Chris DiSalle's Avatar

Chris DiSalle

@chrisdfir.updatex64.zip

Technical Lead, Incident Response @ Cisco Talos DFIR, drums, and the simple things

272
Followers
333
Following
31
Posts
18.08.2023
Joined
Posts Following

Latest posts by Chris DiSalle @chrisdfir.updatex64.zip

Preview
Save the Votes — Citizen Preparedness Resource Find out exactly what documents you need to vote under the SAVE Act. State-by-state guides, birth certificate costs, voter ID rules, and election office links for all 50 states.

The SAVE Act could change how Americans register to vote. Find out what documents you need — state-by-state guide: www.savethevotes.org

#thesaveact #usa #democracy #voting #elections

02.03.2026 21:08 👍 0 🔁 1 💬 0 📌 0

Check out this blog post to learn more about our Incident Response team at Cisco Talos and how we can help your organization.

25.09.2025 00:34 👍 1 🔁 0 💬 0 📌 0
Video thumbnail

Experiencing a security incident? The Cisco Talos Incident Response team delivers fast, expert support to help you identify, contain and remediate threats when every second counts: www.youtube.com/watch?v=XFw0...

15.09.2025 16:14 👍 1 🔁 2 💬 1 📌 0
Quarterly Trends

Quarterly Trends

Watch out for threat actors who try to reel you in! 🎣 Phishing to achieve initial access soared this quarter, comprising 50% of all Talos IR incidents. Read our Quarterly Trends report for Q1 2025: http://cs.co/633252gat3

28.04.2025 14:04 👍 2 🔁 1 💬 0 📌 0

Hot off the press! Check out the Talos 2024 Year In Review report to learn about threat actor activities we encountered last year.

31.03.2025 14:13 👍 1 🔁 0 💬 0 📌 0
Post image

The post-SB set list.. GNX

10.02.2025 17:37 👍 1 🔁 0 💬 0 📌 0

Get the latest on what our team is seeing in the quarterly trends report!
#dfir #cybersecurity

30.01.2025 16:26 👍 4 🔁 0 💬 0 📌 0
Post image

Found one of my favorites in the used bin at the record store today.
Cat Stevens - Buddha and the Chocolate Box (1974)

22.12.2024 19:24 👍 8 🔁 0 💬 0 📌 0
Post image

New addition to the family today, Tater Tot the tortoise. 🐢
#liltottie #tortoise

08.12.2024 21:59 👍 1 🔁 0 💬 0 📌 0
Preview
My 2024 Wrapped - Get yours 2024 Wrapped

Smooth beats fuel the DFIR soul.

04.12.2024 17:51 👍 2 🔁 0 💬 0 📌 0
Preview
Hunting Linux Web Shells with Velociraptor Linux forensics can be tricky, especially when investigating subtle threats like web shells. Unlike Windows, which provides tools like the Master File Table ($MFT) for metadata-rich investigations, Li...

While there are some awesome methods to detect web shells with Yara, sometimes structured data can help solve the case. In this oversimplified example, I go over how you can use two artifacts with Velociraptor to help you find evil on your Linux server.

#dfir #blueteam #cybersecurity

01.12.2024 01:03 👍 10 🔁 6 💬 0 📌 0
Preview
Hunting Linux Web Shells with Velociraptor Linux forensics can be tricky, especially when investigating subtle threats like web shells. Unlike Windows, which provides tools like the Master File Table ($MFT) for metadata-rich investigations, Li...

While there are some awesome methods to detect web shells with Yara, sometimes structured data can help solve the case. In this oversimplified example, I go over how you can use two artifacts with Velociraptor to help you find evil on your Linux server.

#dfir #blueteam #cybersecurity

01.12.2024 01:03 👍 10 🔁 6 💬 0 📌 0

#Linux lacks a resource like the Windows Master File Table ($MFT). I've developed this #Velociraptor artifact to collect metadata from files and folders recursively in selected paths to create a bodyfile. This may bring an MFT-like feel to filesystem analysis. #dfir

github.com/chrisdfir/Ve...

12.11.2024 21:00 👍 31 🔁 14 💬 3 📌 0

Played The Incredible Machine a lot as a little kid. Same dev has a modern version on Steam. store.steampowered.com/app/241240/C...

#games #steam

26.11.2024 12:24 👍 0 🔁 0 💬 0 📌 0
Preview
Malicious QR Codes: How big of a problem is it, really? QR codes are disproportionately effective at bypassing most anti-spam filters. Talos discovered two effective methods for defanging malicious QR codes, a necessary step to make them safe for consumpti...

"According to Cisco Talos’ data, roughly 60% of all email containing a QR code is spam."

Malicious QR codes - how big of a problem is it really? Check out this 60 second recap. The full analysis is available at cs.co/6010tMy7s

#cybersecurity #qrcodes #talosthings

25.11.2024 16:10 👍 4 🔁 1 💬 0 📌 0
Preview
Russian Spies Jumped From One Network to Another Via Wi-Fi in an Unprecedented Hack In a first, Russia's APT28 hacking group appears to have remotely breached the Wi-Fi of an espionage target by hijacking a laptop in another building across the street.

