Alexandre Dulaunoy · @adulau
1188 followers · 107 posts · Server infosec.exchange

Great news! The @misp and the @hashlookup integration is now merged in @TimesketchProj

Thanks to all who helped to make this happens. (David, Thomas, Alexander, Johan, Joachim)

github.com/google/timesketch/p

More documentation and use-cases will be shown in the next weeks.

#dfir #opensource #misp #Timesketch #hashlookup #threatintel #threathunting

Last updated 2 years ago

Wes Lambert · @weslambert
358 followers · 45 posts · Server infosec.exchange

🦖Day 83 of the @velocidex series

Artifact: Server.Utils.BackupGCS/S3

Link:
docs.velociraptor.app/artifact

docs.velociraptor.app/artifact

----

These artifacts are server monitoring artifacts that will watch for flow completions, then zip and send the results to Google Cloud, or an S3 bucket, using the 'upload_gcs()' and 'upload_s3()' functions.

docs.velociraptor.app/vql_refe

docs.velociraptor.app/vql_refe

----

Once uploaded, the collections can be left alone and remain archived, or special post-processing can be applied using third-party tools, depending on defenders' needs.

@eric_capuano and @shortxstack (@recon_infosec) did an excellent job presenting about using these artifacts with Timesketch to generate a timeline of events.

If you haven't already, be sure to check out their presentation from @SANS Summit 2021!

sans.org/presentations/breache

----

That's it for now! Stay tuned to learn about more artifacts! 🦖






#velociraptor #artifactsofautumn #dfir #forensics #infosec #plaso #threathunting #Timesketch

Last updated 2 years ago

cygnetix :unverified:​ · @cygnetix
401 followers · 136 posts · Server infosec.exchange

@seanosullivanuk I haven't used it a whole lot, but I've also heard good things about .

timesketch.org/

#Timesketch

Last updated 2 years ago

Alex · @jaegeral
188 followers · 52 posts · Server infosec.exchange

If you want a very recent Blog Article, two team mates wrote: osdfir.blogspot.com/2022/11/fi
is a cool new tool and the article is the follow up for: osdfir.blogspot.com/2022/08/ge

Where Michal introduces the tool. It can reduce the noise of finding badness in your forensic effort quite a lot. While the Blog is about you can for sure hook it up to any other workflow you have.

#hashr #Timesketch

Last updated 2 years ago