解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 36 – 2023 - SOFTWARE UPDATES

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。

SOFTWARE UPDATES

Apache

Cyber Triage

Didier Stevens

Update: sortcanon.py Version 0.0.3 Filed under: My Software,Update — Didier Stevens @ 17:44 Some new options for my tool sortcanon.py to handle more inputs. A bit of context: when one sorts a list of IPv4 addresses as text, one gets a result as follows. Take this list: Just sorting this gives this result: The IPv4 address starting with 185 comes first, because by default, sorting is string based and digit 1 comes before digit 3. With sortcanon, one can provide a Python function that will be used...

Update: emldump.py Version 0.0.12 Filed under: My Software,Update — Didier Stevens @ 10:29 This update to emldump.py adds a new feature to fix (-F) some obfuscations. For the moment, only one obfuscation method is fixed (many are already ignored with option -f –filter), used in polyglot PDF/Word files. emldump_V0_0_12.zip (D5: 3847B92460C0485E1238C47C29EF9DE1SHA256: AFDFB8E78AE7DE56F50EA73D69705B6DACB425FFBD40D6997D64C7C75E3D8A0D Share this:TwitterFacebook Related Leave a Comment Leave a Comment...

k1nd0ne

Latest Latest Compare Choose a tag to compare View all tags k1nd0ne released this 27 Aug 12:47 v1.3.2-beta eb26f9c 🛠 BugFix: - Issue #7 : Mounted volumes permission issues on Linux fixed by using named volumes. - Windows Timeliner bug where the artifacts are not displaying when the user clicks on the chart. Assets 2 🚀 3 noxPHX, 1259iknowthat, and Yann-Situ reacted with rocket emoji 👀 1 noxPHX reacted with eyes emoji All reactions 🚀 3 reactions 👀 1 reaction 3 people reacted Footer © 2023 GitHub, ...

Magnet Forensics

Responding to cyber security incidents often necessitates leveraging the experience of the broader team to ensure a quick and complete response. IGNITE now allows you to easily share and collaborate on cases within your organization, helping your team work together to reach a quick resolution. Case Sharing in IGNITE With the new case-sharing capabilities, you can easily select “share case” in the top right of a case details page to make the results of your case available to the rest of your orga...

We’re excited to announce that Magnet OUTRIDER now supports triage of iOS devices! This is in addition to already existing triage support of Windows, Macs, and external drives, as well as Android mobile devices. Also with Magnet OUTRIDER 4.0, you can now use MD5 hash matching to locate files on a device using hashsets like VICS or CAID. You can upgrade to the latest version of Magnet OUTRIDER in-product by clicking the Check for Updates button under Manage, or by heading over to the Customer Por...

Ninoseki

Skip to content Toggle navigation Sign up Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Resources Customer Stories ...

Juan Leaniz at Open Source DFIR

Get link Facebook Twitter Pinterest Email Other Apps By Juan Leaniz August 30, 2023 The Turbinia development team are excited to announce the release of a number of new features and improvements for Turbinia. With the latest updates, Turbinia now includes an API server and a web interface, providing even more flexibility and ease of use. In this blog post we'll take a closer look at these exciting new additions.Turbinia API ServerOverviewThe Turbinia API server is an HTTP REST API that allows cl...

OpenCTI

Version 5.10.1 Latest Latest Compare Choose a tag to compare View all tags Filigran-Automation released this 01 Sep 02:07 · 7 commits to master since this release 5.10.1 710c106 This commit was signed with the committer’s verified signature. Filigran-Automation Filigran Automation GPG key ID: 47654BE6AC484914 Learn about vigilant mode. Enhancements: #4214 Add security login for admin user in case of local strategy deactivation Bug Fixes: #4210 Take last item date instead of build date in RSS sta...

Mike Cohen at Rapid7

Sandfly Security

Sandfly 4.6.0 - Advanced Whitelisting and Free SSH HunterLearn moreUnder Attack?SupportContact UsPlatformWhy Sandfly?How Sandfly WorksSSH Key AuditingLinux Threats DetectedWalk ThroughResourcesProduct FAQsProduct DocumentationCode Security AuditsCustomersTestimonialsCase StudiesAboutOur StoryPartners and MSSPsUnder Attack? Contact Us NewsBlogGet SandflyNewsSandfly 4.6.1 - Microsoft Active Directory Support and Default Linux Password AuditingSandfly 4.6.1 - Microsoft Active Directory Support and ...

SigmaHQ

Skip to content Toggle navigation Sign up Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Resources Customer Stories ...

Sleuthkit

The Sleuth Kit can be used with Autopsy, which can be downloaded here. Refer to the SleuthKitWiki for Packages and Add-ons. Bugs See the Support page for details on reporting bugs. Announcements Announcements of new releases are sent to the sleuthkit-announce and sleuthkit-users e-mail lists and the RSS feed . © 2003-2023 Brian Carrier

Yamato Security

Skip to content Toggle navigation Sign up Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Resources Customer Stories ...