Alexandre Dulaunoy
adulau@infosec.exchange
<p>Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff.</p><p>The other side is at <span class="h-card" translate="no"><a href="https://paperbay.org/@a" class="u-url mention">@<span>a</span></a></span> (photography, art and free software at large)</p><p><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/opensource" class="mention hashtag" rel="tag">#<span>opensource</span></a> <a href="https://infosec.exchange/tags/threatintelligence" class="mention hashtag" rel="tag">#<span>threatintelligence</span></a> <a href="https://infosec.exchange/tags/fedi22" class="mention hashtag" rel="tag">#<span>fedi22</span></a> <a href="https://infosec.exchange/tags/threatintel" c
Posts
-
View post
I just released ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage from reverse-DNS PTR hostnames. It is intentionally heuristic and multi-label. PTR naming is operator-controlled and is not authoritative evidence of how an address is actually used. The output therefore includes a confidence score, the text that matched, and the rule IDs that produced each label. To summarize, the library is trying to guess usage (and a bit location) of an IP address bas...
-
View post
I spent many hours in vulnogram today and to be honest. I'm glad that a colleague started to work on a replacement called vulniverse. Still early beta but it's promising. #opensource #vulniverse #cybersecurity #cve #gcve :github: work in progress https://github.com/vulnerability-lookup/vulniverse
-
View post
CVSS and WRONG models are just the same. #cvss #infosec
-
View post
GCVE BCP-07, the Known Exploited Vulnerability (KEV) Assertion Format, has been updated to version 2.2. A key addition is the formalisation of the GCVE KEV Directory, a simple machine-readable directory allowing organisations to announce where their KEV catalogues and exploitation assertions are published. We particularly encourage software and hardware vendors to publish their own KEV catalogues. Vendors are often in the best position to confirm exploitation affecting their products, and publi...
-
View post
GCVE Workshop - 22 September 2026 (14:00-18:00), Luxembourg Before The Vulnopticon Conference We are pleased to announce a GCVE workshop on 22 September 2026, from 14:00 to 18:00, hosted at the CIRCL/LHC offices in Luxembourg, just before the VulnOpticon conference. The workshop is free and open to everyone, but registration is required. 🔗 https://gcve.eu/2026/09/01/gcve-workshop-22-september-2026-1400-1800-luxembourg-before-the-vulnopticon-conference/ #cve #gcve #luxembourg #cybersecurity #...
-
View post
Proposed changes in the CVE program CNA document "Update 4.2.6 from SHOULD to MUST: "CNAs MUST assign different CVE IDs to separate Vulnerabilities"" 🔗 https://github.com/CVEProject/cve-documents/issues/47#issuecomment-5515748024 #cve #vulnerabilitymanagement #cybersecurity
-
View post
ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage and location from reverse-DNS PTR hostnames. Version 0.3 released including new rules and CSV tool. #ptrclassify #infosec #cybersecurity 🔗 https://github.com/adulau/ptrclassify
-
View post
Doing some statistics on the persistence of information published on security and threat intelligence blogs. A surprising number of the domains in the list below are NXDOMAIN nowadays. Don't assume that security information and threat intelligence will remain accessible over time, especially when it is hosted by large private entities. Some are simply mistyped, while others reflect DNS changes over time that eventually left the original URLs broken. Stability and persistence of informatio...
-
View post
From a research paper to running open-source code in just a few days. We (with @cedric@fosstodon.org) have been experimenting in Vulnerability-Lookup with the concept of Local Exploit Hazard, based on the recent research paper “Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency” by Stephen Shaffer and Laura Cristiana Voicu. The idea addresses an important question in vulnerability management: Not simply “How dangerous is this vulnera...
-
View post
Pretty cool idea from @nyanbinary@infosec.exchange - a bot to analyse fucked up references from the CVE records. @fuckeduprefs_bot@infosec.exchange Maybe we could imagine an archive bot at the same time to ensure that the references don't get lost. Just like archive.org or similar. Maybe something for @gcve@social.circl.lu to look into. #cve #vulnerability #gcve
-
View post
A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster in the MISP Galaxy repository, and shared MISP Galaxy metadata. Graph rendering is performed by Pivotick. Source code: https://github.com/adulau/threat-actor-explorer/ Online (in-browser): https://foo.be/threat-actor-explorer/misp-threat-actor-explorer.html Discussions and feedback: https://discourse.ossbase.org/t/playing-with-a-threat-actor-explorer-b...
-
View post
Have you seen any evidence of the famous « collect encrypt data and decrypt later » in incident response ? Until now, I haven’t. #pqc #crypto #cryptography #dfir
-
View post
A new version of the BCP-11 "Community Contribution Fragments for Existing CVE Records" proposal has been published. https://discourse.ossbase.org/t/gcve-bcp-11-community-proposed-updates-to-existing-cve-records/1110/8#p-1495-gcve-bcp-11-community-contribution-fragments-for-existing-cve-records-1 This new version is a major refactoring of the originally proposed format. Feel free to comment, update or propose changes. An implementation will follow when the BCP-11 reach a more stab...
