解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 52 – 2022 - MISCELLANEOUS

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。Week 52 – 2022 は こちら からご確認いただけます。「Buy me a coffee」からカンパをすると喜ばれます。

MISCELLANEOUS

Jessica Hyde

  • A Case for Digital Forensics

SecurityDigital ForensicsGRCInsights By Jessica Hyde, Founder, Hexordia FileCloud: The Hyper-Secure Content Collaboration Axinom: Protecting Premium Content with Technology IMATAG: Protecting Digital Assets Better Verimatrix: Securing Modern Connected World Bring up to speed Why might your organization need to have digital forensics experts at the ready? Folks with this expertise can help your team with a variety of situations including insider theft investigations, wrongful termination cases, h...

Martino Jerian at Amped

  • Survey Results: The State of Video Forensics 2022

During investigations and trials, video is one of the most common and most effective forms of evidence, but unfortunately, it is often taken for granted. There are many challenges to consider in relation to video evidence, and we believe it is of crucial importance to understand how users around the world are handling these and how the trends are shaping the state of video forensics in 2022 and beyond. For this reason, we launched in July a survey to hear the thoughts and opinions of video evide...

Olga Koksharova at Elcomsoft

  • Season’s Greetings and 2022 in Review

December 22nd, 2022 by Olga KoksharovaCategory: «General» The new year is fast approaching, and of course we are curious to know what it has in store for us in the field of computer, mobile, and cloud forensics. But before 2022 is over, we invite you to take a moment to reflect on what 2022 has been like for us. More research, development and updates remained our top priority, as it has been in all previous years. We have continued with constant improvement to our solutions by launching new feat...

Florian Roth

  • Guide to Use Nextron’s Sigma EVTX Checker

Guide to Use Nextron's Sigma EVTX Checker It's a fast go-based scanner for Linux, Windows, and macOS that applies Sigma rules and outputs the matches as JSON. Clone the Sigma Repository and cd into it git clone //github.com/SigmaHQ/sigma.git cd sigma Get the Sigma EVTX Checker It's part of our EVTX repo in which we collect log exports for the Sigma CI pipeline tests. The following commands downloads the version for Linux wget //github.com/NextronSystems/evtx-baseline/releases/latest/download/evt...

Forensic Focus

  • Yulia Samoteykina, Director of Marketing, Atola Technology

Ken Pryor

  • A Little Homelab and Life Update

I'm going to start writing more on my blog. No! Really! You do believe me, right? Ok, can't blame you if you don't. I come back to this from time to time and think this time I'm really going to dive into it, only to get sidetracked in some other direction. I promise I have a good excuse this time.Since I last posted, I have gone back to school on a part-time basis while continuing to work full-time. I decided it was high time to finally get that Associate's Degree I started on decades ago. My da...

Joachim Metz at Open Source DFIR

  • DFIR for good

Get link Facebook Twitter Pinterest Email Other Apps By Joachim Metz December 22, 2022 December is typically the time of year we think of donating to charity. There are many ways we can help others, including with DFIR. The following is one of such tales authored by Assen Tasheff and copied with permission.Once upon a timeOnce upon a time there was a humanitarian aid organization. They had a limited budget to spend on commercial software therefore Linux was their operating system of choice. For ...

Oxygen Forensics

  • Top Software Updates in 2022

Top Software Updates in 2022 Posted on December 21, 2022 FacebookTweetLinkedIn As this year comes to a close, we want to review the top advancements we’ve made to our software in 2022. Table of Contents Mobile Data Extraction Cloud Data Extraction Computer Artifacts Data Import Data Analytics Related Articles Mobile Data Extraction This year we’ve introduced numerous methods and features to allow investigators increased access to evidence from mobile devices and cloud services, even if encrypted...

Grace Chi at Pulsedive

  • 2022 Year in Review

A visual wrap up of Pulsedive in 2022 - a year of people, partners, products, and presentations. Grace Chi Dec 23, 2022 • 3 min read It's been a meaningful year for Pulsedive in our quest to provide frictionless threat intelligence solutions for growing teams.In 2022, we releases 2 major product updates and launched a new product line. We introduced bulk analysis, key integrations (MITRE ATT&CK FTW), and a way for organizations to have their very own Pulsedive instance. These releases - Pulsediv...

SANS

  • Q&A From SANS Special Broadcast: What You Need to Know About OpenAI’s New ChatGPT Bot – and How it Affects Your Security

Q&A From SANS Special Broadcast: What You Need to Know About OpenAI's New ChatGPT Bot - and How it Affects Your Security Emily Blades Q&A From SANS Special Broadcast: What You Need to Know About OpenAI's New ChatGPT Bot - and How it Affects Your Security We had an influx of questions come in during our ChatGPT Special Broadcast on Wednesday, December 21. Here were those questions — and our responses. December 21, 2022 On December 21, 2022, attendees joined us for a SANS Special Broadcast: What...

Byron Price at Sophos

  • Meet Anthony Bradshaw, MDR Threat Analyst and Team Lead

Anthony Bradshaw shares his career journey at Sophos and how we have supported his professional growth and provided opportunities to improve both his skills as an analyst and as a leader. Written by Byron Price December 19, 2022 #SophosLife Here, Anthony details how his career has developed at Sophos and offers insights into how he progressed into the role of Team Lead: The Beginning “It was the winter of 2020 during the early stages of the Covid pandemic, and I was working as an IT security ana...

Ron Deibert at The Citizen Lab

  • CatalanGate Report: Correcting a Case

On December 15, 2022, as part of our regular re-analysis of past cases to find additional spyware infection indicators and details, we discovered that a researcher had misread the labels assigned to two individuals’ results, leading to a confusion between phones owned by two people with the same initials who were part of the same group of potential targets in the CatalanGate investigation. The error originates solely from a single mistake in interpreting a system of working labels, which we used...