volexity · @volexity
283 followers · 17 posts · Server infosec.exchange

@volexity details how to use to detect EDR-nullifying malware. This latest blog post uses the malware, first documented by @TrendMicro, as an example. Read more here: volexity.com/blog/2023/03/07/u

ย 

#memoryanalysis #avburner #dfir #threatintel

Last updated 2 years ago

Antonio Sanz · @antoniosanzalc
284 followers · 280 posts · Server infosec.exchange

RT @Evild3ad79@twitter.com

MemProcFS-Analyzer v0.8 released! Updated User Interface w/ Status Bar and better OS Fingerprinting (incl. DC and Exchange). Added MUICache, BAM, Process Lineage Analysis, and much more analytics.
github.com/evild3ad/MemProcFS-

๐Ÿฆ๐Ÿ”—: twitter.com/Evild3ad79/status/

#memprocfs #memoryanalysis #dfir

Last updated 2 years ago

Stephan Berger · @malmoeb
571 followers · 172 posts · Server infosec.exchange

RT @Evild3ad79@twitter.com

MemProcFS-Analyzer v0.8 released! Updated User Interface w/ Status Bar and better OS Fingerprinting (incl. DC and Exchange). Added MUICache, BAM, Process Lineage Analysis, and much more analytics.
github.com/evild3ad/MemProcFS-

๐Ÿฆ๐Ÿ”—: twitter.com/Evild3ad79/status/

#memprocfs #memoryanalysis #dfir

Last updated 2 years ago

๐Ÿฆ‡missa๐Ÿฆ‡ · @sphynx
563 followers · 87 posts · Server infosec.exchange

Since I started my with SANS, I have taken some GREAT classes and learned so much, but THIS class is one of the top two Iโ€™ve been looking forward to the most (the other being FOR610/GREM planned for this summer)!

I am so excited to get started on - Advanced , , and - and prepare for my this Spring!

Since Thanksgiving, Iโ€™ve also been working my way through a backlog of technical books I have, occasionally reference, but never dove into completely. Iโ€™m remedying that this year and made a promise to myself to sit down and read/work through my bookshelf. I can say that Iโ€™m already seeing the benefits of that effort, unlocking a few โ€œa ha!โ€ moments and further helping me refine my future professional plans.

When I took my first security class years ago, I immediately fell in love with the field. I knew I needed to do this with my career. I have found that feeling again in the last quarter as I spend more time studying and . I took a really nontraditional path into these disciplines, and I have a lot of gaps in knowledge Iโ€™m constantly filling in, but I *love* learning this stuff.

Over 2/3 of the way through my mastersโ€ฆ. The academic end is in sight, but the learning opportunities are infinite :)

#msise #for508 #incidentresponse #threathunting #digitalforensics #GCFA #memoryanalysis #reverseengineering

Last updated 2 years ago

Antonio Sanz · @antoniosanzalc
275 followers · 251 posts · Server infosec.exchange

RT @msuiche@twitter.com

๐Ÿš€๐Ÿš€๐Ÿš€๐Ÿš€๐Ÿš€๐Ÿš€๐Ÿš€๐Ÿš€๐Ÿš€๐Ÿš€๐Ÿš€

DumpIt is now available as a Magnet Free Tools! Tell your friends, so they stop using unofficial builds ๐Ÿ˜‚

twitter.com/magnetforensics/st

๐Ÿฆ๐Ÿ”—: twitter.com/msuiche/status/161

#memoryanalysis

Last updated 2 years ago

volexity · @volexity
221 followers · 2 posts · Server infosec.exchange

Volexityโ€™s Robert Jan Mora was quoted in this article about the Bhima Koregaon case: washingtonpost.com/world/2022/. Perhaps one of the most interesting examples of a โ€œtrojan did itโ€ scenario, the investigation shows why is critical for reconstructing the state of a compromised system.

#memoryanalysis

Last updated 2 years ago

volexity · @volexity
255 followers · 8 posts · Server infosec.exchange

Volexityโ€™s Robert Jan Mora was quoted in this article about the Bhima Koregaon case: washingtonpost.com/world/2022/. Perhaps one of the most interesting examples of a โ€œtrojan did itโ€ scenario, the investigation shows why is critical for reconstructing the state of a compromised system.

#memoryanalysis

Last updated 2 years ago

Beercow :verified: · @Beercow
54 followers · 21 posts · Server infosec.exchange

On the Digital Forensics Discord server the question came up on how to create a Windows profile for Volatility 2. Quick show of hands on who would be interested in a write up.

#dfir #volatility #memoryanalysis

Last updated 2 years ago

Jamie Levy ๐Ÿฆ‰ · @gleeda
805 followers · 178 posts · Server infosec.exchange