解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 WEEK 50 – 2022 - SOFTWARE UPDATES

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。「Buy me a coffee」からカンパをすると喜ばれます。

SOFTWARE UPDATES

Brian Maloney

OneDriveExplorer Public Notifications Fork 9 Star 100 Code Issues 0 Pull requests 0 Actions Projects 0 Security Insights More Code Issues Pull requests Actions Projects Security Insights Releases v2022.12.09 v2022.12.09 Latest Latest Compare Choose a tag to compare View all tags Beercow released this 09 Dec 18:35 v2022.12.09 e390fb6 Change Log Fixed commandline Fixed error when using -l with -f ODL saves to --csv path (default is .) GUI ODL saves to Auto Save Path Assets 3 1 person reacted 👍 1 g...

Costas K

Latest Latest Compare Choose a tag to compare View all tags kacos2000 released this 07 Dec 18:34 v.0.0.69.0 92a4750 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. [Updates] Updated the resident content LNK parser: MD5: E1A19C1B45B042E6FD7038317E06D675 SHA256: 443D8B87CE28F5F1666282C069EDA6C2A3A14BABF27BC1DBE3DD8A22BC2B11E7 Assets 3 All reactions Footer © 2022 GitHub, Inc. Footer navigation Terms Privacy S...

Latest Latest Compare Choose a tag to compare View all tags kacos2000 released this 07 Dec 17:10 · 1 commit to master since this release v.0.0.10.0 ae23860 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. [Update] Added ExtraData info from KnownFolderDataBlock, SpecialFolderDataBlock, EnvironmentVariableDataBlock, ConsoleDataBlock and ConsoleFEDataBlock Fixed issue with Knownfolder paths Other minor changes...

GCHQ

Skip to content Toggle navigation Sign up Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Case Studies Customer Stori...

Datadog Security Labs

Skip to content Toggle navigation Sign up Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Case Studies Customer Stori...

Doug Burks at Security Onion

We recently released Security Onion 2.3.190://blog.securityonion.net/2022/12/security-onion-23190-now-available.htmlToday, we are releasing a hotfix which improves support for Suricata file extraction into Strelka://docs.securityonion.net/en/2.3/release-notes.html#hotfix-20221207-changesNew InstallationsIf you want to perform a new installation, please review the documentation and then you can find instructions here://docs.securityonion.net/en/2.3/download.htmlExisting 2.3 InstallationsIf you ha...

Doug Metz at Baker Street Forensics

DFIR I’ve made some updates to the Mal-Hash PowerShell script. Most notable is that the script now works (via PowerShell) on Windows, Mac and Linux. The script takes the input of a file, calculates the hashes (MD5, SHA1, SHA256), and then submits the HASH to Virus Total for analysis. The script will also run Strings against the sample. The hashes, strings and Virus Total results are both displayed on screen and saved to a text report. Timestamp of the analysis is recorded in UTC. Get Mal-Hash.ps...

Elcomsoft

Elcomsoft Advanced Intuit Password Recovery 3.13 is an incremental update, adding support for Quicken 2021 and 2022, and QuickBooks 2022 and 2023. The new release accommodates for the changes in data formats and encryption in the latest versions of Intuit apps. In addition, the tool improves Windows 11 compatibility and includes essential bug fixes. Advanced Intuit Password Recovery 3.13 gets the ability to recover passwords protecting Intuit Quicken 2021/2022 documents. Passwords protecting Qui...

Eric Zimmerman

ExifTool

ExifTool Version History RSS feed: //exiftool.org/rss.xml Note: The most recent production release is Version 12.50. (Other versions are considered development releases, and are not uploaded to MetaCPAN.) Dec. 6, 2022 - Version 12.52 Added a few new Nikon LensID's (thanks LibRaw and Chris) Added Slovak translations (thanks Peter Bagin) Made SphericalVideoXML readable/writable as a block Improved handling of Matroska metadata tags, including language support Improved French translations (thanks P...

F-Response

Metaspike

Metaspike Software Releases release-notes agungor (Arman Gungor) December 9, 2022, 10:18pm #1 We have released FEC v3.85 with major improvements! Here is what’s new: Output into Disk Images FEC can now pack its MIME or MSG output into VHDX disk images. You can trigger automatic containerization on the Output page as follows: auto-containerize1706×600 56.4 KB Alternatively, you can create the containers when needed as a post-acquisition action: post-containerize2076×1738 281 KB In either case, co...

Oxygen Forensics

Oxygen Forensic® Detective v.15.2 Posted on December 8, 2022 FacebookTweetLinkedIn Our latest update to our flagship solution Oxygen Forensic® Detectivev.15.2 is here! This version introduces the following key features: Import and parsing of Berla iVe backups Brute force for Samsung Exynos devices with FBE Runtastic cloud data extraction The decryption of WhatsApp backups of .crypt15 type Support for XFS file system For a full list of updates, refer to the “What’s New” file in the Oxygen Forensi...

Passware

December 06, 2022 Product Update Passware Kit Mobile 2023 v1 tops up the list of supported devices with over 60 MediaTek-based smartphones by Nokia, Lenovo, Meizu, and others – 260+ devices in total! It also extracts more records from the Dashlane app for iOS. Continue Reading Passware Kit Ultimate: Introducing The All-in-One Forensic Decryption Suite November 16, 2022 Product Update We’re excited to announce Passware Kit Ultimate, an all-purpose decryption bundle. It allows investigators to gai...

X1

The adoption of cloud-based Microsoft 365 (“MS 365”) by enterprises continues to grow exponentially, with the company recently reporting 300 million monthly active users, and the addition of over 100 petabytes of new content each month. There is no question that MS 365 is now a major data source for eDiscovery, second only to file-shares and laptops, and as such provides challenges to every legal and eDiscovery practitioner. While MS 365 includes built-in eDiscovery tools in the Security and Com...