Sign in

Antonio Sanz

@antoniosanzalc.bsky.social
252 followers 150 following 3.2K posts

Fighting evil 24x7. Incident Response & Digital Forensic guy, infosec maniac... and a damn good cook. My team is blue #DFIR - antoniosanzalc@infosec.exchange

PostsRepliesMedia
Antonio Sanz @antoniosanzalc.bsky.social · 09/02/2026
!Este año hago doblete en la @rootedcon! Junto con mi compañero AntonioE, contaremos dentro del track de @ProtAAPP todas las miserias y penurias que hemos sufrido gestionando incidentes de O365 (que llevamos más palos que una estera, tenemos PX) (1/n)
100
Antonio Sanz @antoniosanzalc.bsky.social · 02/02/2026
Este año volvemos a la #RootedCON con una charla llena de TTP, malware, mala baba y drama. Mi compinche en el bien Ana Nieto y yo vamos a desgranar un incidente del grupo APT Lazarus desde dos puntos de vista: malware y respuesta ante incidentes.
rootedcon.com
RootedCON - RootedCON
RootedCON es el mayor congreso de ciberseguridad en España, con ponencias, formaciones y networking para expertos y entusiastas del hacking
100
Reposted by Antonio Sanz
Kostas @kostastsale.bsky.social · 20/11/2025
𝗦𝘂𝗿𝗶𝗰𝗮𝘁𝗮 𝗶𝘀 𝗻𝗼𝘄 𝗽𝗮𝗿𝘁 𝗼𝗳 𝗗𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻𝗦𝘁𝗿𝗲𝗮𝗺 𝘄𝗶𝘁𝗵 𝗽𝗹𝗮𝘆𝗴𝗿𝗼𝘂𝗻𝗱𝘀 𝗮𝗻𝗱 𝗰𝗵𝗮𝗹𝗹𝗲𝗻𝗴𝗲𝘀! Big update for anyone working on network detections. 𝗜𝗻𝗰𝗹𝘂𝗱𝗲𝗱: • 45k+ ET rules available out of the box • Full ET Open ruleset preloaded • Build and validate custom Suricata rules
kostas-ts.medium.com
DetectionStream Just Got a Major Upgrade: Suricata Integration is Here!
I’m excited to share some big news! We’ve just rolled out a massive update to DetectionStream, and it’s one that I had planned to add for a…
143
Reposted by Antonio Sanz
malmoeb.bsky.social @malmoeb.bsky.social · 14/11/2025
This is wild. From a recent IR engagement led by my teammate Florian Scheiber: "The investigation showed that the attacker first compromised the Administrator’s personal Gmail account, redacted@gmail.com. Those credentials appeared in a combolist leaked on 2 June 2025.
122
Antonio Sanz @antoniosanzalc.bsky.social · 30/10/2025
Un honor y un placer volver a participar en las XIX Jornadas STIC del @CCNCERT . Me tendréis el miércoles 26/nov en la sala 25 hablando de un caso de respuesta ante incidentes de un grupo APT muy muy muy jugoso. Malware, ing soc, nube ... drama !de todo! 😅🔥👩‍🚒🧑‍🚒 #STIC2025
000
Reposted by Antonio Sanz
Veni Kunche @veni.dev · 27/10/2025
Check Settings > Manage Apps in your Google Drive, Gemini was enabled by default for me. I only checked because someone had pointed it on Twitter
Screen shot of my setting screen. Settings > Manage Apps shows a list of apps that are connected to my account with the checkbox "Use by default" next to Gemini checked
68047
Antonio Sanz @antoniosanzalc.bsky.social · 14/10/2025
Este 3 y 4 de noviembre repito el curso de #DFIR en la Universidad de Zaragoza. Batallitas, enfoque muy práctico (uno de los días será un CTF entero donde desgranaremos un incidente) y mucho, mucho sobre cómo abordar y responder a incidentes de ciberseguridad !Vamos! 🧑‍🚒🧑‍🚒🧑‍🚒
000
Antonio Sanz @antoniosanzalc.bsky.social · 15/09/2025
Aún queda alguna plaza suelta en la formación de #DFIR que voy a dar en la #rootedconVLC. Si tienes RAM suficiente para meterte un .tar.gz con conocimientos de respuesta ante incidentes ... !vente! La info aquí (que si no te va el DFIR, hay también cosas MUY interesantes): rootedcon.com/formaciones/
rootedcon.com
Formaciones - RootedCON
Próximas formaciones El mundo de la tecnología y, en particular, el de la ciberseguridad requieren de constante actualización. Una de […]
000
Reposted by Antonio Sanz
hakan @hatr.bsky.social · 11/09/2025
if you are interested in apt/hacking history, this interview describing how the apt1 report came to be is for you www.zetter-zeroday.com/how-the-infa...
