解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 44 – 2023 - FORENSIC ANALYSIS

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。

FORENSIC ANALYSIS

Emi Polito at Amped

Forensafe

Solving Cellebrite's September 2023 CTF (Felix's iPhone device) Using ArtiFast 20/10/2023 Friday Cellebrite held their yearly CTF last month and this year the challenge featured 4 devices, belonging to 4 different suspects. In this blog, We will use ArtiFast to answer the questions associated with one of the suspects devices (Felix Daveys iPhone 8 Plus). The Scenario: Terror attacks were planned for Southport, NC in June of 2023. Russell, the primary suspect, lives locally in that area and seems...

27/10/2023 Friday Android installed applications records refer to the data and information stored on an Android device about the software applications installed on it. Android installed application is one of the generic android OS artifacts. The artifact contains information related to installed Applications in the android device. These records include details about the names of installed apps, their version numbers, installation dates, and other relevant information. Digital Forensics Value of ...

Salvation DATA

Work Tips 2023-10-26 Content Overview Common Causes of Partition Loss Case Study Notes Content Overview Common Causes of Partition Loss Case Study Notes Overview Partition is a continuous disk area logically divided by a storage device. In the computer, the operating system also assigns a drive letter to each normal partition, such as C, D, E, etc. Dividing the hard disk into one or more partitions makes it more convenient for investigators to install the operating system, store and manage data....

Taz Wake

Linux incident response - understanding endianess Report this article Taz Wake Taz Wake Cyber security incident response | Threat hunting | Digital forensics | Certified SANS instructor & course author | I am not looking for any new certification training... Published Oct 25, 2023 + Follow Endianess is a concept related to how multibyte data is stored in computer memory. Computers store data in bytes, which are made up of smaller units called bits (usually 8 bits in a byte). When multibyte data ...