Johan Berggren's Avatar

Johan Berggren

@jbn.the4711.net

Digital Forensics and Incident Response @Google :: I write open source tools :: Creator of OpenRelik and Timesketch https://openrelik.org/ https://timesketch.org/ #DFIR • Posts are my own • he/him

306
Followers
199
Following
33
Posts
12.06.2023
Joined
Posts Following

Latest posts by Johan Berggren @jbn.the4711.net

New version of OpenRelik (the #DFIR workflow engine) is out. New workflow UI, support for chords (task groups with callback), MCP server and much much more. Give it a try!

Take a look at the new page for workers showcase, both official and community contributed: openrelik.org/workers/

03.03.2026 15:51 👍 4 🔁 5 💬 0 📌 0

Hey folks at #39c3, I'm around until tomorrow afternoon. If anyone wants to chat about OpenRelik or #DFIR in general. Let me know.

30.12.2025 00:59 👍 3 🔁 0 💬 0 📌 0
Post image Post image Post image Post image

Achievement unlocked: Presenting at BSides Munich! ✅✨
On Nov 17th I presented my talk ”From Hours to Minutes: Automating Incident Response Triage with Open-Source Tools”. Thanks to the @bsidesmunich.bsky.social organizers, volunteers and attendees for an amazing conference!

23.11.2025 10:38 👍 6 🔁 2 💬 0 📌 0

Meatballs ftw 🇸🇪

10.11.2025 00:23 👍 2 🔁 0 💬 0 📌 0

Great stuff from Maarten and the Timesketch team!

19.06.2025 18:55 👍 2 🔁 0 💬 0 📌 0
DetectionForge DetectionForge - A comprehensive detection engineering environment for crafting, validating, and testing LimaCharlie detection rules

🚀 Just launched: DetectionForge — a purpose-built platform for crafting, testing & validating @limacharlie.io detection rules.

Perform detection unit tests & multi-org backtesting + import/export IaC

🔗 Try it: detectionforge.ddi.sh
💻 GitHub: github.com/Digital-Defe... #detectionengineering #secops

19.06.2025 01:14 👍 12 🔁 6 💬 0 📌 2

Great summary of a great paper. Worth a read if you are building LLM agents systems.

13.06.2025 13:45 👍 1 🔁 0 💬 0 📌 0

Great stuff from Eric and Whitney.

05.06.2025 23:20 👍 6 🔁 1 💬 0 📌 0
Preview
Security Fest 2025 - Day 2 YouTube video by Security Fest

Here are the slides/resources from our #SecurityFest talk on "Modernizing Incident Response Using Techniques that Scale"

Talk: www.youtube.com/live/Znl7TBF...

05.06.2025 17:57 👍 14 🔁 8 💬 2 📌 2

Yeah, looking forward to building together :)

05.06.2025 23:17 👍 2 🔁 0 💬 0 📌 0

Thank you for taking the time to visit! It was really great to finally meet in person.

05.06.2025 23:16 👍 2 🔁 0 💬 0 📌 0

Some excellent work by @craiggidney.bsky.social that reduces the number of qubits (in a quantum computer) required to break RSA by 20-fold. If you don’t have a migration plan to safe algorithms, now is the time to start one!

23.05.2025 16:22 👍 11 🔁 6 💬 0 📌 0

tested #openrelik, #hayabusa, #timesketch and #splunk4dfir using #thedfirreport recent analyst case. was a lot fun! will definitely use those tools more now 🚀

30.04.2025 15:19 👍 2 🔁 1 💬 0 📌 0

Hey #DFIR people! New #OpenRelik release just dropped. Some cool new features and a bunch of bug fixes.

26.02.2025 16:32 👍 5 🔁 2 💬 0 📌 0
Preview
unfurl Extract and Visualized Data from URLs

A new Unfurl release is here! v2025.02 adds:

🌐 Parsing encoded/obfuscated IP addresses
🦋 Resolving #Bluesky handles to their identifiers (DIDs) and looking up their creation timestamps
🐛 Bug fixes & better bulk parsing

Blog: dfir.blog/unfurl-parse...
Code: github.com/obsidianfore...

#DFIR #OSINT

19.02.2025 14:46 👍 8 🔁 7 💬 0 📌 0

We should meet up in person.

08.02.2025 12:49 👍 1 🔁 0 💬 1 📌 0
Preview
GitHub - Yamato-Security/hayabusa: Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs. Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs. - Yamato-Security/hayabusa

Hayabusa - A sigma-based threat hunting and fast forensics 🔎 timeline generator for Windows event logs.
It can easily be integrated with other hunting & DFIR tools such as Velociraptor & OpenRelik.

Check it out 🔥🔥:
github.com/Yamato-Secur...

#threathunting #DFIR #sigma #cybersecurity #infosec

12.01.2025 23:43 👍 13 🔁 6 💬 1 📌 1

This is absolute insanity.

02.02.2025 15:28 👍 73 🔁 16 💬 2 📌 3
Evolving GitHub Issues (public preview) GitHub just shipped the largest set of changes to GitHub Issues I can remember in a few years. As an Issues power-user this is directly relevant to me. The big …

Much welcomed updates to GitHub Issues.

simonwillison.net/2025/Jan/16/...

19.01.2025 10:06 👍 0 🔁 0 💬 0 📌 0
Preview
Living in the future, by the numbers Instead of making the traditional New Year predictions, let’s talk instead about the beautiful technological future we live in: the one that exists right now but we don’t always notice.

