Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Thomas Strömberg

@thomrstrom@triangletoot.party
mastodon 4.7.3
  • Open on triangletoot.party

KD4UHP - based in Carrboro, NC

#unix #infosec #bikes #carrboro #motorcycles #photography #hamradio

founder & principle eng @ isotope¹³, ex-Director of Security @ Chainguard & Xoogler

875 Followers
316 Following
44 Posts
Joined November 03, 2022
Pronouns:
He/Him
Home:
https://choosehappy.dev/
My all-consuming startup:
https://isotope13.io/
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 2mo ago
How much disk space does it take to reliably track & scan all the important open-source software releases published throughout the year? About 120TB. Thanks to #FreeBSD, #ZFS, #WesternDigital, and #Ampere for being awesome. :)
9
0
3
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 3mo ago

After being locked away for 10+ years in the Cloud; it's so refreshing, and frustrating to deal with all of the little things; like filesystems, database replication and locks, replacing fans and NICs, debugging OOMs, and crashing daemons on #FreeBSD, #OmniOS, and #Linux;

I feel like everything moves a little more slowly and sustainably this way; but most of all - I really missed getting lost in the details.

triangletoot.party

Triangle Toot Party!

29
5
6
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 3w ago
I have listened to an unhealthy amount of #SkinnyPuppy this week. What have you been listening to? I could use a musical reset and welcome any suggestions.
1
3
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 5mo ago
Boosted by @oxy@social.bsdlab.au
After being hosed by #btrfs on #linux 7.0.1, the #atomdrift postgresql master database is on #OmniOS & #ZFS It's good to be back, even if I'm rusty in Solaris-based environments.
19
1
9
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago

Epic; thanks for the laugh guys!

8
1
4
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 5mo ago
Replying to
@zackwhittaker@mastodon.social My favorite part is that several school districts migrated from PowerSchool to Canvas because the former* was hacked.
11
1
2
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 8mo ago
Replying to
@teunvink@mstdn.social I've used UNIX command lines for passwords similarly in the past; I mean, who's going to suspect it when I accidentally type "sudo ls -lad /etc" into a Discord window?
20
0
2
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 3mo ago
Things are not looking so good for the Linux box that serves the #atomdrift API for serving, foraging, and generally managing sample files. Definitely a shame to be 7000km away from the power button for the next 3 weeks, as it doesn't respond to soft reboot requests. Kinda wish I'd gotten around to enabling remote ZFS snapshots before I left. 🤦
3
3
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago

One of my favorite features with #atomdrift's approach to supply-chain attack decomposition is the ability to quickly find other samples using the same techniques by clicking on the #malecule - our custom hash based on a program's behavioral profile. This NPM was uploaded just a few minutes ago, but matches many attacks we've seen throughout the last month.

triangletoot.party

Triangle Toot Party!

5
0
3
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 5mo ago
I just realized I'm now sitting here with 3TB of #malware on my computer - what could possibly go wrong?
6
1
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 5mo ago

https://codeberg.org/atomdrift/stng - my wild strings(1) replacement for security engineers has a shiny new release (v1.2.0):

* New arm64 stack-XOR decoder for macOS malware
* Fewer false positives for IPv4 constants
* 66% faster XOR scanning

Codeberg.org

stng

strings(1) for malware analysts - stronger, better, faster

7
0
2
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 5mo ago

cleave v1.2.0 is now available! cleave is the successor to malcontent - decomposing a program into a set of MBC/ATT&CK-aligned features useful for security engineers and ML pipelines alike.

The screenshot is how cleave sees an ELF #malware sample that was dropped just yesterday. Using both AST and automated reverse engineering [rizin], cleave executes 50,000+ rules across 75 file formats.

Project: https://codeberg.org/atomdrift/cleave

triangletoot.party
5
0
4
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago

The best part of being a solo-founder is the ability to take guilt-free thinking rides. It gave me the clarity on what I'd like to ship next for #atomdrift - JSON trait context, improved lab interface, and a --second-opinion option for (local but non-deterministic) LLM assistance. Coming to #litmus soon!

triangletoot.party

Triangle Toot Party!