zetter-zeroday.com
How the Infamous APT 1 Report Exposing China’s PLA Hackers Came to Be
This is the first in a series of pieces I’ll publish that take an in-depth look at significant events, people and cases in security and surveillance from the past. If there’s something you think would...
01410
Reposted by Antonio Sanz
The DFIR Report @thedfirreport.bsky.social · 30/06/2025
🌟New report out today!🌟 Hide Your RDP: Password Spray Leads to RansomHub Deployment Analysis and reporting completed by @tas_kmanager, @iiamaleks and UC2 🔊Audio: Available on Spotify, Apple, YouTube and more! thedfirreport.com/2025/06/30/h...
thedfirreport.com
Hide Your RDP: Password Spray Leads to RansomHub Deployment
Key Takeaways Initial access was via a password spray attack against an exposed RDP server, targeting numerous accounts over a four-hour period. Mimikatz and Nirsoft were used to harvest credential…
032
Reposted by Antonio Sanz
Jose Manuel Redondo López @theroundedman.bsky.social · 27/06/2025
Ha llegado la hora de ir regalando contenido a la gente que le pueda interesar. Voy a liberar mis presentaciones para gente de la ESO, por si a alguien le sirven de algo :). Subiré una nueva cada viernes al principio y luego, pues iremos viendo. También las haré en video github.com/jose-r-lopez...
github.com
Home
Formación en ciberseguridad para jóvenes de José Manuel Redondo López - jose-r-lopez/Formacion_-Seguridad_Joven
2014866
Reposted by Antonio Sanz
Kostas @kostastsale.bsky.social · 23/06/2025
DFIR Labs Subscriptions are live 🎉 At $𝟏𝟒.𝟗𝟗/𝐦𝐨𝐧𝐭𝐡, we’re offering something we’re truly proud of, not just great training, but a model that’s sustainable and community-focused. /1
dfirlabs.thedfirreport.com
DFIR Labs - Subscription Plans
152
Reposted by Antonio Sanz
Kostas @kostastsale.bsky.social · 19/06/2025
IR isn’t about mastering tools. It’s about building structured investigation habits: →Start with what you do know →Reconstruct the timeline →Contain without alerting →Keep calm and correlate That confidence comes from method, not magic! /end
083
Antonio Sanz @antoniosanzalc.bsky.social · 04/06/2025
Muchas gracias a la ##c1b3rwall por otro año en el que todo ha ido como la seda. Como es habitual, aquí tenéis las slides de mi presentación sobre cómo mejorar en la gestión de incidentes de ciberseguridad #DFIR: bit.ly/c1b3rwall_incidentes
bit.ly
c1b3rwall2025: Errores frecuentes en incidentes de ciberseguridad
000
Reposted by Antonio Sanz
malmoeb.bsky.social @malmoeb.bsky.social · 14/05/2025
1/ In one of our recent incident response cases, we found a cleverly hidden backdoor that the attacker had installed on various computers and servers in the network. Disguised as a Microsoft Edge service, a Mesh agent was running under the path: C:\Program Files\Microsoft\MicrosoftEdge\msedge.exe
131
Antonio Sanz @antoniosanzalc.bsky.social · 30/04/2025
Si te has leído mi serie de artículos sobre el writeup del #CTF #DFIR de Baklava, pero los quieres leer en "modo informe", aquí tienes todos los recursos:
100
Antonio Sanz @antoniosanzalc.bsky.social · 28/04/2025
Encantado con la gente de hackademics-forum.com por un viernes la mar de guapo hablando de #ransomware. La gente majísima, Córdoba preciosa, !un lujazo! Y las slides, aquí: bit.ly/ransom2025 (ojo que van con extras como os dije) 😉😎👩‍🚒
hackademics-forum.com
Hackademics Forum 2025
Hackademics Forum es un espacio de encuentro dedicado a la ciberseguridad que consistirá en una mañana de charlas y una mesa redonda.
