解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 05 – 2024 - SOFTWARE UPDATES

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。

SOFTWARE UPDATES

Brim

v1.6.0 Latest Latest Compare Choose a tag to compare View all tags philrz released this 29 Jan 23:55 v1.6.0 7b324f1 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: B5690EEEBB952194 Learn about vigilant mode. Visit the Brim Data download page page to find the package for your platform. Update Zed to v1.13.0 Update Brimcap to v1.6.0, which includes a new Zeek v6.0.3-brim1 Update Electron dependency to 28.0.0 (#2934, #2953) Enhance the Zui Installation...

Costas K

Latest Latest Compare Choose a tag to compare View all tags kacos2000 released this 28 Jan 16:01 v.1.0.77.0 28e81f8 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: B5690EEEBB952194 Learn about vigilant mode. [Minor Update] MD5: DD2A6ACC51C9B5BBE271029A2CE4416F SHA256: 51DE50EE7DB7E1F70AD94F464AF599E3655A034D4D383B532E1BF39CB0944170 Assets 3 All reactions Footer © 2024 GitHub, Inc. Footer navigation Terms Privacy Security Status Docs Contact Manage c...

Latest Latest Compare Choose a tag to compare View all tags kacos2000 released this 28 Jan 15:40 v.0.0.12.0 2f60015 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: B5690EEEBB952194 Learn about vigilant mode. [Updates] Added option to save the Prefetch/Superfetch properties to a JSON file Other minor updates MD5: 674E9EB75F5DBFF73C08F8DA74A46FEA SHA256: 2779A2FAA40ABB2A9C595F68AEE96FEBFF8EA9CAA8AC2C8BC47026CA141E85F7 Assets 3 All reactions Footer © 2...

Latest Latest Compare Choose a tag to compare View all tags kacos2000 released this 03 Feb 15:53 v.1.0.10.0 b30486c This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: B5690EEEBB952194 Learn about vigilant mode. [Updates] Added support for extensions [BEEF000B] & [BEEF001D] etc: Currently supported HKCU keys : 'Software\Microsoft\Windows\Shell\BagMRU' 'Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU' 'Software\Microsoft\Windows\C...

Crowdstrike

Skip to content Toggle navigation Sign in Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Resources Learning Pathways...

CyberChef

10.6.0 Latest Latest Compare Choose a tag to compare View all tags a3957273 released this 03 Feb 14:51 · 16 commits to master since this release v10.6.0 df151ea See the CHANGELOG and commit messages for details. Assets 3 👍 5 madduci, NOTgate, m4x10187, QAInsights, and BackSpace54 reacted with thumbs up emoji 😄 1 NOTgate reacted with laugh emoji 🎉 5 NOTgate, Surendrajat, m4x10187, smlx, and brggs reacted with hooray emoji ❤️ 4 NOTgate, sbro101, m4x10187, and RomelSan reacted with heart emoji 🚀 2 ...

Digital Sleuth

Skip to content Toggle navigation Sign in Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Resources Learning Pathways...

Skip to content Toggle navigation Sign in Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Resources Learning Pathways...

Elcomsoft

Enhanced support for legacy devices Elcomsoft iOS Forensic Toolkit 8.53 enhances support for legacy Apple devices, adding the ability to mount HFS images in Windows. In addition, the update brings multiple fixes in HFS extractions and general reliability enhancements. iOS Forensic Toolkit 8.53 introduces improved low-level extraction and analysis capabilities for older Apple devices utilizing a 32-bit architecture. This update brings the ability to seamlessly mount HFS disk images extracted from...

ExifTool

ExifTool Version History RSS feed: //exiftool.org/rss.xml Note: The most recent production release is Version 12.76. (Other versions are considered development releases, and are not uploaded to MetaCPAN.) Jan. 31, 2024 - Version 12.76 (production release) Properly implement patch of 12.45 to avoid duplicating raw data when writing Sony ARW images where the raw data is double-referenced as both strips and tiles Improved handling of bad offsets in HtmlDump output Jan. 30, 2024 - Version 12.75 (pro...

ExifTool Version History RSS feed: //exiftool.org/rss.xml Note: The most recent production release is Version 12.76. (Other versions are considered development releases, and are not uploaded to MetaCPAN.) Jan. 31, 2024 - Version 12.76 (production release) Properly implement patch of 12.45 to avoid duplicating raw data when writing Sony ARW images where the raw data is double-referenced as both strips and tiles Improved handling of bad offsets in HtmlDump output Jan. 30, 2024 - Version 12.75 (pro...

