Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

Unfurl v2025.02 released – SANS Internet Storm Center

Unfurl v2025.02 released – SANS Internet Storm Center

I’ve been a big fan of Ryan Benson’s unfurl[1] tool since he released it a little over 5 years ago. Unfurl is a tool that can parse/decode URLs including things like embedded timestamps and IP addresses. It can be run in gui form via a web browser or as a command-line tool (my preference). Well, last week, Ryan released an update to v2025.02[2,3] of unfurl and added the ability to decode BlueSky URLs (among other bugfixes). I’ve also updated my docker container[4] to run the command-line version of unfurl as well.

References:

1. https://dfir.blog/introducing-unfurl/

2. https://dfir.blog/unfurl-parses-obfuscated-ip-addresses/

3. https://github.com/obsidianforensics/unfurl

4. https://hub.docker.com/repository/docker/clausing/dfir-unfurl/general

—————

Jim Clausing, GIAC GSE #26

jclausing –at– isc [dot] sans (dot) edu

Source link