Cybersecurity blog posts, writeups, papers, and tools
github.com/0xor0ne/awes...
#infosec
Cybersecurity blog posts, writeups, papers, and tools
github.com/0xor0ne/awes...
#infosec
The best way to learn something is to practice it - we all know this.
That's why labbing is important for network engineers for cert study.
If you are learning or curious about Path MTU discovery, our latest Ostinato guide shows how to lab this feature.
1/2
That guest SSID you set up for your neighbors may not be as secure as you think
arstechnica.com/security/202...
Do CISA analysts type out IOC domains by hand?
netresec.com?b=26233f4
GRU unit 26165 domains: accesscan[.]org glize[.]com Youβve verified them, right? Youβve verified them, right?
21 of the world's best intelligence and security agencies cannot be wrong... right?
netresec.com?b=26233f4
Our latest guide goes into details!
ostinato.org/guides/...
2/2
Erik Hjelmvik will run a hands-on network forensic workshop at the upcoming Digital Forensics Research Conference in Sweden. Participants will get the chance to analyze:
πͺ Packets carved from memory dumps
π§
Unencrypted Tor traffic
dfrws.org/dfrws-eu-202...
Decoding #njRAT C2 traffic to extract screenshots, commands and transferred files
netresec.com?b=262adb9
NetworkMiner has been around for a long time, and it shows β in a good way. It feels opinionated. It feels calm. It feels like a tool made by people whoβve already had a few bad days in incident response. No hype. No buzzwords. Just packets telling you what happened.
Thank you for those kind words! π
www.linkedin.com/pulse/issue-...
The early bird discount, for our live online network forensics class, expires by the end of this week. Sign up if youβd like to analyze PCAP files together with Erik Hjelmvik (creator of NetworkMiner and PolarProxy).
netresec.com?b=25A2e4f
π¬ Video: Decoding malware C2 with #CyberChef
netresec.com?b=261f535
Ostinato generated traffic not reaching the intended destination?
Our latest KB article helps you troubleshoot this!
1/2
Curated list of cybersecurity research, RE material, exploitation write-ups, and tools.
github.com/0xor0ne/awes...
#infosec
NetworkMiner 3.1 Released!
π More usernames, passwords and hostnames from #PCAP
π» Improved user interface
πΎ Better details from malware C2 traffic
netresec.com?b=25C4039
Studying for a CCNA/CCIE? Or some other networking cert? Ostinato for Labbing (GNS3, EVE-NG, CML and CLAB) has a Black Friday Sale! Level up your Labs TODAY! #LabEveryday
The Black Friday Sale is now LIVE!
Iβm looking for a junior dev (or intern) to work with me on Ostinato - my network traffic generator / packet crafter product.
C++, Qt, Python, networking - lots of hands-on learning.
Please share if you know someone who might be a good fitπ
Call for Papers: SharkFestβ26 US
Nashville, TN | July 18β23, 2026
Share your packet analysis, troubleshooting, or Wireshark insights with the community! Submit your talk today:
sharkfest.wireshark.org/sfus/
#SharkFest #Wireshark #PacketAnalysis #NetworkEngineering #NashvilleTech #sf26us
Monitoring for too many old indicators not only costs money, it can even inhibit detection of real intrusions.
π Include "last seen" date when publishing IOCs
β Prune old IOCs
π Prioritize long lived IOCs over short lived ones
netresec.com?b=25Be9dd
Some recent job postings requiring Ostinato skills!
Want to generate some synthetic SRv6 traffic?
Details and instructions for each labbing platform are here -
ostinato.org/blog/vi...
(2/2)
I am awarded a gold medal by the Royal Swedish Academy of Sciences for my work on #curl
daniel.haxx.se/blog/2025/10...
After years of steady evolution, Ostinato 2.0 is finally here.
A big milestone for the project - modernized, faster, and built for whatβs next.
Gh0stKCP is a C2 transport protocol based on KCP. It has been used by malware families such as #PseudoManuscrypt and #ValleyRAT.
netresec.com?b=259a5af