000
Antonio Sanz @antoniosanzalc.bsky.social · 23/04/2025
Cuarta entrega del writeup #DFIR del #CTF de Baklava: www.securityartwork.es/2025/04/22/b...
securityartwork.es
Baklava CTF Writeup – Incident Report Style (IV) - Security Art Work
SRV01 Dado que es un activo crítico para la Organización, se solicita por su parte un análisis forense del servidor. Se procesan en primer lugar los logs de eventos por Hayabusa, obteniendo los siguie...
000
Antonio Sanz @antoniosanzalc.bsky.social · 22/04/2025
Este viernes 25 estaré en Córdoba en el Hackademics Forum 2025 hablando de lo que hemos visto en #DFIR de incidentes de #ransomware hackademics-forum.com Como digo siempre, de lo que se aprende mejor es de los errores de los demás, así que... !vente! 😉🔥👨‍🚒
hackademics-forum.com
Hackademics Forum 2025
Hackademics Forum es un espacio de encuentro dedicado a la ciberseguridad que consistirá en una mañana de charlas y una mesa redonda.
000
Antonio Sanz @antoniosanzalc.bsky.social · 15/04/2025
Tercer parte del writeup del #CTF #DFIR de ctf.communia.cc : www.securityartwork.es/2025/04/09/b...
ctf.communia.cc
BaklavaCTF
000
Antonio Sanz @antoniosanzalc.bsky.social · 09/04/2025
Segunda entrada de la resolución del CTF #DFIR Baklava : www.securityartwork.es/2025/04/08/s...
securityartwork.es
Baklava CTF Writeup – Incident Report Style (II) - Security Art Work
Contenido 4.2. WS02 – 192.168.20.42 Se ejecuta la herramienta Hayabusa sobre los logs, encontrando las siguientes alertas: ──────────────────────────────────────╮ │ Top critical alerts:               ...
000
Antonio Sanz @antoniosanzalc.bsky.social · 08/04/2025
Hacía tiempo que no publicaba nada en el blog de @s2grupo , y ya tocaba: securityartwork.es/2025/04/07/b... Es interesante pq además de la resolución del reto #DFIR ... !está en modo informe! 😎😉🧐
securityartwork.es
Baklava CTF Writeup – Incident Report Style (I) - Security Art Work
Contenido Informe de Incidente BAKLAVA Parte 1 1. ¡WARNING! ¡LÉEME PRIMERO! Este documento que estás leyendo es un informe “real” de un incidente ficticio, basado en el CTF DFIR que los compañeros And...
000
Reposted by Antonio Sanz
Kevin 🤖🕵️🍺 @stark4n6.bsky.social · 11/03/2025
Autopsy is finally back! 🐕‍🦺🕵🏼‍♂️ #DFIR
043
Antonio Sanz @antoniosanzalc.bsky.social · 10/03/2025
Mis slides de la charla de la #RootedCON2025 "12 años luchando contra grupos #APT: Qué cojones hemos aprendido", están disponibles aquí: bit.ly/joputasAPT (y sí, con los adoquines del Pilar se bastiona de lujo, altamente recomendados 😂🥳🧐)
111
Antonio Sanz @antoniosanzalc.bsky.social · 10/03/2025
Ya soy persona después de una nueva edición de la #rootedcon2025, intensa como pocas. Como siempre, una locura de charlas, gente, amigos y cosas que aprender. Volquetes de gracias a la Organización de la @rootedcon por hacer que todo fuera como la seda (!y sin bajas!) 🥳👏🤘💪
010
Antonio Sanz @antoniosanzalc.bsky.social · 07/02/2025
Ayer me alegraron el mes: a dos de mis compañeros del equipo de #DFIR de @s2grupo (@nomed__1 y @alejandrochiri_ ) !!! les han aceptado su charla en la #RootedCON2025 !!! -> Wiiiiiiiiiiiiiiiiiiiiiiiiiiii 🥳🥳🥳🥳🥳🥳🥳
110
Antonio Sanz @antoniosanzalc.bsky.social · 05/02/2025
Muchos ya sabéis que @unizar es mi segunda casa😊. Este 17 de febrero de 17 a 18h en la @einaunizar.bsky.social daré una charla sobre cómo es trabajar en #ciberseguridad dentro de las NeoCOM24/25 organizadas por la @AATUZ. Si te pica la curiosidad (buena señal), !pásate y pregunta! 🤘💪👍
031
Antonio Sanz @antoniosanzalc.bsky.social · 03/02/2025
