解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 22 – 2024 - SOFTWARE UPDATES

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。

SOFTWARE UPDATES

Amped

Emi Polito May 29, 2024 Reading time: 5 min We are thrilled to announce the newest release of Amped Replay! We have now added motion detection to aid and speed up your video investigations. Also, we added the ability to resize panels and improved support for audio. Don’t wait, update today! Hello everybody and welcome back to another exciting release of Amped Replay! Your favorite forensic video player is now gathering momentum in the digital forensic community. It is now becoming the go-to play...

Canadian Centre for Cyber Security

Skip to content Navigation Menu Toggle navigation Sign in Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Resources L...

Crowdstrike

Public Notifications You must be signed in to change notification settings Fork 2 Star 43 VirtualGHOST Detection Tool License MIT license 43 stars 2 forks Branches Tags Activity Star Notifications You must be signed in to change notification settings Code Issues 0 Pull requests 0 Projects 0 Security Insights Additional navigation options Code Issues Pull requests Projects Security Insights CrowdStrike/VirtualGHOST This commit does not belong to any branch on this repository, and may belong to a ...

Datadog Security Labs

Skip to content Navigation Menu Toggle navigation Sign in Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Resources L...

Digital Sleuth

Skip to content Navigation Menu Toggle navigation Sign in Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Resources L...

Erik Hjelmvik at Netresec

NetworkMiner 2.9 brings several new and improved features to help analysts make sense of network traffic from malware, criminals and industrial control systems. Highlights from this new version include: TZSP supportStealC extractorImproved Modbus parserJA4 supportGTP decapsulation Malware Traffic Artifact Extraction NetworkMiner is a popular tool for extracting artifacts from malware traffic. Such artifacts can be downloaded malware modules, exfiltrated documents and sometimes even screenshots o...

Hex Rays

Posted on: 27 May 2024 By: Alex Petrov Categories: News Tags: IDA We are pleased to announce that IDA 8.4 Service Pack 2 (SP2) is now available for download! This latest release includes mostly bug fixes. How to request the new versions All new versions are free for users with an active support plan. Please use the “Help < Check for free update” menu item in IDA. It is also possible to configure automatic checks of new versions. Alternatively, you can submit your ida.key, and our servers will pr...

Mazars Tech

Skip to content Navigation Menu Toggle navigation Sign in Product Actions Automate any workflow Packages Host and manage packages Security Find and fix vulnerabilities Codespaces Instant dev environments Copilot Write better code with AI Code review Manage code changes Issues Plan and track work Discussions Collaborate outside of code Explore All features Documentation GitHub Skills Blog Solutions For Enterprise Teams Startups Education By Solution CI/CD & Automation DevOps DevSecOps Resources L...

OpenCTI

Version 6.1.8 Latest Latest Compare Choose a tag to compare View all tags Filigran-Automation released this 31 May 18:06 6.1.8 7cea4ce This commit was signed with the committer’s verified signature. Filigran-Automation Filigran Automation GPG key ID: C708FDB840E80D34 Learn about vigilant mode. Bug Fixes: #7202 Add keyPrefix for sentinel mode Pull Requests: [backend] Add keyPrefix for sentinel redis mode by @Kedae in #7203 Full Changelog: 6.1.7...6.1.8 Contributors Kedae Assets 4 All reactions Fo...

Passware

May 28, 2024 Product Update Passware introduces GPU-accelerated passcode recovery and data extraction for Unisoc- based smartphones. This update supports over 170 models from various manufacturers. Continue Reading Passware Kit 2024 v2 Now Available April 04, 2024 Product Update Passware Kit introduces a built-in resource management tool that allows forensic examiners to easily configure, manage, and monitor a cluster of Passware Kit Agents. The device decryption functionality has been expanded,...

Volatility Foundation

Latest Latest Compare Choose a tag to compare View all tags ikelos released this 29 May 19:45 · 17 commits to develop since this release v2.7.0 b365941 This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: B5690EEEBB952194 Learn about vigilant mode. New plugins: windows.iat windows.truecrypt linux.library_list mac.dmesg Support for configuration files for common CLI options windows.driverirp: Report IRP entries that point inside a hidden module windows.th...

Security Onion

Security Onion 2.4.70 is now available! It includes some new features for our fellow defenders including our new Detections interface to help you take your detection engineering capabilities to the next level!Security Onion is a cybersecurity platform built by defenders for defenders. For this release, we spent several MONTHS thinking through the defender workflow specifically around detection engineering. This resulted in a new interface called Detections that makes it super simple to tune your...

Thiago Canozzo Lahr

Latest Latest Compare Choose a tag to compare View all tags tclahr released this 28 May 11:49 v2.9.0 1105a8e This commit was created on GitHub.com and signed with GitHub’s verified signature. GPG key ID: B5690EEEBB952194 Learn about vigilant mode. Changelog 2.9.0 (2024-05-28) Features uac.log and uac.log.stderr files were moved to the front of the output archive file (by rbcrwd). Artifacts files/logs/macos.yaml: Updated collection support for auditd logs [macos] (by Pierre-Gronau-ndaal). files/l...

Xways

X-Ways Forensics 21.0 Log Out | Topics | Search Moderators | Edit Profile X-Ways User Forum » Public Announcements » X-Ways Forensics 21.0 « Previous Next » Author Message Stefan Fleischmann Username: adminRegistered: 1-2001Posted on Tuesday, Sep 5, 2023 - 4:19: A preview version of X-Ways Forensics 21.0 is now available. The URL of the download directory for all recent versions can be retrieved by querying one's license status as always. What's new in v21.0 Preview 1? * Ability to access the co...

X-Ways Forensics 21.1 Log Out | Topics | Search Moderators | Edit Profile X-Ways User Forum » Public Announcements » X-Ways Forensics 21.1 « Previous Next » Author Message Stefan Fleischmann Username: adminRegistered: 1-2001Posted on Sunday, Jan 21, 2024 - 15:38: A preview version of X-Ways Forensics 21.1 is now available. The latest download instructions including password can be retrieved by querying one's license status, as always. What's new in v21.1 Preview 1? * Better support for larger vo...

X-Ways Forensics 21.2 Log Out | Topics | Search Moderators | Edit Profile X-Ways User Forum » Public Announcements » X-Ways Forensics 21.2 « Previous Next » Author Message Stefan Fleischmann Username: adminRegistered: 1-2001Posted on Friday, Apr 19, 2024 - 16:20: A preview version of X-Ways Forensics 21.2 is now available. The latest download instructions including password can be retrieved by querying one's license status, as always. What's new in v21.2 Preview? * The limit of ~2 billion hash v...

YARA

Latest Latest Compare Choose a tag to compare View all tags plusvic released this 25 May 14:24 · 2 commits to master since this release v4.5.1 0e5b6bb Allow spaces in regexp repetition operators (e.g: {n, m}). BUGFIX: matches operator was not matching empty strings (#c80cd9d). BUGFIX: Several bugs in array type handling in dotnet module (#2064). BUGFIX: Fix issue while parsing .NET files (5bf72f2). BUGFIX: Fix issues while parsing PE resources (c009195, 4793b49). BUGFIX: Infinite loop while pars...