Opens profile photo
Follow
Félix Aimé
@felixaime
Threat Intelligence stakhanovite at . Burn TAs' codes & infrastructures during breakfast đŸ„â˜• . (Former GReAT & )
France, Poitiers Joined February 2009

FĂ©lix Aimé’s Tweets

Topics to follow

Sign up to get Tweets about the Topics you follow in your Home timeline.

Carousel

Blah blah blah. Still waiting (real) samples, no FUD for just marketing purpose. The published papers are completely empty regarding real and actionable intel.
Quote Tweet
PIPEDREAM should best be thought of as an ICS attack framework. It has numerous modules and can be modified easily to target different industries/equipment/environments. It is a very flexible framework that takes advantage of native functionality in these environments.
Show this thread
2
1
7
Show this thread
The fact that 12+ years after the last real improvement to BinDiff, people still use it, and it is still good, is among the proudest achievements of my life. That, and everybody please thank the heck out of for keeping BinDiff alive.
Quote Tweet
Even researchers who reversed then patch just assumed MS knew what it was talking about when it said SMB was involved. twitter.com/OphirHarpaz/st

4
18
163
📱CERTFR-2022-CTI-001 - Mise Ă  jour de la publication d’élĂ©ments de connaissance sur la menace cyber liĂ©e aux tensions internationales actuelles : publication de 3 signatures de dĂ©tection Sigma pour ProxyLogon et ProxyShell. Elles sont Ă  votre disposition !
1
68
100
Show this thread
Looks like #NOBELIUM. They used a variant Trello downloader + unhooking of NTDLL quite recently and it matches our YARA on that.
Quote Tweet
Interesting docx that imitates the document of the Israeli embassy. Contains a js that unpacks the dll. doc > bfc36f03b9752ca9d49ffb4d259129ad dll > E031C9984F65A9060EC1E70FBB84746B @InQuest @IdoNaor1 @James_inthe_box #ThreatHunting #maldoc
Show this thread
Image
Image
Image
1
16
56
Show this thread
BG.
Quote Tweet
Dernier jour Ă  l'@ANSSI_FR en tant chef de la #CTI. Une extraordinaire aventure dans une administration d'exception qui a su donner sa chance au petit analyste que j'Ă©tais ! Je quitte l'ANSSI fier, mais aussi triste. J'aime cette Ă©quipe que je laisse !
Show this thread
1
2
Quand tu te lĂšves le matin et que t'entends sur France Inter qu'un expert (sic.) a parlĂ© de risque de "dissĂ©mination d'armes cyber" en UkraineđŸ‡ș🇩, t'as juste envie de vomir ton petit dĂšj.
2
2
18
Show this thread
Breaking... breaking... euh...
Quote Tweet
#BREAKING #ESETresearch discovered an ongoing #MustangPanda campaign using new #Korplug variant deployed with elaborate custom loaders. Every stage of the deployment process uses anti-analysis techniques and control-flow obfuscation 1/6 @barberousse_bin welivesecurity.com/2022/03/23/mus
Show this thread
4
Replying to
Cyber security is the only industry in the world where 75% of the industry just writes policy and doesn't have any technical clue. It's like a mechanics garage where 75% of them write the procedure on how to change a tyre but only 25% know how.
3
12
57