解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 31 – 2023 - SOFTWARE UPDATES

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。 一部の記事は Google Bard を使い要約しています。4n6 は こちら からご確認いただけます。

SOFTWARE UPDATES

Brim

v1.2.0 Latest Latest Compare Choose a tag to compare View all tags philrz released this 28 Jul 02:18 v1.2.0 0587e84 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. Visit the Brim Data download page page to find the package for your platform. Improved Tabs This change is relevant for users that have have additional Zed lake connections besides just the one to the default lake that starts behind Zui. You'll ...

DFIR labs

Public Notifications Fork 0 Star 0 License Apache-2.0 license 0 stars 0 forks Activity Star Notifications Code Issues 0 Pull requests 0 Actions Projects 0 Security Insights More Code Issues Pull requests Actions Projects Security Insights dfirlabs/bookmarkparser This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository. main Switch branches/tags Branches Tags View all branches View all tags Name already in use A tag already exists with the p...

Doug Burks at Security Onion

IntroductionRecent events have forced us to change course on the base operating system (OS) for Security Onion 2.4. On 6/21/2023, Red Hat announced changes to their source code availability for Red Hat Enterprise Linux (RHEL)://www.redhat.com/en/blog/furthering-evolution-centos-streamOn 6/26/2023, Red Hat then posted a follow-up://www.redhat.com/en/blog/red-hats-commitment-open-source-response-gitcentosorg-changesThese announcements prompted us to go back to first principles and re-evaluate the ...

We recently released the fourth Beta version of Security Onion 2.4://blog.securityonion.net/2023/07/security-onion-24-beta-4-release-now.htmlToday, we are excited to release Security Onion 2.4 Release Candidate 1 (RC1)!HighlightsA few highlights of this release:You may remember the Analyst Workstation in 2.3. It's back in 2.4 and it's now called Security Onion Desktop!//github.com/Security-Onion-Solutions/securityonion/issues/10862SOC now has a new feature that, if enabled, will automatically pe...

Drew Alleman

Latest Latest Compare Choose a tag to compare View all tags Drew-Alleman released this 23 Jul 07:13 · 15 commits to main since this release 1.2.0 c25ffdd This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: 4AEE18F83AFDEB23 Learn about vigilant mode. This update brings a plugin management system to DataSurgeon. You can now add, remove, and list plugins using the --add, --remove, and --list options. I also added a new plugin, ds-winreg-plugin, that can fi...

Eric Zimmerman

Sandfly Security

Sandfly 4.6.0 - Advanced Whitelisting and Free SSH HunterLearn moreUnder Attack?SupportContact UsPlatformWhy Sandfly?How Sandfly WorksSSH Key AuditingLinux Threats DetectedWalk ThroughResourcesProduct FAQsProduct DocumentationCode Security AuditsCustomersTestimonialsCase StudiesAboutOur StoryPartners and MSSPsUnder Attack? Contact Us NewsBlogGet SandflyNewsSandfly 4.6.0 - Advanced Whitelisting and Free SSH HunterSandfly 4.6.0 - Advanced Whitelisting and Free SSH HunterNews Product UpdateDateJuly...

Stratosphere Lab

Stratosphere IPS July 30, 2023 Datasets Introducing Collectress: Consistent Threat Intelligence Feed Collection and Storage Stratosphere IPS July 30, 2023 Datasets Collectress is a free software tool developed by Stratosphere: //github.com/stratosphereips/collectress This blog was authored by Veronica Valeros (@verovaleros) on July 30, 2023This blog introduces Collectress, a new tool developed at the Stratosphere Laboratory. Collectress was born out of the need to have a certain feed for 30 days...

Rapid7

GUI improvementsEnhanced client searchPaged table in Flows ListVQL Plugins and artifactsChrome artifactsLnk forensicsDirect S3 accessorVolume Shadow Copies analysisThe SQLiteHunter projectGlob plugin improvementsServer improvementsConclusionsReleaseVelociraptor 0.7.0 ReleaseMike Cohen 2023-07-27I am very excited to announce the latest Velociraptor release 0.7.0 is now in release candidate status. Please test and report any issues on the Github issue board.In this post I will discuss some of the ...

Xways

Log Out | Topics | Search Moderators | Edit Profile X-Ways User Forum » Public Announcements » X-Ways Forensics 20.9 « Previous Next » Author Message Stefan Fleischmann Username: adminRegistered: 1-2001Posted on Tuesday, May 2, 2023 - 20:45: A preview version of X-Ways Forensics 20.9 is now available. The URL of the download directory for all recent versions can be retrieved by querying one's license status as always. What's new in v20.9 Preview 1? * What's better than 5 hash databases? Right, 6...