π New blog post at skyblue.team/posts/unsafe...
At Airbus CERT, we worked on the sudo CVE-2025-32463 to create detection and hunting rules.
Based on the underlying vulnerability, we developed an eBPF based tool to monitor unsafe chroot behavior regarding NSS reloading.
github.com/airbus-cert/...
Ever dreamt of parsing the $I3O INDX files from a 80GB drive in under 10 seconds? β±οΈ
Dream no more β¨ Courtesy of @eeriedusk.bsky.social and #RustLang π¦π¦π¦
#DFIR #Forensics
New release of minusone (v0.4.0) with a lot of new deobfuscation pattern : github.com/airbus-cert/...
π¨Online version : minusone.skyblue.team π¨
#powershell #deobfuscation