مهمترین پروسه های ویندوزی برای شکار تهدیدات(Threat Hunting)
https://www.socinvestigation.com/important-windows-processes-for-threat-hunting/
https://www.socinvestigation.com/important-windows-processes-for-threat-hunting/
Security Investigation - Be the first to investigate
Important Windows processes for Threat Hunting - Security Investigation
Introduction: The various processes that are running in a Windows computer. Some of the processes are parts of the operating system, while others are applications automatically launched at startup or manually by the user or hackers. Knowing What’s normal…
آموزش جرم یابی شبکه بخش اول
https://www.hackers-arise.com/single-post/2018/02/28/Network-Forensics-Part-1
https://www.hackers-arise.com/single-post/2018/02/28/Network-Forensics-Part-1
اگر دنبال یک ابزار خوب هستی که ردپاهات تو سیستم رو پاک کنی
یا علمی تر بگم یک ابزار عالی برای #AntiForensics
BLEACHBIT
این هم لینک این ابزار:
https://www.bleachbit.org/download
یا علمی تر بگم یک ابزار عالی برای #AntiForensics
BLEACHBIT
این هم لینک این ابزار:
https://www.bleachbit.org/download
یک منبع غنی از ابزار برای BlueTeam#
برای استفاده رایگان از لینک زیر استفاده نمایید
https://github.com/fabacab/awesome-cybersecurity-blueteam
برای استفاده رایگان از لینک زیر استفاده نمایید
https://github.com/fabacab/awesome-cybersecurity-blueteam
برای علاقمندان به Memory Forensic و عاشقان کشف نفوذ در سطح حافظه
معرفی میکنم یک ابزار در این حوزه
Memprocfs Hunter
This script is a memory forensic wrapper to https://github.com/ufrisk/MemProcFS for memory speed analysis. It's includes several hunting modules and ELK import with pre built hunting dashboards. It's have cool features like metadata and imports detection. Eventlog parsning. Yara and ClamAV to detect malicious files and memory injection detection
معرفی میکنم یک ابزار در این حوزه
Memprocfs Hunter
This script is a memory forensic wrapper to https://github.com/ufrisk/MemProcFS for memory speed analysis. It's includes several hunting modules and ELK import with pre built hunting dashboards. It's have cool features like metadata and imports detection. Eventlog parsning. Yara and ClamAV to detect malicious files and memory injection detection
GitHub
GitHub - ufrisk/MemProcFS: MemProcFS
MemProcFS. Contribute to ufrisk/MemProcFS development by creating an account on GitHub.
MemProcFS Analyzer v0.3 releases: Automated Forensic Analysis of Windows Memory Dumps
https://lnkd.in/eefZE-He
https://lnkd.in/eefZE-He
MemLabs 🔍
MemLabs is an educational, introductory set of CTF-styled challenges which is aimed to encourage students, security researchers and also CTF players to get started with the field of Memory Forensics.
https://lnkd.in/emfHbdBe
MemLabs is an educational, introductory set of CTF-styled challenges which is aimed to encourage students, security researchers and also CTF players to get started with the field of Memory Forensics.
https://lnkd.in/emfHbdBe
Forwarded from SecCode (Meisam Monsef)
Media is too big
VIEW IN TELEGRAM
دموی دوره برنامه نویسی Android
با محوریت کنترل گوشی
قسمت 8
مدیریت فایل های گوشی
File Manager
ساخت فایل و پوشه
حذف و ویرایش نام فایل و پوشه
Tested On : Android 11 (without root)
👍😎💀☠️🙀🤜💪
برای ثبت نام و خرید دوره پیام بدهید
@meisamrce
@dorsateam
با محوریت کنترل گوشی
قسمت 8
مدیریت فایل های گوشی
File Manager
ساخت فایل و پوشه
حذف و ویرایش نام فایل و پوشه
Tested On : Android 11 (without root)
👍😎💀☠️🙀🤜💪
برای ثبت نام و خرید دوره پیام بدهید
@meisamrce
@dorsateam
یک دوره آموزشی فوق العاده از یکی از اساتید حرفه ای،
حتما موقع خرید اعلام کنید از کانال ما تا تخفیف شاما حالتون بشه
سپاس
👆👆👆👆👆
حتما موقع خرید اعلام کنید از کانال ما تا تخفیف شاما حالتون بشه
سپاس
👆👆👆👆👆
Feodo Tracker
is a project of abuse.ch with the goal of sharing botnet C&C servers associated with Dridex, Emotet (aka Heodo), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor). It offers various blocklists, helping network owners to protect their users from Dridex and Emotet/Heodo.
https://lnkd.in/ea3kGnCx
is a project of abuse.ch with the goal of sharing botnet C&C servers associated with Dridex, Emotet (aka Heodo), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor). It offers various blocklists, helping network owners to protect their users from Dridex and Emotet/Heodo.
https://lnkd.in/ea3kGnCx
برای علاقمندان به مبحث#threathunting از موسسهSANS
https://start.me/p/DP6oRw/sans-threat-hunting-2021
https://start.me/p/DP6oRw/sans-threat-hunting-2021