makhno (@m4khno_) 's Twitter Profile
makhno

@m4khno_

Security enthusiast, old papy CTF player and eternal n00b for @Beers4Flags, #forensic & #DFIR addict. I like pcap, logs and dump memory analysis

ID: 976017171141808128

calendar_today20-03-2018 08:46:41

1,1K Tweet

822 Followers

263 Following

Catarina de Faria (@c_defaria) 's Twitter Profile Photo

As part of the research my colleagues and I presented at #DFIREurope23 🇨🇿 (github.com/WithSecureLabs…), I updated Chainsaw. It is now capable of analysing SRUM databases and providing new forensic insights 💡(see github.com/WithSecureLabs…) #chainsaw #dfir #SRUM #WithSecure #SANS

As part of the research my colleagues and I presented at #DFIREurope23 🇨🇿 (github.com/WithSecureLabs…), I updated Chainsaw. It is now capable of analysing SRUM databases and providing new forensic insights 💡(see github.com/WithSecureLabs…)
#chainsaw #dfir #SRUM #WithSecure #SANS
Mari Degrazia (@maridegrazia) 's Twitter Profile Photo

I have a new blog post up detailing per app registry hives for analysis in #DFIR investigations related to MSIX Registry Redirection. These hives can contain additional information that may not be found in other locations. ZeroFox SANS DFIR zerofox.com/blog/the-regis…

I have a new blog post up detailing per app registry hives for analysis in #DFIR investigations related to MSIX Registry Redirection. These hives can  contain additional information that may not be found in other  locations.  <a href="/ZeroFox/">ZeroFox</a>  <a href="/sansforensics/">SANS DFIR</a>  zerofox.com/blog/the-regis…
k1nd0ne (@k1nd0ne) 's Twitter Profile Photo

Time to make volatility 3 compatible with modern Windows hibernation file analysis. Blog post : forensicxlab.com/posts/hibernat… Feature : tinyurl.com/5n8u4nr9 Special thanks to Chad Tilbury who gave me the motivation and Joe Sylve 🐘 @[email protected], Vico Marziale, Golden G. Richard III for the incredible work

Mattia Epifani (@mattiaep) 's Twitter Profile Photo

iOS 15 Image Forensics Analysis and Tools Comparison - Native Apps blog.digital-forensics.it/2023/10/ios-15… #DFIR #mobileforensics

k1nd0ne (@k1nd0ne) 's Twitter Profile Photo

MFT records and therefore alternate data streams (ADS) can be carved from a memory image. Here is a volatility 3 plugin added to mftscan in order to extract ADS: Look for downloaded files via Zone.Identifier and potential malicious code! Blog Post : forensicxlab.com/posts/volads/

k1nd0ne (@k1nd0ne) 's Twitter Profile Photo

Analysis of the Import Address Table of a process in memory can be useful when performing Digital Forensic and Reverse Malware Engineering. Here is a volatility 3 plugin to extract the IAT. Merry Christmas! Blog Post : forensicxlab.com/posts/voliat/

Root-Me (@rootme_org) 's Twitter Profile Photo

For Christmas 2023, Root-Me has decided to thank its favorite hackers! 🥳 Two prize packages including XXL mouse pads, mugs, stickers, flags, and pins are up for grabs ! 🎁 To participate, it's as simple as : - Follow Root-Me - RT 🔃 this post - Being verified on the

For Christmas 2023, Root-Me has decided to thank its favorite hackers! 🥳
Two prize packages including XXL mouse pads, mugs, stickers, flags, and pins are up for grabs ! 🎁

To participate, it's as simple as :

- Follow <a href="/rootme_org/">Root-Me</a> 
- RT 🔃 this post
- Being verified on the
Clandestine (@akaclandestine) 's Twitter Profile Photo

#tools #Blue_Team_Techniques 1. Sigma rules for Linux and MacOS blog.virustotal.com/2023/12/sigma-… 2. The multi-platform memory acquisition tool ]-> Win7-10: github.com/Velocidex/WinP… ]-> Linux x64: github.com/Velocidex/Linp…

HackGit (@hack_git) 's Twitter Profile Photo

forensictools A toolkit designed for digital #forensics, offering a wide array of tools. Its primary goal is to simplify the creation of a virtual environment for conducting forensic examinations. github.com/cristianzsh/fo… #cybersecurity #infosec

forensictools

A toolkit designed for digital #forensics, offering a wide array of tools. Its primary goal is to simplify the creation of a virtual environment for conducting forensic examinations.

github.com/cristianzsh/fo…

#cybersecurity #infosec
Mayfly (@m4yfly) 's Twitter Profile Photo

New lab 🏰 for the GOAD project 🥳: SCCM You can now test the SCCM/MECM attacks locally on Virtualbox or Vmware. More information here: mayfly277.github.io/posts/SCCM-LAB… Repository here : github.com/Orange-Cyberde… Thx again Kenji Endo for your help to building this !

New lab 🏰 for the GOAD project 🥳: SCCM
You can now test the SCCM/MECM attacks locally on Virtualbox or Vmware.

More information here:
mayfly277.github.io/posts/SCCM-LAB…

Repository here : github.com/Orange-Cyberde…

Thx again <a href="/KenjiEndo15/">Kenji Endo</a> for your help to building this !
k1nd0ne (@k1nd0ne) 's Twitter Profile Photo

Exciting news: VolWeb 2.0 is out! This digital forensics memory analysis platform leverages the capabilities of volatility 3 framework. With significant enhancements, it now offers improved flexibility and scalability! github.com/k1nd0ne/VolWeb. 1/8

Olivier Tesquet (@oliviertesquet) 's Twitter Profile Photo

En novembre dernier, Disclose révélait l’utilisation illégale d’un logiciel de reconnaissance faciale par la police. Darmanin promettait une enquête indépendante et des conclusions rendues publiques sous trois mois. Depuis, c’est silence radio. disclose.ngo/fr/article/rec…

L'Humanité (@humanite_fr) 's Twitter Profile Photo

Aujourd'hui, nous vous avons révélé le projet confidentiel à « 150 millions d’euros » du milliardaire Pierre-Edouard Stérin pour faire gagner le RN. Notre journaliste Thomas Lemahieu vous explique le dossier. Nos révélations ➡️ l.humanite.fr/A4Y