解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 14 – 2023 - MISCELLANEOUS

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。

MISCELLANEOUS

Kevin Ripa at SANS

Adam at Hexacorn

March 28, 2023 in Preaching Social media are full of questions that are formulated in a passive, passive-aggressive, or upfront aggressive way, often using common fallacies in a manipulative way to discourage dialogue. It is a human nature to simplify things, yet we live in a complex world and, whether we like it or not, there is a historical evidence supporting the notion that we are better off embracing that complexity instead of running away from it…. A lot of these questionable questions, st...

Alican Kiraz

Cyber Security - Incident Response Part 3.3: Recovery | ENSource : //www.hbo.com/chernobylHi everyone, after a long break, we continue with our Incident Response series’s second to last article. At this stage, we will renew/repair the infected systems we isolated and destroy and make our systems function again.In the recovery step, an IR team must think about these three items three times. These repetitive thought notes should include the following:Question 1: Were we hasty?Source : //www.hbo.co...

Anton Chuvakin

So, we went through “Debating SIEM in 2023, Part 1”, now let’s debate a bit more. At this point, everybody who didn’t “rage stop” reading it should be convinced that yes, SIEM does matter in 2023.Debating SIEM in 2023, Part 1Hey, it is 2023, let’s debate SIEM again!medium.comBut why? I bet the views on why SIEM matters differ a lot. So let’s dive into this!Let’s start with this: why should anyone buy an SIEM tool in 2023? And please don’t say “because you are still SIEM-less” or “because you did...

Belkasoft

Loading… Company About News Customers Partners Contact Us Contacts +1 (650) 272-03-84 (USA and Canada) 702 San Conrado Terrace, Unit 1Sunnyvale CA 94085, USA support@belkasoft.com sales@belkasoft.com Subscribe to the newsletter Be the first to receive product updates and company news. Name * Error! Required field E-mail * Error! Required field Subscribe Sending request, please wait ... © 2002-2023 Belkasoft® Terms of use Privacy policy Public offer

Carrie Roberts at Black Hills Information Security

Carrie Roberts // Guest Blog OK, I admit it: I might have a problem. But seriously, can you ever really have enough screen space? In this blog post, I’ll describe a cheap solution for having a lot of screen space for your work-from-home office. I will also share other aspects of my office that make it functional and enjoyable (links are included if you are interested in imitating any of it). I’m using five 43” 4K televisions as monitors for my work-from-home office. Each TV is less than $200, an...

Adam Cohen Hillel at Cado Security

Brad Garnett at Cisco’s Talos

By Brad Garnett Wednesday, March 29, 2023 08:03 Cisco Talos Incident Response On The Radar We’ve written before about the importance of taking a proactive approach to cybersecurity.Whether it be threat hunting, an active defense posture or just improving security instrumentation alerts and logs an organization keeps, it’s best for every user — no matter the size — to be prepared for when a cybersecurity incident or breach occurs.We saw this recently with a customer in the education industry vert...

David Okeyode

The cloud computing market is experiencing strong growth and the top four cloud providers (AWS, Azure, GCP, Alibaba Cloud) are leading the way. According to reported earnings from last year (FY 2022), these top providers control almost 80% of the market! The market is also growing in all regions of the world, with a whopping $47 billion increase from the previous year.According to a recent study, ONE of the reasons for adopting a multi-cloud strategy is to address gaps in regional data governanc...

Bhabesh at ‘defend your networks…’

Share on FaceBook Share on Twitter Share on Pinterest Author Bhabesh March 30, 2023 8 Min Read At Ignite 2022, Microsoft announced their partnership with Zeek, and its corporate sponsor, Corelight, which resulted in Zeek being integrated as a component within Microsoft Defender for Endpoint (MDE). What it means for the rest is that Zeek has finally come to Windows, provided it is still in experimental phase and lacks many features compared to its *nix counterpart. Gradually, this feature parity ...

EclecticIQ

About EclecticIQ Blog Careers Search Platform Solutions Partners Resources Platform Overview Intelligence at the core Products Packages Ecosystem Support Services Academy Solutions Overview By Team By Need Partners Our Partnerships Partner Program Resources Take Action with CTI What is STIX and TAXII? Browse All Resources Open Source Projects About EclecticIQ About Meet the Team Investors & Board Press Releases In the News Events Awards Offices & Teams Blog Careers Platform Learn more about our ...

Forensic Focus

Christa Miller at Forensic Horizons

Photo by Andras Vas on UnsplashRemember the “CSI effect”? The way jurors expected every trial to include forensic evidence, even when none had been and it wasn’t needed to prove the crime? As well, the amount of interest in university forensic science programs?Then remember the hard flop that CSI: Cyber took? “The dialogue is flatter than usual and, for all the techie attempts at whiz-bang-pow, the stories are facile,” wrote one reviewer at Rotten Tomatoes.Not even the CSI franchise, in other wo...

Tom Kopchak at Hurricane Labs

By Tom Kopchak|Published On: March 28th, 2023|Tags: Penetration Testing|As cybersecurity enthusiasts, we don’t miss any chance to participate in events that challenge our skills and support up-and-coming security professionals in the process. That’s why it was a thrill to represent Hurricane Labs at the Northeast regional event for the Collegiate Cyber Defense Competition (NECCDC 2023). Meredith Kasper and I were a part of the Red Team. The purpose of this team is to load up the competition with...

