Sign in

Chris DiSalle

@chrisdfir.updatex64.zip
275 followers 333 following 31 posts

Technical Lead, Incident Response @ Cisco Talos DFIR, drums, and the simple things

PostsRepliesMedia
Chris DiSalle @chrisdfir.updatex64.zip · 02/03/2026
The SAVE Act could change how Americans register to vote. Find out what documents you need — state-by-state guide: www.savethevotes.org #thesaveact #usa #democracy #voting #elections
savethevotes.org
Save the Votes — Citizen Preparedness Resource
Find out exactly what documents you need to vote under the SAVE Act. State-by-state guides, birth certificate costs, voter ID rules, and election office links for all 50 states.
001
Chris DiSalle @chrisdfir.updatex64.zip · 25/09/2025
Check out this blog post to learn more about our Incident Response team at Cisco Talos and how we can help your organization.
020
Reposted by Chris DiSalle
Cisco Talos Intelligence Group @talosintelligence.com · 15/09/2025
Experiencing a security incident? The Cisco Talos Incident Response team delivers fast, expert support to help you identify, contain and remediate threats when every second counts: www.youtube.com/watch?v=XFw0...
112
Reposted by Chris DiSalle
Cisco Talos Intelligence Group @talosintelligence.com · 28/04/2025
Watch out for threat actors who try to reel you in! 🎣 Phishing to achieve initial access soared this quarter, comprising 50% of all Talos IR incidents. Read our Quarterly Trends report for Q1 2025: cs.co/633252gat3
Quarterly Trends
021
Chris DiSalle @chrisdfir.updatex64.zip · 31/03/2025
Hot off the press! Check out the Talos 2024 Year In Review report to learn about threat actor activities we encountered last year.
010
Chris DiSalle @chrisdfir.updatex64.zip · 10/02/2025
The post-SB set list.. GNX
010
Chris DiSalle @chrisdfir.updatex64.zip · 30/01/2025
Get the latest on what our team is seeing in the quarterly trends report! #dfir #cybersecurity
040
Chris DiSalle @chrisdfir.updatex64.zip · 22/12/2024
Found one of my favorites in the used bin at the record store today. Cat Stevens - Buddha and the Chocolate Box (1974)
080
Chris DiSalle @chrisdfir.updatex64.zip · 08/12/2024
New addition to the family today, Tater Tot the tortoise. 🐢 #liltottie #tortoise
030
Chris DiSalle @chrisdfir.updatex64.zip · 04/12/2024
Smooth beats fuel the DFIR soul.
open.spotify.com
My 2024 Wrapped - Get yours
2024 Wrapped
030
Reposted by Chris DiSalle
Chris DiSalle @chrisdfir.updatex64.zip · 01/12/2024
While there are some awesome methods to detect web shells with Yara, sometimes structured data can help solve the case. In this oversimplified example, I go over how you can use two artifacts with Velociraptor to help you find evil on your Linux server. #dfir #blueteam #cybersecurity
linkedin.com
Hunting Linux Web Shells with Velociraptor
Linux forensics can be tricky, especially when investigating subtle threats like web shells. Unlike Windows, which provides tools like the Master File Table ($MFT) for metadata-rich investigations, Li...
0126
Chris DiSalle @chrisdfir.updatex64.zip · 01/12/2024
While there are some awesome methods to detect web shells with Yara, sometimes structured data can help solve the case. In this oversimplified example, I go over how you can use two artifacts with Velociraptor to help you find evil on your Linux server. #dfir #blueteam #cybersecurity
linkedin.com
Hunting Linux Web Shells with Velociraptor
Linux forensics can be tricky, especially when investigating subtle threats like web shells. Unlike Windows, which provides tools like the Master File Table ($MFT) for metadata-rich investigations, Li...
0126
Reposted by Chris DiSalle
Chris DiSalle @chrisdfir.updatex64.zip · 12/11/2024
#Linux lacks a resource like the Windows Master File Table ($MFT). I've developed this #Velociraptor artifact to collect metadata from files and folders recursively in selected paths to create a bodyfile. This may bring an MFT-like feel to filesystem analysis. #dfir github.com/chrisdfir/Ve...
github.com
23014
Chris DiSalle @chrisdfir.updatex64.zip · 26/11/2024
Played The Incredible Machine a lot as a little kid. Same dev has a modern version on Steam. store.steampowered.com/app/241240/C... #games #steam
store.steampowered.com
Contraption Maker on Steam
The spiritual successor to The Incredible Machine from its original designer and programmer. Play 100s of puzzles. Build and share elaborate contraptions with an huge variety of parts and critters.
