Sign in

tomchop

@tomchop.me
850 followers 381 following 132 posts

Cybersecurity nerd; #DFIR @ Google by day; FOSS, threat intel and malware analysis by night. Investigator, coder, terrible sense of humor. yeti-platform.io and more (github.com/tomchop) views are my own • he/him • tomchop.me

PostsRepliesMedia
tomchop @tomchop.me · 25/01/2026
Also, I dropped out of bsky before most of infosec twitter joined, so my feed is quite empty (or flooded by US politics...); are there any lists of cybersec nerds I'm missing?
110
tomchop @tomchop.me · 25/01/2026
I rarely post here, but when I do... I just updated my Volatility autoruns plugin to be compatible with Volatility 3 (long overdue!) Here's the goodies: github.com/tomchop/vola... #dfir #forensics #cybersecurity
github.com
GitHub - tomchop/volatility3-autoruns: Autoruns plugin for the Volatility3 framework
Autoruns plugin for the Volatility3 framework. Contribute to tomchop/volatility3-autoruns development by creating an account on GitHub.
1154
Reposted by tomchop
Maarten van Dantzig @maartenvdantzig.bsky.social · 19/06/2025
Using Timesketch for timeline analysis? We recently added a new feature: LLM summaries of up to 500 events in view. Example below uses Gemini Flash, but you can just as easily use a local Ollama model. Setup guide: timesketch.org/guides/user/...
064
Reposted by tomchop
Mark Russinovich @markrussinovich.bsky.social · 01/04/2025
49111
tomchop @tomchop.me · 02/04/2025
That's not that many cabs.
050
tomchop @tomchop.me · 29/01/2025
Well well well, how the turntables...
030
Reposted by tomchop
Johan Berggren @jbn.the4711.net · 07/01/2025
Great stuff from @tomchop.me! Memory analysis and Yara support in #OpenRelik #DFIR
053
tomchop @tomchop.me · 07/01/2025
I had a look at #OpenRelik last year and wrote a couple workers that might be useful: * github.com/tomchop/open...: Scan memory images using @volatilityfoundation.org plugins. Supports Yara rules * github.com/tomchop/open... - Run Yara rules on a directory. Supports third-party systems like #Yeti!
Demo of the Volatility 3 worker extracting files and plugin outputDemo of the Yara scanner worker showing matches for a dumb DarkComet rule
060
Reposted by tomchop
Johan Berggren @jbn.the4711.net · 12/12/2024
New #OpenRelik release. Task metrics (queue length, completion, failures etc) & new Prometheus exporter. Plus, a new task dashboard for deep dives into task performance. 📝 openrelik.org/changelog/ 🔗 discord.gg/hg652gktwX #DFIR
031
tomchop @tomchop.me · 12/12/2024
This is also the reason I never talk publicly about my dog, any favorite foods, or the season we were in < 3 months ago
020
tomchop @tomchop.me · 04/12/2024
I made this one, which tracks a bunch of infosec-related keywords (and blocks noisy accounts): bsky.app/profile/did:...
000
tomchop @tomchop.me · 29/11/2024
Looks like the kind of manual you could find in The Last of Us that would allow you to upgrade your rifle
010
tomchop @tomchop.me · 27/11/2024
Travel budgets are tight yo
000
tomchop @tomchop.me · 27/11/2024
Looks like shit just got real @swiftonsecurity.com
180
tomchop @tomchop.me · 26/11/2024
Probably the most riveting incident report I've read in a long time. I would've so much liked to be part of this investigation! Kudos to @volexity.com for going into so much detail on this novel network attack technique. www.volexity.com/blog/2024/11...
volexity.com
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...
1124
Reposted by tomchop
Hash Miser ✊🇺🇦 @hash-miser.bsky.social · 23/11/2024
This incredible investigation is worth the time you’ll spend reading it #dfir www.volexity.com/blog/2024/11...
volexity.com
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...
