解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 8 – 2023 - SOFTWARE UPDATES

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。

SOFTWARE UPDATES

Amped

We are thrilled to bring you a huge Amped Replay update today. It’s been in your wish list for a very long time and we can now proudly reveal that Audio Redaction is finally here! UPDATE NOW See the new features in action! Contents 1 Viewing the Audio Plot 2 Redacting the Audio 3 Program Options 4 Enabling/Disabling Snap of Annotations 5 Close/Delete a Project and Associated Media Files 6 Viewing and Clearing the Selected Range 7 Other Improvements 8 Formats 9 Bugs 10 The Final Word For those no...

Cellebrite

← All Releases Version 3.5 | Cellebrite Digital Collector | February 14, 2023 Update now Help Contact Support Cellebrite Digital Collector can now start (boot) Mac M2 and T2 computers running macOS Ventura 13.x. This issue was fixed in this release of Digital Collector: Resolved an issue that prevented previews for *.pdf files from appearing for Mac M2 computers started from Digital Collector. Visit the MyCellebrite Portal for a user guide, quick start guide, and more information. About Investor...

Costas K

Latest Latest Compare Choose a tag to compare View all tags kacos2000 released this 18 Feb 21:34 v.0.0.20.0 c39f48d This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. [Updates] Rearranged the 'ItemID' extensions code for efficiency. Currently supported ListItem ItemID extensions: Type BEEF0001 BEEF0003 BEEF0004 BEEF0005 BEEF0006 BEEF0010 BEEF000A BEEF000B BEEF001A BEEF001B BEEF0019 BEEF0024 BEEF0025 BEEF0026 ...

Datadog Security Labs – GuardDog

v1.1.0 Latest Latest Compare Choose a tag to compare View all tags christophetd released this 15 Feb 07:47 · 10 commits to main since this release v1.1.0 91a35fb This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. What's Changed New features: Create new heuristic to identify PyPI packages with a single Python file (closes #160) by @christophetd in #162 Enhancements: Catch dynamic execution of base64-encoded co...

Didier Stevens

Update: pdf-parser.py Version 0.7.8 Filed under: My Software,Update — Didier Stevens @ 12:15 A small feature update for pdf-parser.py Statistics include unreferenced objects now: pdf-parser_V0_7_8.zip (D5: 7BBEA9497666397CBBB88B012A710210SHA256: FE393865861E00B48124B99CD5AEBBB5A632F1FBD883F4E4044DF8C8FA75BE9D Share this:TwitterFacebook Related Leave a Comment Leave a Comment » No comments yet. RSS feed for comments on this post. TrackBack URI Leave a Reply (comments are moderated) Enter your com...

Update: xor-kpa.py Version 0.0.7 Filed under: My Software,Update — Didier Stevens @ 0:00 I added extra plaintexts for the modulus of Cobalt Strike’s public RSA key. xor-kpa_V0_0_7.zip (D5: FB8155E56234648CC3AFFD890BFE9043SHA256: 069DCA2A1901D448DBF2CF202B5CE49846EFCBAACB73BF35B20AA085AAB31BA9 Share this:TwitterFacebook Related Leave a Comment Leave a Comment » No comments yet. RSS feed for comments on this post. TrackBack URI Leave a Reply (comments are moderated) Enter your comment here... Fill...

Update: file-magic.py Version 0.0.6 Filed under: My Software,Update — Didier Stevens @ 18:37 This new version of file-magic.py adds a definition to identify OneNote .one files: And adds support for pyzipper. file-magic_V0_0_6.zip (D5: 2C564E9B215672BA9352934C8B91B0ECSHA256: 6102CE6788EB17B17AB3C0AB054FE9ECA2C557E9349A7ACF9612759CC5C6CA97 Share this:TwitterFacebook Related Leave a Comment Leave a Comment » No comments yet. RSS feed for comments on this post. TrackBack URI Leave a Reply (comments ...

