home.social

#dfir — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dfir, aggregated by home.social.

  1. 2026-10-05 RDP IOCs - 330 scans
    Thread with top 3 features in each category and links to the full dataset

    Top IPs:
    82.85.225.167 - 36
    50.250.207.222 - 33
    109.49.210.201 - 27

    Top ASNs:
    AS8075 - 45
    AS8612 - 36
    AS7922 - 33

    Top Accounts:
    142.93.8.59 - 213
    hello - 27
    Administr - 18

    Top ISPs:
    Microsoft Corporation - 45
    Tiscali Italia SpA - 36
    Comcast Cable Communications, LLC - 33

    Top Clients:
    Unknown - 330

    Top Software:
    Unknown - 330

    Top Keyboards:
    Unknown - 330

    Top IP Classification:
    hosting - 177
    Unknown - 150
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

  2. 2026-10-05 RDP IOCs - 220 scans
    Thread with top 3 features in each category and links to the full dataset

    Top IPs:
    82.85.225.167 - 24
    50.250.207.222 - 22
    109.49.210.201 - 18

    Top ASNs:
    AS8075 - 30
    AS8612 - 24
    AS7922 - 22

    Top Accounts:
    142.93.8.59 - 142
    hello - 18
    Administr - 12

    Top ISPs:
    Microsoft Corporation - 30
    Tiscali Italia SpA - 24
    Comcast Cable Communications, LLC - 22

    Top Clients:
    Unknown - 220

    Top Software:
    Unknown - 220

    Top Keyboards:
    Unknown - 220

    Top IP Classification:
    hosting - 118
    Unknown - 100
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

  3. 2026-10-05 RDP IOCs - 110 scans
    Thread with top 3 features in each category and links to the full dataset

    Top IPs:
    82.85.225.167 - 12
    50.250.207.222 - 11
    109.49.210.201 - 9

    Top ASNs:
    AS8075 - 15
    AS8612 - 12
    AS7922 - 11

    Top Accounts:
    142.93.8.59 - 71
    hello - 9
    Administr - 6

    Top ISPs:
    Microsoft Corporation - 15
    Tiscali Italia SpA - 12
    Comcast Cable Communications, LLC - 11

    Top Clients:
    Unknown - 110

    Top Software:
    Unknown - 110

    Top Keyboards:
    Unknown - 110

    Top IP Classification:
    hosting - 59
    Unknown - 50
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

  4. ----------------

    🛠️ Tool
    ===================

    Velociraptor Skills is a public GitHub repository (ig-labs/velociraptor-skills) providing reusable Codex skills and DFIR tooling for Velociraptor operations. It covers setup, collection, hunting, and host analysis workflows.

    Key Features

    The repository includes eight distinct skills:
    • prep-dfir-tools - prepares DFIR tooling environment
    • velociraptor-artifact-selection - artifact selection guidance
    • velociraptor-collection - evidence collection workflows
    • velociraptor-engagement-setup - engagement configuration
    • velociraptor-host-analysis - host-level forensic analysis
    • velociraptor-hunting - hunt-based detection operations
    • velociraptor-live-api-client - live API interaction
    • velociraptor-mapped-client - mapped evidence handling

    A shared ./vraptor runtime supports all skills, along with bounded custom-agent templates and installation helpers.

    Technical Implementation

    The default setup connects to an existing live Velociraptor server and uses the OpenAI API for analysis. Prerequisites include Python 3.11+, Git, a server administrator's API-client YAML, and an OpenAI API key. Credentials are stored outside the checkout directory.

    Multiple server connections are supported within a single installation. Each server gets its own reference name and API-client YAML path. The --server-profile flag selects the connection per command.

    For live-remote mode, the setup command vraptor setup start --mode live-remote --id ir1234 --server-profile "<SERVER REFERENCE>" handles server maintenance or hunt review without requiring a hostname or visible client.

    Codex and Claude Code Integration

    Skills are linked separately via ./utils/link-codex-skills.sh for Codex and ./utils/link-claude-skills.sh for Claude Code. The linking creates symlinks, so the checkout must remain available. Existing symlinks are updated; real files are preserved and reported as conflicts.

    Limitations

    Remote API access requires no local Velociraptor binary, SSH connection, or Codex login. However, offline checks do not prove live authentication. Explicit connection and AI tests are documented in the installation guide. The repository includes a public release review covering import scope, sanitization, and validation results.

    The --no-configure flag skips the setup wizard during upgrades, and --no-path handles dependency-only installation or CI environments.

    🔹 tool #velociraptor #dfir #codex #incident_response

    🔗 Source: github.com/ig-labs/velocirapto

Share on Mastodon

Enter the server where you have an account.