解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 11 – 2023 - SOFTWARE UPDATES

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。

SOFTWARE UPDATES

Brian Maloney

OneDriveExplorer Public Notifications Fork 10 Star 109 Code Issues 0 Pull requests 0 Actions Projects 0 Security Insights More Code Issues Pull requests Actions Projects Security Insights Releases v2023.03.10 v2023.03.10 Latest Latest Compare Choose a tag to compare View all tags Beercow released this 10 Mar 19:04 v2023.03.10 c13e136 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. Change Log Added GUI Sync...

Brim

v1.0.0 Latest Latest Compare Choose a tag to compare View all tags philrz released this 06 Mar 21:24 v1.0.0 3016da4 The Brim app is now named Zui! Pronounced: “zoo-ee” Visit the Brim Data download page page to find the package for your platform. Where are my pools? If you've upgraded to Zui from Brim, the pools you had in Brim are still present but you'll need to run a migration script to convert them to a new Zed lake storage format. See the Brim/Zui Transition guide for details. Other Changes ...

Costas K

Latest Latest Compare Choose a tag to compare View all tags kacos2000 released this 05 Mar 18:43 v.1.0.72.0 83ebab5 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. [Updates] Small correction MD5: B1FE02A98BF1024283127B7F62E4BE5B SHA256: 65C36420E2DB2F3D4A068BC905F6B788C9376736B183C94E9893CB00A5D53119 Assets 3 1 person reacted 👍 1 AndrewRathbun reacted with thumbs up emoji All reactions 👍 1 reaction Footer ...

Latest Latest Compare Choose a tag to compare View all tags kacos2000 released this 12 Mar 00:55 v.0.0.8.0 64741d7 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. [Update] Reversed the order in the Events list - now they appear with the newest event on top MD5: 913B7C9E6378B5EC0EC78F076155EABA SHA256: 554F14351D25E5FEB8ECFB7C6AB8A807CB8269D43FA65DEC75ED7979321D8280 PS: only works in x64 Windows (8.1/10) As...

Latest Latest Compare Choose a tag to compare View all tags kacos2000 released this 11 Mar 23:53 v.0.0.31.0 f240546 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. [Updates] Added option to carve & display LNK files from raw files (bin,001,etc) (needs more testing) If an 'automaticDestinations-ms' file is corrupted, it will automatically try to carve out the LNK entries from the streams and display them. A...

Latest Latest Compare Choose a tag to compare View all tags kacos2000 released this 06 Mar 11:55 v.0.0.20.0 2814738 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. [Update] Small correction MD5: 0F3FF5A4279F41EDF3B6155764193ADB SHA256: 7BB39EC66E70B3B307AAFC25E72A2C5A24F53DAA4DFE168B6E7E93A4B7BE6AFE Assets 3 All reactions Footer © 2023 GitHub, Inc. Footer navigation Terms Privacy Security Status Docs Conta...

Datadog Security Labs

Skip to content Toggle navigation Sign up Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Case Studies Customer Stori...

Foxton Forensics

Browser History Examiner PageRecon Free Tools Browser History Capturer Browser History Viewer SQLite Examiner Support Customer Portal FAQs Submit Ticket Resources Blog Downloads Free Tools News Company Contact Us Our Clients About us Browser History Examiner — Version History FeaturesPricingFAQsUser GuideVersion History Version 1.18.1March 07, 2023 Performance improvements to favicon extraction Version 1.18.0October 18, 2022 Support for Safari web browserAdded PLIST viewerSupport for Chromium 'S...

Free Tools Browser History Capturer Browser History Viewer SQLite Examiner Support Customer Portal FAQs Submit Ticket Resources Blog Downloads Free Tools News Company Contact Us Our Clients About us PageRecon FeaturesPricingFAQsUser GuideVersion History Free Trial Buy Now Web page screenshots with an audit trail PageRecon makes it easy to capture web pages in a manner that can be verified for authenticity. Take full-page screenshots of any web page using the built-in web browser. View example PD...

Griffeye

Hasherezade

Skip to content Toggle navigation Sign up Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Case Studies Customer Stori...

Jason Ostrom

IntroductionEdge is a new reconnaissance tool with a unique capability of mapping IP addresses to their cloud providers. It can tell you the data center and service an IP address is hosted with. It automatically downloads all three cloud provider (AWS, Azure, GCP) IP address JSON files, parses and loads them into memory, and can then perform fast lookups at scale. It tells you which cloud provider the IP address belongs to (AWS, Azure, GCP) along with the data center and cloud service (if applic...

Manabu Niseki

Skip to content Toggle navigation Sign up Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Case Studies Customer Stori...

Nextron Systems

Mar 7, 2023 | Newsletter, THOR, THOR Lite, Tutorial We are excited to announce that the upcoming version 1.11 our tool, THOR Util, now has the capability to convert log output files from both the default and JSON format into CSV files. This new feature will make it easier for users to analyze their log data and extract the information they need. With the ability to convert log files into CSV, users can now import their log data into their favorite spreadsheet software and manipulate it to create...

Open Source DFIR

Get link Facebook Twitter Pinterest Email Other Apps By Joachim Metz March 05, 2023 Plaso 20230226 releasedThe Plaso team is delighted to announce a new Plaso release, 20230226. This release has a mixture of new features and under the hood improvements.Notable changesSeveral improvements for IIS 10 log (#4566), Automatic Destination (#4568, #4570), Custom Destination (#4569) and PLS recall (#4572) format edge cases.Added bloom (filter) database hash tagging analysis plugin (#4527), with thanks t...

OpenCTI

Version 5.6.2 Latest Latest Compare Choose a tag to compare View all tags SamuelHassine released this 11 Mar 14:21 5.6.2 002e102 This commit was signed with the committer’s verified signature. richard-julien Julien Richard GPG key ID: 5A3D156BFCC8BAA7 Learn about vigilant mode. Dear community, OpenCTI version 5.6.2 has been released 👏! This version hotfixes 3 minor bugs and add the support of HTTP/HTTPS proxy for the platform process (mainly for synchronization purposes) 📡. Enhancements: #2370 H...

Oxygen Forensics

Oxygen Analytic Center v.1.0 Posted on March 7, 2023 FacebookTweetLinkedIn Welcome our new product – Oxygen Analytic Center. It enables real-time, browser-based collaborative data review and analysis — any time, anywhere — so investigators, team members, and eDiscovery professionals can resolve cases faster and more efficiently. Any time, anywhere remote work Give multiple users simultaneous access to their assigned dataset, so everyone on the case can maximize their productivity. All that’s nee...

Xways

X-Ways Forensics 20.8 Log Out | Topics | Search Moderators | Edit Profile X-Ways User Forum » Public Announcements » X-Ways Forensics 20.8 « Previous Next » Author Message Stefan Fleischmann Username: adminRegistered: 1-2001Posted on Tuesday, Feb 7, 2023 - 17:54: A preview version of X-Ways Forensics 20.8 is now available. The URL of the download directory for all recent versions can be retrieved by querying one's license status as always. What's new in v20.8 Preview 1? * Improved some aspects o...

X-Ways Forensics 20.7 Log Out | Topics | Search Moderators | Edit Profile X-Ways User Forum » Public Announcements » X-Ways Forensics 20.7 « Previous Next » Author Message Stefan Fleischmann Username: adminRegistered: 1-2001Posted on Sunday, Sep 18, 2022 - 17:22: A preview version of X-Ways Forensics 20.7 is now available. The URL of the download directory for all recent versions can be retrieved by querying one's license status as always. What's new in v20.7 Preview 1? * 5% more definitions of ...