Un verdadero placer volver a estar en la #RootedCON2025 este año, además contando algo que conozco muy bien (hostias mediante): Cómo luchar contra APT (Advanced Persistent Threats). Muchas batallitas, algún que otro salseo, !y como siempre mucha mala baba! ¿A qué esperáis? 😎🥳🤘
021
Antonio Sanz @antoniosanzalc.bsky.social · 29/01/2025
Los que curramos en #DFIR funcionamos a base de evidencias, cafeína y una mezcla de odio y curiosidad. Pero las evidencias son nuestra base: si no tenemos, no podemos darte resultados sólidos, solo hipótesis basadas en nuestra experiencia (1/n)
110
Antonio Sanz @antoniosanzalc.bsky.social · 28/01/2025
Escenario: tienes tu backup en S3 vía Veeam Backup, con cifrado (por seguridad, you know). Si te cae un #ransomware a nivel de ESX, van a arrasar con TODAS tus VM... incluida la del Veeam Backup (1/2)
100
Reposted by Antonio Sanz
SwiftOnSecurity @swiftonsecurity.com · 23/01/2025
Doing external IR for hands-on-keyboard is crazy hard, it's not something I really do much but on occasion observe. The layers of people and systems and fog of war and butt covering and breadth of skills and investigative practice and tracking of threads of information and timeline mapping. Crazy.
91226
Reposted by Antonio Sanz
Marc Rivero | @seifreed @seifreed.bsky.social · 15/01/2025
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access buff.ly/3PuPNuC
buff.ly
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever…
012
Antonio Sanz @antoniosanzalc.bsky.social · 16/01/2025
Si estás en una investigación de un incidente #DFIR, y estás bloqueado: comenta el incidente con alguien (obviamente siguiendo las normas TLP). El mero hecho de tener que explicar a alguien te fuerza a ordenar las ideas... y te las aclara a ti mismo (1/n)
100
Antonio Sanz @antoniosanzalc.bsky.social · 24/12/2024
Feliz Navidad a toda la buena gente de #ciberseguridad, sobre todo a los equipos del SOC que hoy les toca currar velando a que todo esté en orden. A ver si los malos cambian por un día el teclado por el vodka... 🙌🤟🫡
130
Antonio Sanz @antoniosanzalc.bsky.social · 20/12/2024
Este año me he portado bien. He sido bueno. He parado muchos ataques. Solo quiero una cosa, Papá Noel: que todas las organizaciones pongan 2FA en sus VPN, y me quiten de trabajar en 2025 en #DFIR. En serio, gente... !HACEDLO! y !Felices Fiestas! 🥳🥳🥳
000
Antonio Sanz @antoniosanzalc.bsky.social · 17/12/2024
Estoy en una reunión con developas y gente de sistemas para un proyecto nuevo. El de sistemas ha empezado con "y dónde se guardan las pass?" "Y la HA?" In love con los sysadmin que saben su stuff...😍 😍 😍
020
Reposted by Antonio Sanz
inginformatico @inginformatico.bsky.social · 17/12/2024
Mastering Sysmon: Deploying, Configuring, and Fine-Tuning" by @dfirinsights. A free mini eBook for #DFIR professionals with practical steps to deploy, fine-tune, and start logging with Sysmon dfirinsights.com/2024/11/27/m... #DigitalForensics #IncidentResponse #Sysmon #CyberSecurity
032
Reposted by Antonio Sanz
Carly Page @carlypage.bsky.social · 11/12/2024
Security researchers at Lookout have uncovered a new surveillance tool that they say has been used by Chinese law enforcement to collect sensitive information from Android devices in China techcrunch.com/2024/12/11/r...
techcrunch.com
Researchers uncover Chinese spyware used to target Android devices | TechCrunch
The spyware, called EagleMsgSpy, has been used by Chinese law enforcement, according to cybersecurity firm Lookout.