1116
Reposted by tomchop
daniel wraith @danielroe.dev · 23/11/2024
if you have a @github.com profile, can i ask you to update it with your @bsky.app handle? 🙏 👉 it enables some very cool integrations, like auto curated feeds and starter packs for contributors and tech
83995207
tomchop @tomchop.me · 23/11/2024
“i know bsky is an echo chamber because those echo chamber posts keep coming back around and i know what an echo is”
000
tomchop @tomchop.me · 21/11/2024
There's probably less content than there was on twitter in 2012, but this already feels much nicer and relevant than what X is right now.
020
tomchop @tomchop.me · 19/11/2024
Shiiiiyet, I'm gonna try to not miss this edition! 🤞🏼🤞🏼🤞🏼
020
tomchop @tomchop.me · 19/11/2024
Amazing, thanks! skyfeed.app offers a (less polished, more hacky) similar interface but also allows you to create custom feeds
020
tomchop @tomchop.me · 18/11/2024
*cue pokémon battle song* "plaso I choose you!!"
031
tomchop @tomchop.me · 17/11/2024
Thanks, this is useful! I also started a feed a long time ago with more generic infosec keywords: bsky.app/profile/did:...
bsky.app
020
tomchop @tomchop.me · 15/11/2024
Thinking of coming up with a Bluesky #DFIR Starter Pack with @the4711.org... who should we include?
260
Reposted by tomchop
Filippo Valsorda @filippo.abyssdomain.expert · 30/03/2024
I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission. The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system(). It's RCE, not auth bypass, and gated/unreplayable.
7686276
Reposted by tomchop
Martijn Grooten @martijngrooten.bsky.social · 28/11/2023
Today, we published this Field Guide to incident response for civil society and media, which I’ve been working on for the past year or so and which I am pretty excited about internews.org/resource/fie...
083
tomchop @tomchop.me · 14/11/2023
Yes, for sure. Otherwise does the project even exist?? I tried briefly playing a bit with Dall-E but didn't get any satisfying results :(
110
tomchop @tomchop.me · 14/11/2023
We are looking forward to integrating formats such as dfiq.org, shipping tighter integrations with DFIR platform tools like timesketch.org, turbinia.plumbing, and misp-project.org!
000
tomchop @tomchop.me · 14/11/2023
Please feel free to use (and tell us when you do! we love hearing about people's use-cases), file lots of bugs, and feel free to contribute: guides, documentation, even cool screenshots, everything is welcome.
100
tomchop @tomchop.me · 14/11/2023
The changes in the codebase have been massive (remember, it's only 2 people working on this): 480 commits to the API server. 139 commits to the frontend SPA.
100
tomchop @tomchop.me · 14/11/2023
This version marks the start of a focus shift away from classic CTI and towards a platform for DFIR teams wishing to integrate CTI in their pipelines for incident response, threat hunting, and detection, and to be able to collate "forensics intelligence" to share with other teams
110
tomchop @tomchop.me · 14/11/2023
This has been years in the making, literally. @Sebdraven and I are happy to announce the release of #Yeti 2.0 (after we promised an EOM release at @hack_lu last month) Website: yeti-platform.io Release: github.com/yeti-platform/yeti mini-🧵👇🏻 #DFIR #infosec #CTI #cybersec
Screenshot of Yeti showing information on the Scattered Spider intrusion set.
183
tomchop @tomchop.me · 19/10/2023
The talk I have at @hack_lu about Yeti and our vision of the future of forensics intelligence is online! We're already getting lots of FRs, which we'll do our best to implement before our official release EOM. Hope I made @Sebdraven proud 🥹 #dfir #infosec
youtube.com
Hack.lu 2023: Yeti: Old Dog, New Tricks - Sébastien Larinier and Thomas Chopitea
054
tomchop @tomchop.me · 16/10/2023
I haven't had time to talk about it, but @sebdraven and I are giving a talk this week at #HackLu about some cool new changes coming to Yeti: pretalx.com/hack-lu-2023... It's going to be fun to talk about this project that has been on my todo list for 10+ years! 😅 #DFIR #infosec #CTI
Screenshot of a Github PR page showing 301 files changed, and 10k lines of code added and 14k of code deleted
020
tomchop @tomchop.me · 01/10/2023
Mais quel grognon celui-là !
000
tomchop @tomchop.me · 30/08/2023
Is that what PHP stands for?
