023/talk/JAKAKS/

It's going to be fun to talk about this project that has been on my todo list for 10+ years! 😅 #DFIR

Yeti - old dog, new tricks hack.lu

We are going to tell the story of Yeti, why it was created, where it's now, and about all the friends we made along the way. Besides the new DFIR twist we want to give Yeti, we'll highlight some of the major changes in the codebase: - Total revamp of the Web UI using VueJS. - Backend migration to ArangoDB (graph database) - Code health: Python typing, e2e tests, making development faster and more reliable, and making community contributions much easier. - Production and development Docker images - Integration with third-party OSS tools such as Timesketch and Turbinia.

My team just released https://dfiq.org, which is "a collection of Digital Forensics Investigative Questions and the approaches to answering them."

The idea came from the will to organize investigative approaches to similar cases to increase consistency across response efforts. #dfir #infosec

Home - DFIQ (Digital Forensics Investigative Questions)

📢 The #BSides Zurich #CfP has still about a month to go. It's a laid-back one-day event in Zurich, Switzerland. 🇨🇭

First time presenter? Applications for our mentoring program close in ~two weeks (May 18), so better hurry up!

https://bsideszh.ch/call-for-papers/

Call for Papers

Conference format We want BSides Zurich to be a conference where attendees and speakers have a real opportunity to mingle and engage in active discussions. In order to achieve this, we chose an atypical conference format that our attendees have really enjoyed. There are a total of 6 talks plus a keynote, all in English. Talks are grouped by 3 and are divided into two sessions (morning and afternoon). Each talk is only 20 minutes long, and after the 3 morning talks, each speaker gets an assigned room for a 30-minute-long breakout “discussion” session.

I'm very excited to announce the release of #Yeti 2.0-Alpha. Yeti is undergoing major changes, one of them is a ✨brand new ✨ frontend based on VueJS.

Please feel free to take it for a spin, but don't take it too seriously: many more improvements are to come! 🚀 #CTI #DFIR #Automation #threatintel

https://github.com/yeti-platform/yeti/releases/tag/2.0-Alpha

Release 2.0-Alpha · yeti-platform/yeti

This is an Alpha version, so expect things to be broken and change a lot. Use at your own risk! Some major changes: New installation process using docker Revamp of the whole UI to a modern web fro...

GitHub