Magnet Forensics

Scanning, and More Magnet AXIOM 7.9 is here, our first monthly release of 2024! We’ve added new features and functionality to help you work as efficiently as possible and save time in your investigations: Device Information Quick Report – Quickly gather device information and identifiers for the evidence sources in your case in a concise report right from AXIOM’s case dashboard. Improved Video Processing Performance – Improvements to performance and review ofvideo evidence. Improved File and Fol...

New Custom Fields, and More The release of Magnet AXIOM Cyber 7.9 is here, and it’s an exciting one for digital forensic examiners who support eDiscovery stakeholders. In this release, we’ve made several enhancements, including: Chat Artifact Linking in Load Files Improved Mobile Processing Speeds Improved Video Processing Performance Add Custom Fields to a Portable Case We’ve also updated and added to our artifact support (updates are at the end of this blog.) Upgrade to AXIOM Cyber 7.9 within ...

Mandiant

Skip to content Toggle navigation Sign in Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Resources Learning Pathways...

MasterParser

Latest Latest Compare Choose a tag to compare View all tags YosfanEilay released this 04 Feb 13:52 · 5 commits to main since this release v2.2 bcc65f1 Feature Update Assets 2 All reactions Footer © 2024 GitHub, Inc. Footer navigation Terms Privacy Security Status Docs Contact Manage cookies Do not share my personal information You can’t perform that action at this time.

Florian Roth at Nextron Systems

Announcing the Launch of Analysis Cockpit v4.0 by Florian Roth | Feb 1, 2024 We are pleased to announce the release of Analysis Cockpit v4.0, marking a significant update from version 3.10. This latest version introduces key improvements, including restructured database indices for enhanced performance, an upgraded operating system, and advancements in time synchronization and user interface. Aimed at delivering a more stable and efficient experience, v4.0 is built to better meet the technical n...

OpenCTI

Version 5.12.29 Latest Latest Compare Choose a tag to compare View all tags Filigran-Automation released this 03 Feb 09:12 · 26 commits to master since this release 5.12.29 ca5b8c6 This commit was signed with the committer’s verified signature. SamuelHassine Samuel Hassine GPG key ID: 966CA4FD74C31B9B Learn about vigilant mode. Bug Fixes: #5794 AWS Role authentication broken after library upgrade Full Changelog: 5.12.28...5.12.29 Assets 4 All reactions Footer © 2024 GitHub, Inc. Footer navigatio...

Passmark Software

Home Products Training Support About Us Forum Sign In FAQ What’s New Pricing Download Free Trial Buy Now What's New? Expand all Collapse all V11.0 build 1002 2nd February 2024 Android Artifacts Added icon for MMS audio files Added duration display to audio and video files Added device serial number to main window Changed the order of the counters in OSFExtract to match the order in which we collect the data Changed the collection dialog elements order Changed default file viewer tab for opening ...

Sigma

Latest Latest Compare Choose a tag to compare View all tags github-actions released this 29 Jan 18:30 · 3 commits to master since this release r2024-01-29 be359ef This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: B5690EEEBB952194 Learn about vigilant mode. New Rules new: CodePage Modification Via MODE.COM new: CodePage Modification Via MODE.COM To Russian Language new: HackTool - EDRSilencer Execution - Filter Added new: HackTool - SharpMove Tool Exec...

v0.11.3 Latest Latest Compare Choose a tag to compare View all tags thomaspatzke released this 29 Jan 23:01 v0.11.3 ce62623 What's Changed Updated packaging and jinja2 pinned versions by @slincoln-aiq in #188 Validators are now aware about correlation rule and pass if not applicable on these. Fixed duplicate file name validator detecting multiple rules in a single file as issue. Full Changelog: v0.11.2...v0.11.3 Contributors slincoln-aiq Assets 2 All reactions Footer © 2024 GitHub, Inc. Footer n...

Volatility Foundation

Latest Latest Compare Choose a tag to compare View all tags ikelos released this 31 Jan 21:35 · 46 commits to develop since this release v2.5.2 d2f7b41 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: B5690EEEBB952194 Learn about vigilant mode. New Layers: Amazon S3 support Google Cloud Storage support New plugins: linux.vmayarascan windows.mftscan.ads New features: Dumping of Elf files added to the elfs plugin Improvements to ELF support Bugfixes to...

Xorhex

Mlget README Home Blog Categories Mlget ReadME Share Search Share PostTwitterFacebookRedditLinkedInEmailxorhexFocus on Threat Research Things.Mlget READMEJanuary 1, 0001xorhex4-Minute ReadMlgetMlget is designed to fetch malware from a variety of sources so that you don’t have to manually hunt for a hash everywhere.SourceReleasesLicense TypeMIT LicenseVersion This ReadMe Matchesv3.4.1SourcesThese are the services that Mlget can query. The version number corresponds to the version release number o...