解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 37 – 2023 - MISCELLANEOUS

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。

MISCELLANEOUS

ADF Solutions

Posted by ADF Solutions on September 8, 2023 Find me on: Facebook LinkedIn Twitter Tweet Data analysis can quickly become overwhelming without proper organization tools. Extracting, analyzing, and reporting on this data efficiently is of paramount importance to investigators. Mobile Device Investigator (MDI), the analysis section of Mobile Device Investigator, is an invaluable asset for digital forensics professionals. Its functionalities for data examination, organization, and reporting simplif...

Alex Teixeira

Alex Teixeira·FollowPublished inDetect FYI·5 min read·1 day ago--1ListenShareThe idea is to explore a few simple steps of the workflow I often use when developing Splunk dashboards that I'm sure others can benefit.I’ll start sharing more practical Splunk tips besides the usual Detection Engineering insights so stay tuned for more!Let's start with the must know, then we go over the ones I believe are overlooked despite the major benefit they bring.The Obvious Tips for beginnersWell, those cannot ...

Fabian Mendoza at AboutDFIR

AboutDFIR Site Content Update – 09/08/2023 By Fabian MendozaOn September 8, 2023September 8, 2023 Tools & Artifacts – Windows – new entry added – Microsoft Remote Access VPN – Forensic Aspects of Microsoft Remote Access VPN Tools & Artifacts – Linux – new entry added – Walk-through of Dr. Ali Hadi’s Web Server Case CTF Tools & Artifacts – iOS – new entry added – Telegram – Investigating iOS Telegram Tools & Artifacts – DVR/Multimedia – new entry added – Deblur a Moving Car Jobs – old entries cle...

Craig Ball at ‘Ball in your Court’

: A Primer for Forensic Examiners.” I describe it thus: This paper covers ways to become an effective witness and pitfalls to avoid. They say lawyers make notoriously poor witnesses and I have no illusions that I’m a great witness. But after forty years of trial practice and thirty as a forensic examiner, I’ve learned a few lessons I hope might help other examiners build their skills in court. In the paper, I discuss the difficulty computer forensic examiners face honing their testimonial abilit...

Brendan Mccreesh

My GIAC Certified Forensic Analyst Certification [GCFA] I have to say, I admire those that can post regularly to their blog as I find it very difficult to carve out time to put something together. I knew it had been a while since my last post, however October 2021 was a shock to me. Time flies. Since my last post, I completed the SANS FOR508 – Advanced Incident Response, Threat Hunting, and Digital Forensics OnDemand course with Chad Tilbury at the helm and obtained the GCFA certification. I enj...

Forensic Focus

Matt Lehman at GreyNoise

Matt LehmanSeptember 6, 2023Introducing the GreyNoise Labs Python CLI package: a robust toolkit for advanced users seeking to maximize the potential of our experimental Labs services.Cybersecurity data analysis is a complex and rapidly evolving landscape. To stay ahead, power users need tools that offer swift and accurate data handling. That's where the new GreyNoise Labs CLI package comes in. Crafted to optimize the parsing and manipulation of our sensor datasets, this CLI will not only expedit...

Magnet Forensics

We’re proud to be continuing our commitment to help promising officers get an opportunity to enter the field of—or advance in—digital forensics through the Magnet Forensics Scholarship Program. Applications are now open for the 2023 awards and will close December 1, 2023. Who Can Apply for the Scholarship Two categories are awarded in the Magnet Forensics Scholarship Program: new to digital forensics and advanced. The new to digital forensics category is aimed at promising officers who are looki...

Apple is continuously rolling out updated versions of its mobile operating system, iOS, to address security concerns and introduce new features. While these ongoing releases provide value for the end users, they also add to the challenges faced by examiners who need to access and extract critical data from mobile devices involved in criminal investigations. The GrayKey team works diligently to ensure that we keep pace with the latest version of Apple’s operating system and have recently updated ...

Ed Cabrera at Trend Micro

TrickBot & Conti Sanctions: Implications for CISOs & Boardrooms Discover what the increased regulatory risk due to recent US and UK sanctions imposed on TrickBot and Conti cybercriminals mean for CISOs and board members. By: Ed Cabrera September 08, 2023 Read time: ( words) Save to Folio Subscribe Recent sanctions imposed by the U.S. Treasury Department and the U.K. Foreign, Commonwealth & Development Office have drawn the attention of the cybersecurity community. These sanctions target the Tric...