110
Chris DiSalle @chrisdfir.updatex64.zip · 25/11/2024
"According to Cisco Talos’ data, roughly 60% of all email containing a QR code is spam." Malicious QR codes - how big of a problem is it really? Check out this 60 second recap. The full analysis is available at cs.co/6010tMy7s #cybersecurity #qrcodes #talosthings
cs.co
Malicious QR Codes: How big of a problem is it, really?
QR codes are disproportionately effective at bypassing most anti-spam filters. Talos discovered two effective methods for defanging malicious QR codes, a necessary step to make them safe for consumpti...
041
Reposted by Chris DiSalle
Andy Greenberg @agreenberg.bsky.social · 22/11/2024
Russian spies—likely Russia's GRU intelligence agency—used a new trick to hack a victim in Washington, DC: They remotely infected another network in a building across the street, hijacked a laptop there, then breached the target organization via its Wifi. www.wired.com/story/russia...
wired.com
Russian Spies Jumped From One Network to Another Via Wi-Fi in an Unprecedented Hack
In a first, Russia's APT28 hacking group appears to have remotely breached the Wi-Fi of an espionage target by hijacking a laptop in another building across the street.
12571320
Chris DiSalle @chrisdfir.updatex64.zip · 21/11/2024
The 2025 Snort Calendar has arrived 🎉 This year’s theme is Video Games! To get your copy of the 2025 Snort Calendar, fill out our short survey here: cs.co/6018sNeKi Calendars will begin shipping in December 2024. U.S. shipping only, available while supplies last. #cybersecurity #snort #talosthings
120
Chris DiSalle @chrisdfir.updatex64.zip · 21/11/2024
New edition of the Talos Threat Source Newsletter is out. Drums, leadership communications, and the intersection between. Good stuff although I wouldn't say Travis Barker is "easy".. those hands are fast. #cybersecurity #threatintel #talosthings
blog.talosintelligence.com
Bidirectional communication via polyrhythms and shuffles: Without Jon the beat must go on
The Threat Source Newsletter is back! William Largent discusses bidirectional communication in the SOC, and highlights new Talos research including the discovery of PXA Stealers.
010
Chris DiSalle @chrisdfir.updatex64.zip · 21/11/2024
Topics covered with the kids: - What is cybersecurity? (high level) - How does the Internet work? - Underwater sea cable map - How technology can be used for bad - Stranger danger - Password security hands-on - Don't click random things #cybersecurity #education #teachin
330
Chris DiSalle @chrisdfir.updatex64.zip · 20/11/2024
Speaking at the elementary school teach-in tomorrow. Building a small cyber army one class room at a time. It's the long game... #cybersecurity
010
Reposted by Chris DiSalle
Mehmet Ergene @cyb3rmonk.bsky.social · 20/11/2024
🔥 You can now allow/block FQDNs using Windows Firewall learn.microsoft.com/en-us/window...
learn.microsoft.com
Windows Firewall dynamic keywords
Learn about Windows Firewall dynamic keywords and how to configure it using Windows PowerShell.
0229
Reposted by Chris DiSalle
Pierre Cadieux @pchobbit.bsky.social · 19/11/2024
Hey #infosec and #cybersecurity folks. I have a couple thinky questions I'd like to get perspective on: - What makes a "good" cybersecurity partner in this day and age? - What services or capabilities are table stakes for you? always curious what you folks are seeing or would like to see
152
Reposted by Chris DiSalle
Eric Capuano @eric.zip · 18/11/2024
Random Monday thoughts… As most of us have come here to find a safe haven from extremism, I feel it’s important not to use this sanctuary to intentionally sow further division. Paraphrasing Ram Dass, “individualism leads to war, anger, insecurity, and fear.”
1323
Chris DiSalle @chrisdfir.updatex64.zip · 18/11/2024
Securing a #web server? Consider using CSPBypass to check your HTTP headers for flaws in your Content Security Policies (CSP). Designed for ethical hacking, this is can be multi-purpose. Protect ya neck! #cybersecurity #blueteam #websecurity #http github.com/renniepak/CS...
131
Chris DiSalle @chrisdfir.updatex64.zip · 17/11/2024
This git is full of resources for event logs/auditing. Covers everything from tool configs to audit cheatsheets to event attack chains and data samples. In #DFIR visibility is key. This is a solid resource for those responding to an incident or trying to prevent one. #grc github.com/stuhli/aweso...
github.com
GitHub - stuhli/awesome-event-ids: Collection of Event ID ressources useful for Digital Forensics and Incident Response
Collection of Event ID ressources useful for Digital Forensics and Incident Response - stuhli/awesome-event-ids
0136
Chris DiSalle @chrisdfir.updatex64.zip · 17/11/2024
Beastie Boys - License To Ill "Now here's a little story I've got to tell about three bad brothers you know so well"
010
Chris DiSalle @chrisdfir.updatex64.zip · 17/11/2024
Vulnerabilities from 2021 still haunt orgs. When I respond to attacks where these have been exploited I commonly hear "We were just about to upgrade that server next quarter." Yesterday's threats may still present risks today. Focus on asset and vulnerability management.. among other things.
000
Chris DiSalle @chrisdfir.updatex64.zip · 15/11/2024
Digging deck.blue for the ability to add columns for lists and hashtags. This helps keep the posts most important to me from getting lost in the sauce.
262
Reposted by Chris DiSalle
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 14/11/2024
MemProcFS is a GREAT Memory Forensics tool. Sharing here in case you have not checked this before! #DFIR #MemoryForensics #MemProcFS github.com/ufrisk/MemPr...
github.com
GitHub - ufrisk/MemProcFS: MemProcFS
MemProcFS. Contribute to ufrisk/MemProcFS development by creating an account on GitHub.
1398
Chris DiSalle @chrisdfir.updatex64.zip · 14/11/2024
It's no surprise, credential reuse from infostealers is fueling authentication attacks. Our researchers at Talos detailed findings around a new campaign targeting education and government orgs, PXA Stealer. blog.talosintelligence.com/new-pxa-stea... #threatintel #infostealer #talosthings
blog.talosintelligence.com
New PXA Stealer targets government and education sectors for sensitive information
Cisco Talos discovered a new information stealing campaign operated by a Vietnamese-speaking threat actor targeting government and education entities in Europe and Asia.
030
Reposted by Chris DiSalle
Kevin 🤖🕵️🍺 @stark4n6.bsky.social · 14/11/2024
It's been a while but 35% off on my Teepublic shop running now www.teepublic.com/user/stark4n6
teepublic.com
T-Shirts by stark4n6 | TeePublicSearchFilterClose
Shop t-shirts, phone cases, hoodies, art prints and mugs created by independent artists from around the globe.
184
Chris DiSalle @chrisdfir.updatex64.zip · 13/11/2024
Is anyone using X-Ways X-Tensions worth sharing for #DFIR? I've found the Yara plugin from CS to be pretty useful. github.com/CrowdStrike/... Greater list of plugins for those interested: www.x-ways.net/forensics/x-... #cybersecurity #blueteam #digitalforensics
000
Reposted by Chris DiSalle
Tom Warren @tomwarren.co.uk · 12/11/2024
wowzers, 1 million people have now joined Bluesky in the past week 🤯 if you're new to Bluesky here's some useful tools: • Deck Blue (TweetDeck for Bluesky) • Bluesky Directory of starter packs to follow people • Verge staff starter pack • Sky Follower Bridge for finding your Twitter friends
42773209
Chris DiSalle @chrisdfir.updatex64.zip · 13/11/2024
Cisco Talos Incident Response (Talos IR) recently observed an attacker conducting big-game hunting and double extortion attacks using the relatively new Interlock ransomware. Read the blog here: cs.co/6019SsMIh #dfir #threatintel #cybersecurity
cs.co
Unwrapping the emerging Interlock ransomware attack
Cisco Talos Incident Response (Talos IR) recently observed an attacker conducting big-game hunting and double extortion attacks using the relatively new Interlock ransomware.
0164
Chris DiSalle @chrisdfir.updatex64.zip · 12/11/2024
#Linux lacks a resource like the Windows Master File Table ($MFT). I've developed this #Velociraptor artifact to collect metadata from files and folders recursively in selected paths to create a bodyfile. This may bring an MFT-like feel to filesystem analysis. #dfir github.com/chrisdfir/Ve...
github.com
23014
Chris DiSalle @chrisdfir.updatex64.zip · 12/11/2024
#Linux forensics can be a pain. I've created this #Velociraptor artifact to output regular files, sockets, device files, and deleted files used by each process. This artifact collects metadata about open file descriptors from active processes. #dfir docs.velociraptor.app/exchange/art...
docs.velociraptor.app
Linux.Forensics.ProcFD :: Velociraptor - Digging deeper!
1151