0209
Reposted by Antonio Sanz
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 01/11/2024
If you need datasets for your #DFIR training? Feel free to use any of my cases found in the URL below. They can be used for both academic or commercial training. www.ashemery.com/dfir.html
1288
Reposted by Antonio Sanz
Daniel Cuthbert @dcuthbert.bsky.social · 11/12/2024
First up, Frédérick Douzet on the geopolitics of internet data routes. How access to the net is often heavily targeted by those wanting to control and have geopolitical control
1154
Antonio Sanz @antoniosanzalc.bsky.social · 09/12/2024
2h haciendo pruebas de velocidad de transferencia (tengo que copiar este viernes "unos pocos Tb para un amigo #DFIR"), y me veo que mis 2 discos SSD (Crucial X6 de 500Gb y Sandisk SSD Extreme de 1Tb) me dan 40-50MB/s leyendo de un SATA USB y escribiendo en un NVME USB (1/n)
121
Reposted by Antonio Sanz
Horkos @wylienewmark.bsky.social · 06/12/2024
And you thought your business had a lot of unpatched edge devices that enable long-dwell persistence! I love how so many problems in cybersecurity are basic and ubiquitous — like common networking appliances having code riddled with vulnerabilities — but people wanna invest in AI or whatever…
1238
Antonio Sanz @antoniosanzalc.bsky.social · 06/12/2024
Small treasures can be found on some EventLogs:
buff.ly
Finding Forensic Goodness In Obscure Windows Event Logs
Digital Forensics and Threat Hunting for Artifacts In Obscure Windows Event Logs
010
Antonio Sanz @antoniosanzalc.bsky.social · 05/12/2024
Great spreadshit for #DFIR to know if something was executed - blog.1234n6.com/available-ar...
blog.1234n6.com
Available Artifacts - Indicators of Execution Updated
The "Indicators of Execution" spreadsheet I put together in 2018 has been somewhat neglected of late. So, with the release of Server 2025 I set about updating it to reflect the current state of Window...
0131
Antonio Sanz @antoniosanzalc.bsky.social · 02/12/2024
Nuevo caso de DFIRreport, como siempre un lujo #DFIR thedfirreport.com/2024/12/02/t...
thedfirreport.com
The Curious Case of an Egg-Cellent Resume
Key Takeaways Initial access was via a resume lure as part of a TA4557/FIN6 campaign. The threat actor abused LOLbins like ie4uinit.exe and msxsl.exe to run the more_eggs malware. Cobalt Strike and…
011
Antonio Sanz @antoniosanzalc.bsky.social · 01/12/2024
Con respecto a la posible brecha de datos de #AEAT: en #ciberseguridad trabajamos con datos, no con rumores. No es la primera vez que un actor "dice tener datos" y luego es una filfa. Prudencia y análisis lo primero🧐🤓😄
1105
Antonio Sanz @antoniosanzalc.bsky.social · 29/11/2024
Organización impecable como siempre de las #XVIIIJornadasCCNCERT por parte del @CCNCERT, en lo que es uno de los mayores foros de #ciberseguridad de España y lugar de encuentro y aprendizaje
011
Antonio Sanz @antoniosanzalc.bsky.social · 25/11/2024
!Mañana comienzan las #XVIIIJornadasCCNCERT! Aquí tienes el programa completo: buff.ly/3B05Eh7 (y si quieres saber algo más de APT y de cómo luchamos contra ellas... mañana a las 11.15h en la sala 25 nos veremos ;) )
buff.ly
011
Antonio Sanz @antoniosanzalc.bsky.social · 25/11/2024
Un hilo imprescindible con herramientas de #Bluesky:
publico.es
El hilo que explica tres herramientas muy potentes de Bluesky para cortar la toxicidad
El hilo de un usuario de Bluesky explicando tres potentes herramientas para cortar la toxicidad en esta red social
032