Chris DiSalle :crt_w_prompt: :dumpster_fire:

Nerdy shit and good vibes.
Technical Lead, Incident Response @ Cisco Talos Intelligence Group

#hacking, #dfir, #redteam, #blueteam, #coding, #3dprinting, #vanlife, #camping

Chris DiSalle :crt_w_prompt: :dumpster_fire:chrisdfir@infosec.exchange
2023-04-20

Come swing by the booth and say hey If you are headed to #RSAC next week. Be prepared for nerdy discussions.

Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
2022-12-24
Daily Struggle / Two Buttons meme showing a sweating man struggling to choose a button to press: adduser or useradd
Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
2022-12-24

Cool thing happened at work yesterday. I was notified that I won a "beacon" award, this is an award that leaders are nominated for by their teams. This is an award only approved for 1% of the people leaders in the company. I am exceptionally humbled and very thankful to my team for nominating me and writing all of the great things they did as part of the submission process. I will continue to strive to improve daily, but very proud of where we are as a team and the excellent future we have made.

Chris DiSalle :crt_w_prompt: :dumpster_fire:chrisdfir@infosec.exchange
2022-12-14

The inaugural 2022 Talos Year in Review was released today! With the detail that went into this report, you don't want to sleep on it. Check it out in the link below. #dfir #blueteam #threatintel #talos

blog.talosintelligence.com/tal

Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
2022-12-14

I got to be a guest on Talos Takes! Talking about some of the best free ways to up your security learning game! #blueteamvillage #talos #defcon
buzzsprout.com/2018149/1158670

Chris DiSalle :crt_w_prompt: :dumpster_fire:chrisdfir@infosec.exchange
2022-12-12

Just used #ChatGPT to discover information about my wife's family ancestry. Turns out that lineage goes deep into the Sassanian Empire and Persian royalty about 1800 years ago or so. Sometimes the internet is cool.

Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
2022-12-08

Friends, we're thrilled to finally announce the launch of our first paid course!

Python for Defenders, Pt. 2, is out now! $14.99 USD.

This course builds on the free PFD1 and examines how to use #Python and #Jupyter Notebooks to analyze forensic and logging data to detect and understand malicious activity.

The course also examines the craft of writing Notebooks for use in a defense team, from writing style to user interface design.

We hope you'll love this course, and all the others available at the Institute.

#InfoSec #CyberSecurity #BlueTeam

taggartinstitute.org/p/python-

Python for Defenders, Pt. 2 logo.
Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
2022-11-28

If you need something to put on in the background, NASA’s #Artemis livestream is absolutely spectacular right now. Yes, that’s the Earth and the moon. video.ibm.com/channel/b4dEcL3b #space #science #nasa

The Artemis spacecraft on the left with the Earth and the moon on the right
Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
2022-11-25

Could I tempt you to boost this post, or get involved in a project to customise Linux for users with special needs/learning difficulties? I have two such children. Adults now (18). I want to do something for my boys and for people like them. 🙂❤️

I've already done a bit, using Ansible, with AlmaLinux and Ubuntu: github.com/robpomeroy/BrightOS

Please spread the word - I'm sure someone out there would love to get involved!

#SpecialNeeds #Linux #Education #NonProfit

"Tux" style penguin (Linux mascot) in a wheelchair, with a lightbulb shining nearby.
Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
BSides Orlando - September 26-27, 2025bsidesorlando@infosec.exchange
2022-11-23

📯 Thank you to everyone who made BSides Orlando 2022 a grand celebration of these unprecedented times. Farewell, for now, and fare thee well! 🐊🛡️

a large screen at the back of a dark stage displays a cartoon of an alligator in armor holding a banner of the BSides Orlando logo. In the foreground is a podium displaying a cartoon crest for the Order of the Toothy Grin. The stage is set for BSides Orlando 2022.
Chris DiSalle :crt_w_prompt: :dumpster_fire:chrisdfir@infosec.exchange
2022-11-23

#DFIR #Threathunting Tip

When performing analysis to hunt for a specific MITRE ATT&CK technique, gathering information on potential tools, commands, and arguments in advance can be highly beneficial. One method that produces quick wins is to search that technique on GitHub where you can find basic detection logic from Red Canary, SIGMA, Swimlane, etc.


- Search all repositories on GitHub for technique (e.g. T1083)
- Switch search to ‘Code’ and Language to ‘Markdown’
- Sort by ‘Recently indexed’
- Review and integrate top findings into hunt
- Profit

Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2022-11-21

Pals, I see a lot of people copy-pastaed their Twitter bio here - you can have longer and even formatted bios here, and remove all the kludges you did to make them fit on birdsite if you so desire! Remember, hastags of interests, groups, and topics help people find you. :a_trusted_friend:​

There are also custom emoji on your server (they vary) that you can utilize! (Here's a lookup to check a server's emojos.in/).

#MastodonTips

Chris DiSalle :crt_w_prompt: :dumpster_fire:chrisdfir@infosec.exchange
2022-11-21

@13Cubed I know when I roll out of bed and see that 13Cubed YT notification, it's going to be a good morning. Thanks for the great content!

Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
2022-11-21

Happy Thanksgiving week! 🦃 Here’s a new 13Cubed episode about MUICache – a Windows forensic artifact that doesn't get a lot of attention. Enjoy! youtube.com/watch?v=ea2nvxN878 #DFIR #forensics

Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
Goldie Chan :breadified:goldiechan@mstdn.social
2022-11-20

💚 everyone deserves to be loved 💙
💙 everyone deserves to be loved 💜
💜 everyone deserves to be loved ❤️
❤️ everyone deserves to be loved 🧡
🧡 everyone deserves to be loved 💛
💛 everyone deserves to be loved 💚

#Love #MentalHealth

Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
Alexis Brignoni :python: :donor:DFIR_abrignoni@infosec.exchange
2022-11-20
Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
willasaywhatwillasaywhat
2022-11-20

The badge @bsidesorlando this year was awesome. The SAO was a nice touch; going to have to bring that with me next summer camp.

Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
Dr Nestori Syynimaa :verified:DrAzureAD@infosec.exchange
2022-11-20

Slides from my "Attacking Azure Active Directory Under-The-Radar" talk at #BSides Orlando from this morning are available at aadinternals.com/talks

Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
2022-11-19

“We are releasing to the community a set of open-source YARA Rules and their integration as a VirusTotal Collection to help the community flag and identify Cobalt Strike’s components and its respective versions.”

cloud.google.com/blog/products

#cobaltstrike

Chris DiSalle :crt_w_prompt: :dumpster_fire: boosted:
Very Hairy Jerryjerry@infosec.exchange
2022-11-19

There’s been a lot of discussion about a rule we recently instituted regarding security testing on the infosec.exchange instance. I understand the value or pen testing as much or more than most people, and I’m fully cognizant that pen tests are happening all the time and I’m not getting the report. I get it. But there are now 28,000 people using this service to communicate. I know there are vulnerabilities waiting to be discovered. Finding blog post fodder by fuzzing instances that are already running hot due to explosive growth is not super helpful. But at the same time, I WANT that testing to happen.

As a result, I am going to set up two instances tomorrow that only federate with each other. This is where I’d prefer legitimate security testing be performed. I’ll also be using it as the QA environment to test new updates and settings prior to deploying to the production instance. I’ll moderate signups because I don’t want it accidentally becoming fediverse 2.0 in the ongoing rush for the doors at twitter, but will accept anyone who wants to join, with clear indications that it’s a sandbox and should not be considered safe.

Thanks for patience as we continue to find out way.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst