Sign in

tomchop

@tomchop.me
849 followers 381 following 132 posts

Cybersecurity nerd; #DFIR @ Google by day; FOSS, threat intel and malware analysis by night. Investigator, coder, terrible sense of humor. yeti-platform.io and more (github.com/tomchop) views are my own • he/him • tomchop.me

PostsRepliesMedia
tomchop @tomchop.me · 25/01/2026
Also, I dropped out of bsky before most of infosec twitter joined, so my feed is quite empty (or flooded by US politics...); are there any lists of cybersec nerds I'm missing?
110
tomchop @tomchop.me · 25/01/2026
I rarely post here, but when I do... I just updated my Volatility autoruns plugin to be compatible with Volatility 3 (long overdue!) Here's the goodies: github.com/tomchop/vola... #dfir #forensics #cybersecurity
github.com
GitHub - tomchop/volatility3-autoruns: Autoruns plugin for the Volatility3 framework
Autoruns plugin for the Volatility3 framework. Contribute to tomchop/volatility3-autoruns development by creating an account on GitHub.
1154
Reposted by tomchop
Maarten van Dantzig @maartenvdantzig.bsky.social · 19/06/2025
Using Timesketch for timeline analysis? We recently added a new feature: LLM summaries of up to 500 events in view. Example below uses Gemini Flash, but you can just as easily use a local Ollama model. Setup guide: timesketch.org/guides/user/...
064
Reposted by tomchop
Mark Russinovich @markrussinovich.bsky.social · 01/04/2025
49111
tomchop @tomchop.me · 02/04/2025
That's not that many cabs.
050
tomchop @tomchop.me · 29/01/2025
Well well well, how the turntables...
030
Reposted by tomchop
Johan Berggren @jbn.the4711.net · 07/01/2025
Great stuff from @tomchop.me! Memory analysis and Yara support in #OpenRelik #DFIR
053
tomchop @tomchop.me · 07/01/2025
I had a look at #OpenRelik last year and wrote a couple workers that might be useful: * github.com/tomchop/open...: Scan memory images using @volatilityfoundation.org plugins. Supports Yara rules * github.com/tomchop/open... - Run Yara rules on a directory. Supports third-party systems like #Yeti!
Demo of the Volatility 3 worker extracting files and plugin outputDemo of the Yara scanner worker showing matches for a dumb DarkComet rule
060
Reposted by tomchop
Johan Berggren @jbn.the4711.net · 12/12/2024
New #OpenRelik release. Task metrics (queue length, completion, failures etc) & new Prometheus exporter. Plus, a new task dashboard for deep dives into task performance. 📝 openrelik.org/changelog/ 🔗 discord.gg/hg652gktwX #DFIR
031
tomchop @tomchop.me · 12/12/2024
This is also the reason I never talk publicly about my dog, any favorite foods, or the season we were in < 3 months ago
020
tomchop @tomchop.me · 27/11/2024
Looks like shit just got real @swiftonsecurity.com
180
tomchop @tomchop.me · 26/11/2024
Probably the most riveting incident report I've read in a long time. I would've so much liked to be part of this investigation! Kudos to @volexity.com for going into so much detail on this novel network attack technique. www.volexity.com/blog/2024/11...
volexity.com
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...
1124
Reposted by tomchop
Hash Miser ✊🇺🇦 @hash-miser.bsky.social · 23/11/2024
This incredible investigation is worth the time you’ll spend reading it #dfir www.volexity.com/blog/2024/11...
volexity.com
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...
1116
Reposted by tomchop
danielroe @danielroe.dev · 23/11/2024
if you have a @github.com profile, can i ask you to update it with your @bsky.app handle? 🙏 👉 it enables some very cool integrations, like auto curated feeds and starter packs for contributors and tech
83995207
tomchop @tomchop.me · 19/11/2024
Shiiiiyet, I'm gonna try to not miss this edition! 🤞🏼🤞🏼🤞🏼
020
tomchop @tomchop.me · 18/11/2024
*cue pokémon battle song* "plaso I choose you!!"
031
tomchop @tomchop.me · 15/11/2024
Thinking of coming up with a Bluesky #DFIR Starter Pack with @the4711.org... who should we include?
260
Reposted by tomchop
Filippo Valsorda @filippo.abyssdomain.expert · 30/03/2024
I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission. The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system(). It's RCE, not auth bypass, and gated/unreplayable.
7686276
Reposted by tomchop
Martijn Grooten @martijngrooten.bsky.social · 28/11/2023
Today, we published this Field Guide to incident response for civil society and media, which I’ve been working on for the past year or so and which I am pretty excited about internews.org/resource/fie...
083
tomchop @tomchop.me · 14/11/2023
This has been years in the making, literally. @Sebdraven and I are happy to announce the release of #Yeti 2.0 (after we promised an EOM release at @hack_lu last month) Website: yeti-platform.io Release: github.com/yeti-platform/yeti mini-🧵👇🏻 #DFIR #infosec #CTI #cybersec
Screenshot of Yeti showing information on the Scattered Spider intrusion set.
183
tomchop @tomchop.me · 19/10/2023
The talk I have at @hack_lu about Yeti and our vision of the future of forensics intelligence is online! We're already getting lots of FRs, which we'll do our best to implement before our official release EOM. Hope I made @Sebdraven proud 🥹 #dfir #infosec
youtube.com
Hack.lu 2023: Yeti: Old Dog, New Tricks - Sébastien Larinier and Thomas Chopitea
054
tomchop @tomchop.me · 16/10/2023
I haven't had time to talk about it, but @sebdraven and I are giving a talk this week at #HackLu about some cool new changes coming to Yeti: pretalx.com/hack-lu-2023... It's going to be fun to talk about this project that has been on my todo list for 10+ years! 😅 #DFIR #infosec #CTI
Screenshot of a Github PR page showing 301 files changed, and 10k lines of code added and 14k of code deleted
020
tomchop @tomchop.me · 14/08/2023
My team just released dfiq.org, which is "a collection of Digital Forensics Investigative Questions and the approaches to answering them." The idea came from the will to organize investigative approaches to similar cases to increase consistency across response efforts. #dfir #infosec
dfiq.org
Home - DFIQ (Digital Forensics Investigative Questions)
141
tomchop @tomchop.me · 12/08/2023
How your email finds me.
020
tomchop @tomchop.me · 24/07/2023
VirusTotal announces Yara netloc, to extend Yara's capabilities to VT network sandbox results (domains, IPs, URLs), and not only file bytes. Looks promising! #infosec #cti blog.virustotal.com/2023/07/actiona…
130
Reposted by tomchop
Kim Zetter @kimzetter.bsky.social · 24/07/2023
For 25+ yrs police, military, intel agencies and critical infrastructure around the world relied on the TETRA radio standard to secure critical communications. But now Dutch researchers have examined secret algorithms used in TETRA and found something startling - an intentional backdoor, and more
wired.com
Code Kept Secret for Years Reveals Its Flaw—a Backdoor
A secret encryption cipher baked into radio systems used by critical infrastructure workers, police, and others around the world is finally seeing sunlight. Researchers say it isn’t pretty.
03320
Reposted by tomchop
Johan Berggren @jbn.the4711.net · 21/07/2023
Never take file paths for granted in digital forensics. New blog post by Joachim Metz: osdfir.blogspot.com/2023/07/whats-i…
osdfir.blogspot.com
What’s in a (file) path?
What’s in a (file) path? Background For the experienced reader this might seem a very basic topic, however file paths are things we easily...
031
Reposted by tomchop
Johan Berggren @jbn.the4711.net · 21/07/2023
Hey DFIR folks: we released a new version of Timesketch today. - OpenSearch queries in DFIQ - Preserve user defined filters - Support event list sorting - Rework comments - Analyzer results in the CLI - Sketch attributes in the CLI github.com/google/timesketch/releas…
github.com
Release 20230721 · google/timesketch
What's Changed fixes #2809 UI bug by @jkppr in #2810 Timeline and Scenarios fixes + small UI fixes by @berggren in #2808 Show selected event in context view by @berggren in #2811 Consitent forms a...
041
tomchop @tomchop.me · 20/07/2023
This is very exciting, and comes (in part) from direct pushback from the infosec community. Well done to everyone who was vocal about this!! #infosec www.microsoft.com/en-us/security/bl…
In response to the increasing frequency and evolution of nation-state cyberthreats, Microsoft is taking additional steps to protect our customers and increase the secure-by-default baseline of our cloud platforms. These steps are the result of close coordination with commercial and government customers, and with the Cybersecurity and Infrastructure Security Agency (CISA) about the types of security log data Microsoft provides to cloud customers for insight and analysis.
