
makhno
@m4khno_
Security enthusiast, old papy CTF player and eternal n00b for @Beers4Flags, #forensic & #DFIR addict. I like pcap, logs and dump memory analysis
ID: 976017171141808128
20-03-2018 08:46:41
1,1K Tweet
822 Followers
263 Following

.volatility New Release: #volatility3 v2.5.0 - visit github.com/volatilityfoun… for details and downloads. #memoryforensics #dfir





My last #forensic chall The Brofessor , Maki , Jean Marsault & co are you amateur enough to test and succeed ?😇😋😘


Time to make volatility 3 compatible with modern Windows hibernation file analysis. Blog post : forensicxlab.com/posts/hibernat… Feature : tinyurl.com/5n8u4nr9 Special thanks to Chad Tilbury who gave me the motivation and Joe Sylve 🐘 @[email protected], Vico Marziale, Golden G. Richard III for the incredible work


MFT records and therefore alternate data streams (ADS) can be carved from a memory image. Here is a volatility 3 plugin added to mftscan in order to extract ADS: Look for downloaded files via Zone.Identifier and potential malicious code! Blog Post : forensicxlab.com/posts/volads/


Analysis of the Import Address Table of a process in memory can be useful when performing Digital Forensic and Reverse Malware Engineering. Here is a volatility 3 plugin to extract the IAT. Merry Christmas! Blog Post : forensicxlab.com/posts/voliat/




New lab 🏰 for the GOAD project 🥳: SCCM You can now test the SCCM/MECM attacks locally on Virtualbox or Vmware. More information here: mayfly277.github.io/posts/SCCM-LAB… Repository here : github.com/Orange-Cyberde… Thx again Kenji Endo for your help to building this !


Exciting news: VolWeb 2.0 is out! This digital forensics memory analysis platform leverages the capabilities of volatility 3 framework. With significant enhancements, it now offers improved flexibility and scalability! github.com/k1nd0ne/VolWeb. 1/8




Aujourd'hui, nous vous avons révélé le projet confidentiel à « 150 millions d’euros » du milliardaire Pierre-Edouard Stérin pour faire gagner le RN. Notre journaliste Thomas Lemahieu vous explique le dossier. Nos révélations ➡️ l.humanite.fr/A4Y