010
tomchop @tomchop.me · 26/08/2023
You've been here way too long for me not to have realized 🤨
000
tomchop @tomchop.me · 20/08/2023
Creating new ones you mean? I use skyfeed.app, it’s pretty straightforward
skyfeed.app
SkyFeed
Real-time client for Bluesky
000
tomchop @tomchop.me · 19/08/2023
Welcome everyone! I've been trying to come up with a feed with some infosec community content: bsky.app/profile/tomchop.bsky.socia…
010
tomchop @tomchop.me · 14/08/2023
We're hoping that this will also be a good home for common forensic approaches, and lower the bar for newcomers to the field. :)
020
tomchop @tomchop.me · 14/08/2023
My team just released dfiq.org, which is "a collection of Digital Forensics Investigative Questions and the approaches to answering them." The idea came from the will to organize investigative approaches to similar cases to increase consistency across response efforts. #dfir #infosec
dfiq.org
Home - DFIQ (Digital Forensics Investigative Questions)
141
tomchop @tomchop.me · 12/08/2023
How your email finds me.
020
tomchop @tomchop.me · 07/08/2023
What is this mastodon interface?? looks so much better than the default website!
100
tomchop @tomchop.me · 24/07/2023
FTR, this is the list that I'm using (with hashtags) forensics dfir incidentresponse cti threatintel infosec cybersec malware appsec reverseengineer redteam blueteam devsecops 0day exploit cve (+ fancy regex) hacker hacking offsec backdoor atp{1,3}
220
tomchop @tomchop.me · 24/07/2023
What keywords are you using? I also built one here: bsky.app/profile/did:plc:ckxoq4m2ey…. Should we combine both?
111
tomchop @tomchop.me · 24/07/2023
VirusTotal announces Yara netloc, to extend Yara's capabilities to VT network sandbox results (domains, IPs, URLs), and not only file bytes. Looks promising! #infosec #cti blog.virustotal.com/2023/07/actiona…
130
Reposted by tomchop
Kim Zetter @kimzetter.bsky.social · 24/07/2023
For 25+ yrs police, military, intel agencies and critical infrastructure around the world relied on the TETRA radio standard to secure critical communications. But now Dutch researchers have examined secret algorithms used in TETRA and found something startling - an intentional backdoor, and more
wired.com
Code Kept Secret for Years Reveals Its Flaw—a Backdoor
A secret encryption cipher baked into radio systems used by critical infrastructure workers, police, and others around the world is finally seeing sunlight. Researchers say it isn’t pretty.
03320
Reposted by tomchop
Johan Berggren @jbn.the4711.net · 21/07/2023
Never take file paths for granted in digital forensics. New blog post by Joachim Metz: osdfir.blogspot.com/2023/07/whats-i…
osdfir.blogspot.com
What’s in a (file) path?
What’s in a (file) path? Background For the experienced reader this might seem a very basic topic, however file paths are things we easily...
031
Reposted by tomchop
Johan Berggren @jbn.the4711.net · 21/07/2023
Hey DFIR folks: we released a new version of Timesketch today. - OpenSearch queries in DFIQ - Preserve user defined filters - Support event list sorting - Rework comments - Analyzer results in the CLI - Sketch attributes in the CLI github.com/google/timesketch/releas…
github.com
Release 20230721 · google/timesketch
What's Changed fixes #2809 UI bug by @jkppr in #2810 Timeline and Scenarios fixes + small UI fixes by @berggren in #2808 Show selected event in context view by @berggren in #2811 Consitent forms a...
041
tomchop @tomchop.me · 20/07/2023
This is very exciting, and comes (in part) from direct pushback from the infosec community. Well done to everyone who was vocal about this!! #infosec www.microsoft.com/en-us/security/bl…
In response to the increasing frequency and evolution of nation-state cyberthreats, Microsoft is taking additional steps to protect our customers and increase the secure-by-default baseline of our cloud platforms. These steps are the result of close coordination with commercial and government customers, and with the Cybersecurity and Infrastructure Security Agency (CISA) about the types of security log data Microsoft provides to cloud customers for insight and analysis.
010