-
View post
When I added the threat-actor @misp@misp-community.org galaxy type on Mar 4, 2016, I didn’t expect that, years later, vendors would still invent new names for already known threat actors, avoid using UUIDs, reuse similar names for different actors, and create confusing names by mixing tools or software used by the actors. That’s why we continue the tedious work of maintaining a proper threat-actor database, with relationships to other galaxies such as MITRE ATT&CK, Malpedia, and more. Afte...
-
View post
The Radio Image Framing Protocol (RIFP) 1.0 is an experimental, extensible standard for sending images over low-rate radio links. The default rifp-cpfsk-4800 profile uses binary continuous-phase FSK and can be deployed around 433.92 MHz where local regulation permits it. RIFP itself is not tied to 433 MHz or to FSK and can be used in any frequency bands. I'm still exploring various low-cost options for a device that can receive and display images on an e-ink screen in emergency areas or si...
-
View post
Pivotick is an open-source network graph library to facilitate pivoting. Version 1.4.0 has been released and also includes a security fix. Release notes https://github.com/Pivotick/Pivotick/releases/tag/v1.4.0 Documentation https://pivotick.github.io/Pivotick/ Vulnerability fixed in 1.4.0 https://vulnerability.circl.lu/vuln/gcve-1-2026-20151 Gallery https://pivotick.github.io/Pivotick/gallery.html #opensource #infovis #graph #networkgraph #visual
-
View post
So finally Kimi-k3 is not really open-source https://huggingface.co/moonshotai/Kimi-K3/blob/main/LICENSE I'm a bit disappointed. #kimi #ai #opensource
-
View post
The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System initiative. The lab allows the GCVE community to explore promising concepts without immediately imposing the stability, compatibility, and operational requirements expected from the core GCVE infrastructure. Open to comments/ideas. #gcve #cve #cybersecurity https://discourse.ossbase.org/t/gcve-lab-proposal/1117 https://gcve.eu @gcve@social.circl.lu @gcv...
-
View post
Wireshark for the web (webasm) Open, dissect and analyse .pcap / .pcapng capture files entirely in your web browser. Online - local in your browser https://stricaud.github.io/wpcapng/ Sourc code - https://github.com/stricaud/wpcapng #nids #pcap #networkanalysis #wireshark
-
View post
I don’t like playing the futurologist, but after seeing AI companies warn EU institutions about the supposed risks of open-weight models, I suspect some are lobbying to regain control over genuine open source and open-weight AI. Don’t fall into the trap: the greater danger lies in opaque, proprietary models, not open-source ones. #opensource #ai #cybersecurity
-
View post
@neal@social.gompa.me All is documented as BCP including IDs allocation https://gcve.eu/bcp/ If you have any question feel free. @bernardq@ehlo.exim.org
-
View post
We are exploring some ambitious ideas around reducing external dependencies and relying more on our own libraries across MISP and related tooling. Over the past year, we have been working on a replacement network graph library for the new MISP interface and things are getting really interesting. Pivotick is already used in around ten open-source tools, including CTI Transmute, AIL Project, and Rulezet. It has also recently been integrated into the new MISP UI, OverMind. The library is, of course...
-
View post
We started rulezet project after identifying a clear gap in open source tooling for detection rules management: the ability to operate synchronised instances while still allowing each organisation to maintain its own autonomous rule repository. Rulezet addresses this need as an open source platform for managing, sharing, and synchronising detection rules. Each organisation can run its own standalone instance and decide independently which other instances, communities, or repositories it wants t...
-
View post
Looking at the current distributed.net statistics on the current RC5-72 brute force, this actually puts some key-size discussions into perspective. #cryptography #crypto #symmetric #cybersecurity
-
View post
We just released cve-search v6.0.1 - it is a security and maintenance release. All users are strongly encouraged to upgrade. Thanks to @oh2fih@infosec.exchange for the remediation fix and release support. Thanks to George Chen for the report about the security vulnerability. #cve #gcve #cybersecurity 🔗 https://github.com/cve-search/cve-search/releases/tag/v6.0.1
-
View post
« Once an organisation accepts that the difficult software will be bought elsewhere, internal teams slowly lose the habit of building. Procurement becomes a substitute for strategy. Legal review becomes a substitute for leadership. Risk management becomes a substitute for execution. » https://foo.be/2026/06/Sovereignty-Is-Engineered-Not-Procured.html #sovereignty #europe #opensource
-
View post
An idea for next year workshop @passthesaltcon@infosec.exchange - open source license for developers? It could be a nice opportunity because it seems to be a never ending learning process. #opensource
-
View post
@aristot73@infosec.exchange I'm not into this kind of sport. But here, it might be different ;-) Should we expect the harbor of Antwerp to be bombed soon. @bert_hubert@mastodon.nl
-
View post
Yesterday, in our very warm office, an interesting discussion emerged: there was no dedicated taxonomy for evaluating Cyber Threat Intelligence (CTI) in MISP. So, we created one called: cti-evaluation 🔗 https://www.misp-project.org/taxonomies.html#_cti_evaluation My colleagues Théo Geffe and Christian Studer then took it one step further by implementing it in CTI-transmute. From discussion to a first implementation and tests in less than 48 hours, not too bad! Feedback on the taxonomy is m...
-
View post
I still don’t understand standards committees composed of people who have never implemented software. They design a standard without ever confronting the realities of implementation, then wonder why no one adopts it. #openstandard #standard