Kevin Pagano at Stark 4N6

Posted by Kevin Pagano April 01, 2023 Get link Facebook Twitter Pinterest Email Other Apps Shortlink: startme.stark4n6.comIf people have suggestions for additions please feel free to shoot me a message on Twitter (@KevinPagano3) or Mastodon.Cipher & Decoding ToolsAres - Automated decoding of encrypted text without knowing the key or ciphers usedBlog FeedBelCyber - Ahmed BelhadjadjiCyberFox - Mathias FuchsEric Capuano's SubstackSeth EnokaForensic-Impact - ParabenForensic ToolsMAGNET RESPONSE - qu...

Salvation DATA

Knowledge 2023-03-30 In today’s fast-paced, technology-driven world, digital forensic investigations play a critical role in uncovering valuable evidence and solving complex cases. As the need for efficient and effective digital forensic labs grows, so does the demand for comprehensive solutions to equip these facilities. Enter SalvationDATA, a leading digital forensic lab solution provider committed to revolutionizing the way forensic professionals work. Over the years, our forensic laboratory ...

SANS

Unlock Your Cybersecurity Potential: A Look at What's New in the Updated New to Cyber Field Manual Emily Neuens Unlock Your Cybersecurity Potential: A Look at What's New in the Updated New to Cyber Field Manual Discover all of the changes made to the New to Cyber Field Manual. March 28, 2023 As cybersecurity continues to grow and evolve, so does the demand for skilled professionals in the field. However, getting started in cybersecurity can be daunting, especially for those unfamiliar with the i...

homepage Open menu Go one level top Train and Certify Train and Certify Immediately apply the skills and techniques learned in SANS courses, ranges, and summits Overview Courses Overview Full Course List By Focus Areas Cloud Security Cyber Defense Cybersecurity and IT Essentials DFIR Industrial Control Systems Offensive Operations Management, Legal, and Audit By Skill Levels New to Cyber Essentials Advanced Expert Training Formats OnDemand In-Person Live Online Course Demos Training Roadmaps Ski...

homepage Open menu Go one level top Train and Certify Train and Certify Immediately apply the skills and techniques learned in SANS courses, ranges, and summits Overview Courses Overview Full Course List By Focus Areas Cloud Security Cyber Defense Cybersecurity and IT Essentials DFIR Industrial Control Systems Offensive Operations Management, Legal, and Audit By Skill Levels New to Cyber Essentials Advanced Expert Training Formats OnDemand In-Person Live Online Course Demos Training Roadmaps Ski...

homepage Open menu Go one level top Train and Certify Train and Certify Immediately apply the skills and techniques learned in SANS courses, ranges, and summits Overview Courses Overview Full Course List By Focus Areas Cloud Security Cyber Defense Cybersecurity and IT Essentials DFIR Industrial Control Systems Offensive Operations Management, Legal, and Audit By Skill Levels New to Cyber Essentials Advanced Expert Training Formats OnDemand In-Person Live Online Course Demos Training Roadmaps Ski...

Thomas Wolfe Digital Forensics Salary, Skills, and Career Path How to become a digital forensic analyst March 30, 2023 ​​​​​Becoming a digital forensic analyst is not an easy task. It requires an education that provides hands-on experience, not just theory. However, with the right steps, anyone can become a digital forensic analyst. It is no secret that digital forensics is a rapidly growing field. With cybercrime on the rise, businesses, state and federal government, and law enforceme...

homepage Open menu Go one level top Train and Certify Train and Certify Immediately apply the skills and techniques learned in SANS courses, ranges, and summits Overview Courses Overview Full Course List By Focus Areas Cloud Security Cyber Defense Cybersecurity and IT Essentials DFIR Industrial Control Systems Offensive Operations Management, Legal, and Audit By Skill Levels New to Cyber Essentials Advanced Expert Training Formats OnDemand In-Person Live Online Course Demos Training Roadmaps Ski...

Mani Keerthi Nagothu at SentinelOne

March 27, 2023 by Mani Keerthi Nagothu PDF Cybersecurity incidents are no longer black swan events in today’s world. In recent decades, they have become so common that few organizations are spared from the rippling effects of successful cyberattacks. Having a strong incident response strategy is a crucial line of defense organizations have against threat actors. Depending on the type of incident and how impactful it is on the targeted organization, there are a large number of moving parts that m...

SUMURI

When conducting digital forensic examinations on Mac systems, it is essential to use a Mac and tools specifically designed for the macOS and Apple file systems. Macs use complex file systems, including the Apple File System (APFS) and Mac OS Extended (HFS+) file systems, which may not be fully understood by Windows-based forensic tools.Using Mac native tools designed explicitly for Mac systems is critical to ensuring comprehensive and accurate digital forensic examinations. These tools are desig...

The COVID-19 pandemic has resulted in a significant increase in the number of employees working from home, which has had an impact on the field of eDiscovery. One of the main effects is that companies may have a harder time collecting and preserving electronically stored information (ESI) that is located on employees’ personal devices or home computers. This can make it more difficult to locate relevant ESI in response to a discovery request. Additionally, companies may also need to review a lar...

Terryn at chocolatecoat4n6

What’s in my DFIR toolbox? | 2023 March 29, 2023March 29, 2023 / ChocolateCoat You know what they say sharing is caring. So, I recently got a new system and had to get my usual tools back on the system. I figured this would be a great time to share with you all the tools I default to and why I use them. If you work in DFIR, I don’t think too many of these will be much of a surprise but everyone loves to show off their collection right? Also, for context, this is my personal Windows system and I ...

Larry Gill and John Patzakis at X1

By Larry Gill and John Patzakis Last week X1 attended and exhibited at Legalweek in New York, engaging with many customers, partners, and industry colleagues. It was great to connect with so many of our customers, and friends and hear their valuable feedback and insight regarding industry trends, pain-points, and their process and technology wish-lists to better address today’s eDiscovery and information governance challenges. Here is a report on three key takeaways from these interactions and t...