解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 33 – 2023 - FORENSIC ANALYSIS

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。

FORENSIC ANALYSIS

ADF Solutions

Posted by ADF Solutions on August 11, 2023 Find me on: Facebook LinkedIn Twitter Tweet In today's digital age, mobile devices have become an integral part of our lives. They store a wealth of personal information, making them an attractive target for malicious actors. Whether you're an investigator, a digital forensics expert, or simply concerned about the security of your own device, being able to scan and analyze mobile devices is crucial. That's where Mobile Device Investigator (MDI) comes in...

Belkasoft

Introduction KnowledgeC.db is an SQLite database file that stores records of various activities on Apple devices. Those may include: Application usage information: records of what applications were installed and used, along with timestamps, durations, and frequency Internet activity: browsing history and search queries Call and message history: details such as call and message numbers, timestamps, and call durations Device state: information on battery usage, charging and screen lock events, con...

Cloudbrothers

Fabian Bader enthalten in Azure AD Entra KQL Sentinel Entra ID 2023-08-06 11178 wörter 53 minuten Inhalt The challenge The way to the solution The solution Entra ID - Azure AD Authentication and authorization error codes References The challenge Most of us analyzing Azure AD SignIn logs have been there. You come across a failed sign-in, but the ResultDescription is not really helpful, but only shows “Other”. Other? But what other? When using the Entra ID portal UI most of those error codes ...

Forensafe

04/08/2023 Friday Android Aqua Mail is one of the email applications designed to help users manage and organize their email accounts effectively on Android devices. It provides a user-friendly interface and a range of features to enhance the email experience. Those features include, but are not limited to, multi-account support, calendar integration, intelligent sorting, and advanced folder management Digital Forensics Value of Aqua Mail Android Aqua Mail artifacts, like those from any other ema...

Justin De Luna at ‘The DFIR Spot’

We've all heard of "Link" or "LNK" files, right? You want a faster way to open your favorite game, document or application without need to navigate to it's directory each time, so you create a shortcut file. Yeah yeah, we've done that; but did you know that Windows is creating these shortcut or "LNK" files for you each time a file is created and opened? The RundownWindows 7-11 Location: C:\Users\%username%\AppData\Roaming\Microsoft\Windows\RecentWindows XP Location: C:\Documents and Settings\%us...

Lorena Carthy-Wilmot

Vipps App — ForensicsRandom Dent·Follow6 min read·3 days ago--ListenShareMy notes regarding the Norwegian payment app, Vipps.Vipps is awesome, and I use it all the time (so do a lot of people in Norway):Vipps is a payment solution that enables you to pay in shops, online and in applications containing the Vipps symbol. You can transfer money to clubs, associations and organisations and receive and transfer money from and to other persons. Source: //vipps.no/I see it so often in extractions, but ...

Lucid Truth Technologies

Report this article Lucid Truth Technologies Lucid Truth Technologies Build the Best Case Possible with the Help of a Digital Forensic Investigator Published Aug 8, 2023 + Follow My friend and colleague, Kevin Ripa of the Grayson Group of Companies, has published some astonishing research [1] that shows Microsoft Windows can inaccurately report the serial numbers of the drives attached to the computer system and may even report the same incorrect serial number for multiple drives. This can lead ...

Jaspreet Singh at Mailxaminer

How to Trace Email Sender IP Address in Outlook Jaspreet Singh | Published: 10-08-2023 | Forensics | 5 Minutes Reading Are you looking for a solution for how to trace sender IP address in Outlook? Then, this blog will help you guide the appropriate way of finding out the sender’s IP address from an incoming email in Outlook. Sometimes it happens when you receive an email you would know the sender’s name and domain( for example, gmail.com and yahoo.com) but it is not easy to know the IP address o...