Russian spies—likely Russia's GRU intelligence agency—used a new trick to hack a victim in Washington, DC: They remotely infected another network in a building across the street, hijacked a laptop there, then breached the target organization via its Wifi. www.wired.com/story/russia...

22.11.2024 12:06 👍 579 🔁 327 💬 12 📌 46
Post image

The 2025 Snort Calendar has arrived 🎉 This year’s theme is Video Games! To get your copy of the 2025 Snort Calendar, fill out our short survey here: cs.co/6018sNeKi Calendars will begin shipping in December 2024. U.S. shipping only, available while supplies last.
#cybersecurity #snort #talosthings

21.11.2024 22:12 👍 1 🔁 0 💬 0 📌 0
Preview
Bidirectional communication via polyrhythms and shuffles: Without Jon the beat must go on The Threat Source Newsletter is back! William Largent discusses bidirectional communication in the SOC, and highlights new Talos research including the discovery of PXA Stealers.

New edition of the Talos Threat Source Newsletter is out. Drums, leadership communications, and the intersection between. Good stuff although I wouldn't say Travis Barker is "easy".. those hands are fast.
#cybersecurity #threatintel #talosthings

21.11.2024 20:00 👍 1 🔁 0 💬 0 📌 0
Preview
a man in a suit and tie is sitting at a desk in front of a bookshelf . ALT: a man in a suit and tie is sitting at a desk in front of a bookshelf .

Those children will have the strongest passwords in all of the land.

21.11.2024 17:51 👍 2 🔁 0 💬 0 📌 0

Topics covered with the kids:
- What is cybersecurity? (high level)
- How does the Internet work?
- Underwater sea cable map
- How technology can be used for bad
- Stranger danger
- Password security hands-on
- Don't click random things

#cybersecurity #education #teachin

21.11.2024 14:07 👍 2 🔁 0 💬 2 📌 0

Speaking at the elementary school teach-in tomorrow. Building a small cyber army one class room at a time. It's the long game...
#cybersecurity

20.11.2024 22:00 👍 1 🔁 0 💬 0 📌 1
Preview
Windows Firewall dynamic keywords Learn about Windows Firewall dynamic keywords and how to configure it using Windows PowerShell.

🔥 You can now allow/block FQDNs using Windows Firewall
learn.microsoft.com/en-us/window...

20.11.2024 10:19 👍 22 🔁 9 💬 0 📌 0

Hey #infosec and #cybersecurity folks. I have a couple thinky questions I'd like to get perspective on:
- What makes a "good" cybersecurity partner in this day and age?
- What services or capabilities are table stakes for you?

always curious what you folks are seeing or would like to see

19.11.2024 01:57 👍 5 🔁 2 💬 1 📌 0

Random Monday thoughts…

As most of us have come here to find a safe haven from extremism, I feel it’s important not to use this sanctuary to intentionally sow further division.

Paraphrasing Ram Dass, “individualism leads to war, anger, insecurity, and fear.”

18.11.2024 18:57 👍 33 🔁 3 💬 1 📌 0

Securing a #web server? Consider using CSPBypass to check your HTTP headers for flaws in your Content Security Policies (CSP). Designed for ethical hacking, this is can be multi-purpose. Protect ya neck! #cybersecurity #blueteam #websecurity #http

github.com/renniepak/CS...

18.11.2024 17:17 👍 2 🔁 1 💬 0 📌 0
Preview
GitHub - stuhli/awesome-event-ids: Collection of Event ID ressources useful for Digital Forensics and Incident Response Collection of Event ID ressources useful for Digital Forensics and Incident Response - stuhli/awesome-event-ids

This git is full of resources for event logs/auditing. Covers everything from tool configs to audit cheatsheets to event attack chains and data samples. In #DFIR visibility is key. This is a solid resource for those responding to an incident or trying to prevent one. #grc

github.com/stuhli/aweso...

17.11.2024 22:27 👍 11 🔁 6 💬 0 📌 0

Beastie Boys - License To Ill

"Now here's a little story I've got to tell about three bad brothers you know so well"

17.11.2024 21:36 👍 1 🔁 0 💬 0 📌 0

Vulnerabilities from 2021 still haunt orgs. When I respond to attacks where these have been exploited I commonly hear "We were just about to upgrade that server next quarter." Yesterday's threats may still present risks today. Focus on asset and vulnerability management.. among other things.

17.11.2024 20:28 👍 0 🔁 0 💬 0 📌 0
Post image

Determining how a process interacted on a Linux host can be a hassle without the data laid out in front of you. The goal of the ProcFD output is to provide the analyst structured data for quick sorting, making the analysis of running processes more efficient. #linux #dfir

16.11.2024 18:24 👍 3 🔁 1 💬 0 📌 0
Post image

The response for this artifact has been overwhelmingly positive. I wanted to provide a screenshot of the output to illustrate the value to those who haven't had a chance to tinker. The ability to sort the filesystem output based on timestamps can be very helpful during an investigation.
#dfir #linux

16.11.2024 18:14 👍 4 🔁 1 💬 1 📌 0