Update: cut-bytes.py Version 0.0.16 Filed under: My Software,Update — Didier Stevens @ 0:00 In this new version of cut-bytes.py, I add support for custom Python transforms (options -P and -S), pyzipper and fixed a bug. cut-bytes_V0_0_16.zip (D5: 04E6E0E46C6698127BAE443AF5CEF0F6SHA256: 0657F6A6837CEC9F3E9E50551F8861D19B70305A4B7C3C409D561C3462550D24 Share this:TwitterFacebook Related Leave a Comment Leave a Comment » No comments yet. RSS feed for comments on this post. TrackBack URI Leave a Reply...

Update: process-binary-file Version 0.0.9 Filed under: My Software,Update — Didier Stevens @ 0:00 This is a bug fix update. python-templates_V0_0_10.zip (D5: 29806A562411E4584455746C8CE41BABSHA256: CC520C26BE6E59F48AEA639EC477983333D75F91FFE295915DB4711C275E26DB Share this:TwitterFacebook Related Leave a Comment Leave a Comment » No comments yet. RSS feed for comments on this post. TrackBack URI Leave a Reply (comments are moderated) Enter your comment here... Fill in your details below or click...

DissectMalware

Public Notifications Fork 7 Star 58 A python library to parse OneNote (.one) files License Apache-2.0 license 58 stars 7 forks Star Notifications Code Issues 0 Pull requests 0 Actions Projects 0 Security Insights More Code Issues Pull requests Actions Projects Security Insights DissectMalware/pyOneNote This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository. main Switch branches/tags Branches Tags View all branches View all tags Name alrea...

IntelOwl

v4.2.1 Latest Latest Compare Choose a tag to compare View all tags mlodic released this 17 Feb 17:26 v4.2.1 df1c01c This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. please refer to the Changelog Assets 2 All reactions Footer © 2023 GitHub, Inc. Footer navigation Terms Privacy Security Status Docs Contact GitHub Pricing API Training Blog About You can’t perform that action at this time. You signed in with an...

Manabu Niseki

Skip to content Toggle navigation Sign up Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Case Studies Customer Stori...

MISP

  • go to homepage Toggle Navigation Home Features Data Models Data Models MISP core format MISP taxonomies MISP Galaxy MISP Objects Default feeds Documentation Documentation Documentation OpenAPI Tools Support Contributing Research projects Legal License Legal and policy GDPR ISO/IEC 27010:2015 NISD Communities Download Events Upcoming events Past events Webinars Hackathon MISP Summit News Contact Reaching us Contact Us Press inquiries Professional Services Commercial Support Security Matters Who...

Rapid7

Performance improvementsNew client-server communication protocolNew Virtual File System GUIFaster export functionalityTracing capability on client collectionsVQL improvement - disk based materialize operatorNew MSI deployment optionConclusionsReleaseVelociraptor 0.6.8 ReleaseMike Cohen 2023-02-13I am very excited to announce the latest Velociraptor release 0.6.8 is in release candidate status. This release has been in the making for a few months now and has a lot of new features and bug fixes.In...

ADF

Posted by Brittany Roberts on February 16, 2023 Find me on: LinkedIn Tweet ADF software is deployed in field and lab investigations of smartphones, computers, and storage devices and is used by digital first responders to quickly collect, identify, and report on digital evidence - thereby reducing or eliminating forensic backlogs that many agencies and organizations face today. Organizations have come to rely on ADF’s revolutionary digital investigation approach to solve their forensic backlog p...

WithSecure Labs

Skip to content Toggle navigation Sign up Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Case Studies Customer Stori...

Xways

X-Ways Forensics 20.8 Log Out | Topics | Search Moderators | Edit Profile X-Ways User Forum » Public Announcements » X-Ways Forensics 20.8 « Previous Next » Author Message Stefan Fleischmann Username: adminRegistered: 1-2001Posted on Tuesday, Feb 7, 2023 - 17:54: A preview version of X-Ways Forensics 20.8 is now available. The URL of the download directory for all recent versions can be retrieved by querying one's license status as always. What's new in v20.8 Preview 1? * Improved some aspects o...

Yamato Security

Skip to content Toggle navigation Sign up Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Case Studies Customer Stori...