3
0
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago
Replying to
Well fuck. I still can't get it to boot into OF, so I pulled the drives out to see if I could plug it into a Linux box. This PowerMac G5 may set the record for the most internal storage of a machine from its generation ever: 9TB across 4 SATA drives. I think I'm gonna need a bigger boat.
4
1
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 2mo ago
I've been trying to stay quiet about it over vacation, but I'm damned impressed with how #atomdrift is showing up in the malware detection charts. Nothing comes close to it for #supplychainsecurity. Have a question? Leave a comment.
1
0
1
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago
Replying to
For the [citation needed] folks: https://www.ntsb.gov/safety/safety-studies/Documents/SR1801.pdf TL;DR - due to the added cognitive overhead, balance, and reaction time needed to safely operate a motorcycle: >0.02 BAC bad, >0.05 dead In other words, it takes the average person at least 1h45m after consuming a double IPA where the risk is reduced far enough to safely ride again.
ntsb.gov
2
1
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 2mo ago
Replying to
@AAKL@infosec.exchange @SocketSecurity@fosstodon.org Clever! Kudos to Socket for this discovery. I would have missed it otherwise.
1
0
1
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 2mo ago
Replying to
@wdormann@infosec.exchange Not to be an apologist - but that's super weird and unlike anything I've seen on an Android device. Who makes it? Just like with Linux distros, which dialer version an Android phone ships or how it's themed is a matter of taste, and this phone appears to have unusual taste.
1
1
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 6mo ago
Replying to
The concept is simple: decompose a program into atoms, identify the unique mal-ecule that makes up the program, and use a fast local ML to keep the false-positive rates low. Treat binaries and source code as first-class citizens, with automated reverse-engineering of both sets. We still have a long way to go, but if you want to check out where we are today (including a web portal for analyzing samples), see https://atomdrift.org/
atomdrift.org

Atomdrift - probably the world's best malware detection stack. - The Atomdrift Project

Open-source, local-first supply-chain attack detection across binaries, packages, scripts, and source — Apache 2.0.

4
0
1
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago
Replying to
@FritzAdalis@infosec.exchange You can see in that screenshot - 70% disk savings for malware - as there are a lot of byte duplicates within strains & families; less for my goodware dataset, because it's almost entirely .tar.gz/.xz archives already.
2
0
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago
Replying to
I am failing to get this thing to boot into OpenFirmware without an Apple keyboard. Thankfully they aren't as proprietary as NeXT keyboards - this really should just work!
2
4
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 3mo ago
Replying to
@oxy@social.bsdlab.au Damn, I'm actually impressed too - Max still has it! #Graspop (and events like it) are one of the things I miss most about moving back to the US. There's nothing like it here, IMHO.
1
0
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 3mo ago
Replying to
@cwebber@social.coop This same concern is why I've spent the last 5 months fighting fire with fire: https://atomdrift.org/ - open-source AI detection models & tools. I tried to keep up as a human writing YARA rules [see "malcontent"], but the amount of malware slop we're now seeing every day just makes it untenable :(
atomdrift.org

Atomdrift - probably the world's best malware detection stack. - The Atomdrift Project

Open-source, local-first supply-chain attack detection across binaries, packages, scripts, and source — Apache 2.0.

1
0
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 7mo ago
Replying to on triangletoot.party
This is also my first time publishing to codeberg, so I have literally no idea what I'm doing.
3
2
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 6mo ago
Replying to
I've poured hundreds of hours (and thousands of dollars' worth of GPUs, RAM, and storage) into Atomdrift because it's well past time the open-source community had a solution. While ClamAV served us well for the past 23 years, its design always assumed that malware samples were static, well-known, and in binary form. That's not the case in 2026.
2
1
2
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago
Replying to
If we dial the clock back to 2016, it turns out that Ubuntu 16.04 has an ISO that supposedly works with OpenFirmware's USB boot: https://cdimage.ubuntu.com/ubuntu/releases/16.04/release/
cdimage.ubuntu.com