It's easy to lose sight of the fact that, from a tech perspective, we're absolutely living in the future. Our CEO and co-founder @apenwarr.ca looks at just how powerful our modern machines are — and what that means for all of us

08.01.2025 18:46 👍 47 🔁 18 💬 0 📌 4
Preview
Japan's wooden satellite leaves International Space Station Carefully crafted wooden box, LignoSat, is on its own

Wooden satellite.. amazing. And built without nails or glue. Oh Japan, never change ♥️

www.theregister.com/2025/01/08/j...

08.01.2025 18:40 👍 1 🔁 0 💬 0 📌 0

Great stuff from @tomchop.me! Memory analysis and Yara support in #OpenRelik

#DFIR

07.01.2025 18:07 👍 5 🔁 3 💬 0 📌 0

Great summary of last year of databases.

01.01.2025 20:52 👍 1 🔁 0 💬 0 📌 0

    The GPT-4 barrier was comprehensively broken
    Some of those GPT-4 models run on my laptop
    LLM prices crashed, thanks to competition and increased efficiency
    Multimodal vision is common, audio and video are starting to emerge
    Voice and live camera mode are science fiction come to life
    Prompt driven app generation is a commodity already
    Universal access to the best models lasted for just a few short months
    “Agents” still haven’t really happened yet
    Evals really matter
    Apple Intelligence is bad, Apple’s MLX library is excellent
    The rise of inference-scaling “reasoning” models
    Was the best currently available LLM trained in China for less than $6m?
    The environmental impact got better
    The environmental impact got much, much worse
    The year of slop
    Synthetic training data works great
    LLMs somehow got even harder to use
    Knowledge is incredibly unevenly distributed
    LLMs need better criticism
    Everything tagged “llms” on my blog in 2024

The GPT-4 barrier was comprehensively broken Some of those GPT-4 models run on my laptop LLM prices crashed, thanks to competition and increased efficiency Multimodal vision is common, audio and video are starting to emerge Voice and live camera mode are science fiction come to life Prompt driven app generation is a commodity already Universal access to the best models lasted for just a few short months “Agents” still haven’t really happened yet Evals really matter Apple Intelligence is bad, Apple’s MLX library is excellent The rise of inference-scaling “reasoning” models Was the best currently available LLM trained in China for less than $6m? The environmental impact got better The environmental impact got much, much worse The year of slop Synthetic training data works great LLMs somehow got even harder to use Knowledge is incredibly unevenly distributed LLMs need better criticism Everything tagged “llms” on my blog in 2024

Here's my end-of-year review of things we learned out about LLMs in 2024 - we learned a LOT of things simonwillison.net/2024/Dec/31/...

Table of contents:

31.12.2024 18:10 👍 653 🔁 148 💬 28 📌 47
Preview
Snöstorm i Jämtland – då surfade Årebor i Kallsjön Vanligtvis brukar nysnö locka ut människor i backar och skidspår så här års. Men i veckan var det annat som lockade för ett gäng Årebor. Istället för att ta till vara på vinterns första ordentliga snö...

In Sweden you have to take every opportunity to surf, regardless of the weather and season.. this one is for @halvarflake.bsky.social

(In Swedish, but the picture really tells the whole story :)
www.svt.se/nyheter/loka...

22.12.2024 12:01 👍 9 🔁 2 💬 1 📌 0
YouTube Share your videos with friends, family, and the world

Home Assistant is an amazing OSS project. I'll excited to build on the new Voice device. I will get mine in a few days, and I can finally talk to my house! Build any automation I can imagen. Custom wake word (ok computer 🖖). LLM function calling anyone...

www.youtube.com/live/ZgoaoTp...

21.12.2024 19:57 👍 2 🔁 0 💬 0 📌 0
Post image

New #OpenRelik release. Task metrics (queue length, completion, failures etc) & new Prometheus exporter. Plus, a new task dashboard for deep dives into task performance.

📝 openrelik.org/changelog/
🔗 discord.gg/hg652gktwX

#DFIR

12.12.2024 11:29 👍 3 🔁 1 💬 0 📌 0
Video thumbnail

Within software architecture, few people shaped the industry as much as @gradybooch.bsky.social. Safe to say he's a true legend.

In today's The Pragmatic Engineer Podcast episode, he shares fascinating stories, insights, observations.

Watch here: newsletter.pragmaticengineer.com/p/software-a...

04.12.2024 19:50 👍 451 🔁 61 💬 14 📌 9
Preview
Blog: The Great Google Password Heist: 15 years of hacking passwords to test our security (and build team culture!) The Leaving Tradition in Google's security team, which could be described as a type of small-scale offensive security exercise, is a great (and fun) example of team culture. Curious? See this blog pos...

When I moved back to Sweden a few years back my team snagged my password in this great tradition. The hack involved ketchup and I was very proud of everyone involved.

bughunters.google.com/blog/6355265...

04.12.2024 21:47 👍 7 🔁 1 💬 0 📌 1

🚀 New OpenRelik release

Role-based access control, folder sharing, database improvements, optimisations for file listings, chunked file uploads, bug fixes and refactoring efforts to improve stability.

📝 https://openrelik.org/changelog/
🔗 https://discord.gg/hg652gktwX

#DFIR

27.11.2024 15:41 👍 4 🔁 3 💬 0 📌 0