- 10: Pocket Knife
- 13: Wallet
- 16: Watch
- 18: ?
- 21: Flask
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
for ($fqdn, $ipv4) in $rows { | |
[ inet:dns:a = ( $fqdn, $ipv4 ) +#ioc +#adversary.nsogroup +#infrastructure ] | |
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#!/usr/bin/env python | |
# encoding: utf-8 | |
""" | |
freegeoip-geolookup.py | |
Created by Scott Roberts. | |
Copyright (c) 2015. All rights reserved. | |
A basic Maltego script to geolocate IPv4Addresses using Freegeoip.net. |
I hereby claim:
- I am sroberts on github.
- I am sroberts (https://keybase.io/sroberts) on keybase.
- I have a public key ASCkaqzoKIRjKiuUTpAnkRKZtNSZ2G-7D7VMh5w8QlVi2wo
To claim this, I am signing this object:
Here is an overview of my past (and sometimes upcoming) speaking opportunities.
- Mind The Sec: TBD
- SANS DFIR Summit: Japanese Manufacturing, Killer Robots, & Effective Incident Handling
- SANS Leadership Summit: Crisis Communication for Incident Response
- ArchC0n: Chasing Shiny Objects: InfoSec budget decisions in a hype driven world
- SANS DFIR Summit: Responding @ Scale - osquery for Mass Incident Detection & Response (Slides)
I hereby claim:
- I am sroberts on github.
- I am sroberts (https://keybase.io/sroberts) on keybase.
- I have a public key ASBN2JRFuuB8vzXzq06VSCrmaXjHU9q0LR4K6aM6UUujkgo
To claim this, I am signing this object:
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# Set up your Transform object. This is the basis for returning results. | |
trx = MaltegoTransform() |
NewerOlder