解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 49 – 2023 - FORENSIC ANALYSIS

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。

FORENSIC ANALYSIS

Emi Polito at Amped

Emi Polito November 28, 2023 Happy Tuesday everyone and welcome to our fourteenth installment of the “Learn and solve it with Amped FIVE” series. This week we will discuss how to increase the exposure of dark footage. Contents 1 Why Is It So Dark? 2 A Little Variation of Pixel Values Can Go a Long Way 3 Nothing We Can Do! 4 Limited vs. Full-Color Range in Videos 5 Increasing Exposure in Amped FIVE 6 Smart Adjust 7 Conclusions Why Is It So Dark? Dark images and videos can cause us many problems w...

Cyber Triage

Derek Eiri

In Search of Extraction Techniques for Pair-Locked iOS Devices Derek Eiri digital forensics 2023-11-202023-11-21 In my experience, extracting data from supervised iOS devices in a corporate environment has presented unique challenges to collect data. Supervision is intended to provide organizations control over the iOS devices it owns. This may include ensuring appropriate use consistent with a corporate policy. For example, not allowing iCloud backups, disabling AirDrop, and not allowing iCloud...

Oleg Afonin at Elcomsoft

November 30th, 2023 by Oleg AfoninCategory: «General» The latest update of iOS Forensic Toolkit brought an all-new Linux edition, opening up a world of possibilities in mobile device analysis. The highly anticipated Linux edition preserves and expands the features previously available to macOS and Windows users. Forensic professionals can now perform advanced logical and low-level extractions with the aid of a custom extraction agent and extract information using the bootloader-level exploit, ma...

November 30th, 2023 by Oleg AfoninCategory: «General» The latest update to the iOS Forensic Toolkit has expanded data extraction support for older models of Apple Watch, introducing low-level extraction capabilities for Apple Watch Series 0, Series 1, and Series 2. In a landscape where new devices are released on a yearly schedule, we stand committed to a balanced approach. While it’s easy for many to dismiss older devices, we recognize their significance as they frequently reappear in the labs ...

Forensafe

01/12/2023 Friday Viber PC is a Japanese corporation Rakuten's that provides cross-platform voice-over IP (VoIP) and instant messaging (IM) web service. Android Viber allows users to send any kind of message such as text, video, contact info, and audio, and to exchange and share data with other users. In addition to that, Viber is available on Windows, macOS, Linux, Android, and iOS devices. Digital Forensics Value of Android Viber Android Viber artifacts provide information about phone/video ca...

Ian Whiffin at DoubleBlak

Ian Whiffin Posted: 24th November 2023 Tweet #share I’ve had a few questions recently about the BrowserState.db database on iOS that caused me to dig a little deeper into this source and this blog will share the findings along with demonstrating a feature of the upcoming version of ArtEx (2.8.0.0). The Problem The request has always revolved around the accuracy of the timestamp that can be found in the last_viewed_time field of the TABS table of the BrowserState.db database. This timestamp value...

Kevin Pagano at Stark 4N6

Posted by Kevin Pagano December 01, 2023 Get link Facebook Twitter Pinterest Email Other Apps Shortlink: startme.stark4n6.comQR Code:If people have suggestions for additions please feel free to shoot me a message on the app formerly known as Twitter (@KevinPagano3) or Mastodon.Blog FeedAbhiram's BlogBlue Crew ForensicsFancy ForensicsiOS Unified Logs - Lionel NotariJosh LemonRevo4n6Forensic ToolsBelkasoft T (Triage)EventTranscriptParserEvanole - HexordiaTeraLogger - A Teracopy history log parserM...

Megan Roddie

Dots do matter: Why dots in Gmail addresses impact Google Workspace investigationsMegan Roddie·Follow3 min read·2 days ago--ListenShareDots don’t matter in Gmail addresses… if you’re sending or receiving emails to a Gmail address with a “.” character in it. As the Gmail Help Center article explains:If someone accidentally adds dots to your address when emailing you, you’ll still get that email. For example, if your email is johnsmith@gmail.com, you own all dotted versions of your address:- john....

Salvation DATA

Work Tips 2023-11-29 Content Overview Different Types of Video Files Case Study In Summary Content Overview Different Types of Video Files Case Study In Summary Overview Video and DVR forensics is a sub-branch of digital forensics, it is the activity to identify, retrieve and analyze video and metadata from CCTV DVRs and surveillance systems in a forensically sound manner. The way videos and images are captured can have a dramatic impact on how people interpret what they see. In a criminal case,...