Tootfinder

Opt-in global Mastodon full text search. Join the index!

No exact results. Similar results found.
@adulau@infosec.exchange
2025-03-06 15:24:36

There is a new #Fediverse bot that facilitates web forensic analysis of websites.
You can submit a domain for crawling by messaging @…, and it will respond with the analysis results.

An output result of a phishing webpage on LookyLoo.circl.lu
@adulau@infosec.exchange
2025-03-04 09:27:11

Don't forget! In vulnerability-lookup, you can quickly identify sighted vulnerabilities that are not yet published or are scheduled for publication soon (highlighted in yellow in the screenshot).
This example is interesting, a pre-publication on GitHub Gist before the official CVE release.

Sighting for non published CVEs.
@adulau@infosec.exchange
2025-02-22 08:36:43

We imported the data from Black Basta Ransomware group leak into AIL and there are many interesting aspects.
The federation network of Matrix servers (see the screenshot) used to communicated among the affiliates/group(s).
Activities in the chat room, especially the daily activity view in AIL. Guessing the location and timezone of groups or affiliates is an endless source of information.
They rely on many open-source and SaaS tools, including Googl…

Lists of Matrix server references involved in the Black Basta ransomware group leak. The data has been imported to AIL.
Activities in the chat room, especially the daily activity view in AIL.
Many interesting correlations with cryptocurrencies, IP addresses, CVE numbers, and chat username relationships (who talks to whom and when).
@adulau@infosec.exchange
2025-03-06 15:13:06

@… www.whitehouse.gov

@adulau@infosec.exchange
2025-02-25 13:02:26

Super happy to see the open source sysdiagnose joining the hackathon.lu held in Luxembourg on April 8th and 9th, 2025.
sysdiagnose is an open-source framework developed to facilitate the analysis of the Apple sysdiagnose files and especially the one generated on mobile devices (iOS / iPadOS). In the light of targeted attacks against journalists, activist, representatives from the civil society and politicians, it empowered incident response team to review device behaviour and ensure th…