Ubuntu 16.04.7 LTS (Xenial Xerus)

CD images for Ubuntu 16.04.7 LTS (Xenial Xerus)

1
5
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 12mo ago
Replying to
@ryanc@infosec.exchange Thanks for sharing - both the repo and your amazing execution of this classic over SSH :)
2
1
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 47mo ago

Our latest #opensource drop: https://github.com/chainguard-dev/acls-in-yaml

As part of #SOC2 #compliance, we've been using this to run monthly #audit reviews of our ACLs across SaaS platforms: #GCP, #Slack, #Vercel, etc.

acls-in-yaml dumps #ACLs from each platform into a consistent and neutral #YAML format, which makes it easy to visualize change over time.

We use this by committing the result into a #Github repo and getting the PR reviewed by the admins for each system.

PS: ACL change alerts are also awesome!

triangletoot.party

Triangle Toot Party!

12
2
7
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 45mo ago

New blog post outlining some of the #infosec #detection techniques we use with #osquery, specifically against the most interesting new macOS malware of the past year:

https://unfinished.bike/behavioral-detection-of-macos-malware-using-osquery

triangletoot.party

Triangle Toot Party!

11
2
7
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 12mo ago
Replying to
@ryanc@infosec.exchange I'm impressed by the quality. What'd you use for the conversion?
1
1
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 47mo ago
Replying to
@tylerauerbeck I initially read this as "tools" -- and I felt seen in a way that I'd never experienced before.
2
0
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago

Most malicious #npm packages steal; #express-timer just deletes your source tree a minute after you install it — and its author fumbled their own online-banking password into the very same tarball; just wow.

It's trivially detectable using existing open-source software too: https://atomdrift.org/discoveries/2026/06/express-timer-self-destruct-wiper/

triangletoot.party
0
0
1
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 45mo ago
Replying to
@ariadne@social.treehouse.systems I am! I appreciate it's minimalism and focus on the writing process rather than the distracting machinery underneath.
0
0
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 2mo ago
Replying to
@synlogic4242@social.vivaldi.net @david_chisnall@infosec.exchange I used OmniGraffle for a good decade or so - such a wonderful tool! OmniGroup was one of the very first vendors to put out professional tools for macOS, so I stuck with them for a very long time. At Google I even created some pipelines that automated metadata->.graffle generation via Applescript :) Nowadays I use Excalidraw for hand-drawn, or begrudgingly Graphviz for automated graphs. Excalidraw is the only thing that has felt as fun an freeing as OG once did.
0
1
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 7mo ago
Replying to
@troed@swecyb.com Holler if you have any thoughts or recommendations for improving it. There are a ton of edge cases where the automatic key decryption doesn't work yet, but I can only fix those if I knew about them ;) Most of what I use this for is ELF/machO binaries, so it's probably stronger there at the moment.
0
0
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago
Replying to
Holding Alt on a PC keyboard got me into a boot menu, but my shiny USB stick doesn't show up there. CTRL-Z from the boot menu doesn't seem to do anything other than change to a refresh icon.
0
3
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 7mo ago
Replying to
@matt@proud.social that implies I've even implemented CI :)
0
0
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago
Replying to
@WideEyedCurious@mstdn.social Yup! It's a core feature of the series. I haven't had a firewire cable in probably 15 years though :( That would be a clutch way to just mount & copy the data over otherwise!
0
1
0
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 3mo ago

With #atomdrift - we're detecting a dozen new supply-chain attacks every day; on-par with the commercial vendors. Most are boring, but some are brazen - this attempt at a CDN-distributed #cryptojacker is the latter: https://atomdrift.org/discoveries/2026/06/v018-axios-cdntest-c-is-for-cookie/

triangletoot.party

Triangle Toot Party!

0
0
1
0
Open post
Thomas Strömberg @thomrstrom@triangletoot.party
· 4mo ago

New day, new silly malware samples found - this time it's PyPI's turn: https://atomdrift.org/discoveries/2026/06/spadata-roblox-cookie-stickup/

atomdrift.org
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:09:46 UTC