Skip to content

Instantly share code, notes, and snippets.

View sroberts's full-sized avatar
:shipit:

Scott J. Roberts sroberts

:shipit:
View GitHub Profile
@sroberts
sroberts / gentlementogentlemengifts.md
Created June 13, 2013 16:21
Gifts men give men...
  • 10: Pocket Knife
  • 13: Wallet
  • 16: Watch
  • 18: ?
  • 21: Flask
for ($fqdn, $ipv4) in $rows {
[ inet:dns:a = ( $fqdn, $ipv4 ) +#ioc +#adversary.nsogroup +#infrastructure ]
}
@sroberts
sroberts / freegeoip-geolookup.py
Last active February 10, 2022 13:22
A basic Maltego script to geolocate IPv4Addresses using Freegeoip.net.
#!/usr/bin/env python
# encoding: utf-8
"""
freegeoip-geolookup.py
Created by Scott Roberts.
Copyright (c) 2015. All rights reserved.
A basic Maltego script to geolocate IPv4Addresses using Freegeoip.net.
@sroberts
sroberts / cti-and-ramen.md
Last active September 22, 2021 23:21
My outline for my Cyber Threat Intelligence & Ramen: A Recipe for Both presentation

Slides

Homemade Ramen & Threat Intel

A recipe for both

  • Scott J Roberts
    • Instructor: SANS FOR578 Cyber Threat Intelligence
    • Author: Intelligence Driven Incident Response
  • Metaphor Warning!!!

Keybase proof

I hereby claim:

  • I am sroberts on github.
  • I am sroberts (https://keybase.io/sroberts) on keybase.
  • I have a public key ASCkaqzoKIRjKiuUTpAnkRKZtNSZ2G-7D7VMh5w8QlVi2wo

To claim this, I am signing this object:

Here is an overview of my past (and sometimes upcoming) speaking opportunities.

2017

2016

Keybase proof

I hereby claim:

  • I am sroberts on github.
  • I am sroberts (https://keybase.io/sroberts) on keybase.
  • I have a public key ASBN2JRFuuB8vzXzq06VSCrmaXjHU9q0LR4K6aM6UUujkgo

To claim this, I am signing this object:

# Set up your Transform object. This is the basis for returning results.
trx = MaltegoTransform()