Jim Clausing
@jclausing.bsky.social
250 followers 220 following 14 posts
pilot, cyclist, Unix/Linux, DFIR
Posts Media Videos Starter Packs
jclausing.bsky.social
2 more days to get the early-bird discount for one of my all-time favorite conferences, #SANS #DFIRCON in Miami in Nov. There are a bunch of hands-on workshops on Sun, 16 Nov, lots of evening events during the week #FOR577 my last in 2025. Reg here: www.sans.org/cyber-securi...
jclausing.bsky.social
Linux touches every part of our networks. Our routers, switches, and firewalls likely run some flavor of Linux or Unix. Join me in London in July for the newly updated #SANS #FOR577 where we'll learn how to investigate attacks on Linux systems. www.sans.org/cyber-securi...
Reposted by Jim Clausing
sansisc.bsky.social
Tool update: sigs.py - added check mode https://isc.sans.edu/diary/31706
ISC Logo
Reposted by Jim Clausing
sansisc.bsky.social
SANS Stormcast Monday Feb 24th: sigs.py update; Google Introdusing Quantum Safe Sigs; MSFT Update Win 11 issues; LTE/5G Vulns;
https://isc.sans.edu/podcastdetail/9336
image of sans internet stormcenter logo with stormcast flair
Reposted by Jim Clausing
sansisc.bsky.social
Unfurl v2025.02 released https://isc.sans.edu/diary/31716
ISC Logo
jclausing.bsky.social
Join me in one of my favorite places for the updated FOR577. Now, with more BTRFS, more rootkits, and more Linux attacks. #FOR577 #SANSSecWest
Reposted by Jim Clausing
sansisc.bsky.social
New tool: immutable.py https://isc.sans.edu/diary/31598
ISC Logo
jclausing.bsky.social
I just posted a Handler's Diary, I've released a python script to find Linux files with the immutable bit set. #FOR577 @sansisc.bsky.social #SANSDFIR isc.sans.edu/diary/New+to...
New tool: immutable.py - SANS Internet Storm Center
New tool: immutable.py, Author: Jim Clausing
isc.sans.edu
jclausing.bsky.social
Is that even a question? Of course, he does
Reposted by Jim Clausing
abrignoni.com
And Google.
#DigitalForensics #MobileForensics #DFIR #Code
Reposted by Jim Clausing
danielroe.dev
if you have a @github.com profile, can i ask you to update it with your @bsky.app handle? 🙏

👉 it enables some very cool integrations, like auto curated feeds and starter packs for contributors and tech
jclausing.bsky.social
Congrats to Tyler and Zachary for an outstanding job in the day 6 challenge
Reposted by Jim Clausing
hindsig.ht
Since I'm trying out #Bluesky, I figured I should add in support for it in Unfurl!

The v2024.11.20 release has some minor updates, but the biggest feature is the ability to parse a timestamp from Bluesky post IDs (or atproto TIDs).

Example: dfir.blog/unfurl/?url=...

Give it a try at unfurl.link!
Reposted by Jim Clausing
cedricpernet.bsky.social
Awesome research ! - The Nearest Neighbor Attack: How A Russian #APT Weaponized Nearby Wi-Fi Networks for Covert Access - @volexity.com - www.volexity.com/blog/2024/11... #cyberespionage
jclausing.bsky.social
Time to find the newest Lethal Forensicators #SANS #FOR610
Reposted by Jim Clausing
oddthisday.bsky.social
Daughter tells me she heard today that if you wear a band T-shirt (especially as a young woman) and a man says to you “name five of their songs”, the correct response is “name five women who trust you”, so I pass this on in case any of you need it
jclausing.bsky.social
So, I was considering the cost of #12DaysOfChrostmas gifts from #truelove and was wondering do I need to include 12 pear trees or can she just use the 2 we already have?
jclausing.bsky.social
Another great class and 2 more brand new lethal forensicators! Congratulations Takuya and Ryo! #SANS #FOR610 #malware
jclausing.bsky.social
I dropped a quick little tool today after some discussion on class today of the /proc filesystem and network connections #dfir #for577 isc.sans.edu/diary/New%20...
New tool: le-hex-to-ip.py - SANS Internet Storm Center
New tool: le-hex-to-ip.py, Author: Jim Clausing
isc.sans.edu
jclausing.bsky.social
Interested in learning #malware analysis Down Under? Join me as we bring SANS #FOR610 back to Syney in September
jclausing.bsky.social
And here they are, congrats cow, Howard, and TerryTubby
jclausing.bsky.social
Time to crown some new REM Masters in Singapore. Who will they be?