010
Reposted by tomchop
tlansec @tlansec.bsky.social · 12/07/2023
ICYMI, yesterday Microsoft reported on CVE-2023-36884 a vulnerability which myself and @r00tbsd.bsky.social reported earlier on this month. At the time we put together a nice infographic which explained our understanding of the execution chain that led to the installation of the malware involved.
0114
tomchop @tomchop.me · 11/07/2023
Two MSOffice #0days (exploited in the wild) were perched today, #CVE-2023-36874 and #CVE-2023-36884. Kudos to the folk at Google TAG and Volexity! #infosec msrc.microsoft.com/update-guide/vul… msrc.microsoft.com/update-guide/vul…
msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
061
Reposted by tomchop
evacide @evacide.bsky.social · 10/07/2023
Apple has rolled out a rapid response patch for iOS, iPadOS, and MacOS to fix a 0-day in WebKit that "may be actively exploited." Go patch your stuff. support.apple.com/en-us/HT213823
2107112
Reposted by tomchop
Ron Bowes @iagox86.bsky.social · 05/07/2023
We just published our detailed analysis of CVE-2023-2868, a shell command injection vulnerability in the #Barracuda Secure Email Gateway appliance. Big props to my co-worker Curtis Fielding for putting all this together! #infosec #vulnerability #exploit #PoC #rapid7
attackerkb.com
CVE-2023-2868 | AttackerKB
On May 30, 2023, Barracuda Networks published an advisory for CVE-2023-2868, an easily exploitable remote command injection vulnerability affecting several ver…
045
Reposted by tomchop
Caræsten 🇵🇸 @cara.city · 06/07/2023
WE WILL RELEASE A NEW TWITTER CLONE EVERY HOUR UNTIL OUR DEMANDS ARE MET
3455281416
tomchop @tomchop.me · 05/07/2023
(cyber) Incident response in a nutshell
010
tomchop @tomchop.me · 05/07/2023
I used to get a spike in Mastodon notifications whenever the brid site did something stupid. It seems to be happening here now, which gives me hope that this might be the next "permanent" home.
000
tomchop @tomchop.me · 04/07/2023
#DarknetDiaries is one of the best infosec podcasts out there. Def gonna give this a listen!
020
Reposted by tomchop
Kevin 🤖🕵️🍺 @stark4n6.bsky.social · 04/07/2023
Where are all the #DFIR folks at?!
663
tomchop @tomchop.me · 02/07/2023
OK, in case this helps anyone - I used skyfeed.app to build a feed that regroups infosec related keywords: bsky.app/profile/did:plc:ckxoq4m2ey… I have no idea how to make this more discoverable, but there it goes.
231
tomchop @tomchop.me · 02/07/2023
I gave a talk last week. My "whodis" slide didn't contain any social media links—because I just don't know what to say at this point. Current platforms are falling short (cesspool / desert / off-topic). I guess I'm taking the opportunity to consume less of it, which is not bad.
000
tomchop @tomchop.me · 12/06/2023
The #elbjazz festival in Hamburg was a nice way to disconnect from the socials… what have y’all been up to?
000
tomchop @tomchop.me · 06/06/2023
Oh, you work in detection engineering? Name all the log files.
120
tomchop @tomchop.me · 30/05/2023
Maybe this custom feed feature is gonna make it easier to discover content and cut down a bit on the noise. Where should I start?
000
Reposted by tomchop
Alexandria Ocasio-Cortez @aoc.bsky.social · 21/05/2023
One of the under-appreciated roles of bartenders is that it‘s literally their job to cultivate strong community. Regulars keep a place in business. The best bartenders curate a strong vibe that draws solid people in, who then form a community that gathers at your spot. Story below tracks 100%
760993
tomchop @tomchop.me · 20/05/2023
Shit, the yrr are after us
000
tomchop @tomchop.me · 19/05/2023
The mix of British / American accents in TotK is really sending me 🤣🫠
000
tomchop @tomchop.me · 19/05/2023
I must be doing *something* right. *follows back*
A picture of thedevil.bsky.social’s profile page indicating that they’re following me.
000
tomchop @tomchop.me · 18/05/2023
Very excited to see this coming!
010
tomchop @tomchop.me · 18/05/2023
The Great Asscape
010
tomchop @tomchop.me · 18/05/2023
This is where I skeet from.
Shady looking white van that says “äss bar”, which sounds rowdy but actually just means “food bar” in Swiss-German
010