Forwarded from cissp (Alireza Ghahrood)
Videos
• The Future of Incident Response - Presented by Bruce Schneier at OWASP AppSecUSA 2015.
Windows Evidence Collection
• AChoir - Framework/scripting tool to standardize and simplify the process of scripting live acquisition utilities for Windows.
• Crowd Response - Lightweight Windows console application designed to aid in the gathering of system information for incident response and security engagements. It features numerous modules and output formats.
• DFIR ORC - DFIR ORC is a collection of specialized tools dedicated to reliably parse and collect critical artifacts such as the MFT, registry hives or event logs. DFIR ORC collects data, but does not analyze it: it is not meant to triage machines. It provides a forensically relevant snapshot of machines running Microsoft Windows. The code can be found on GitHub.
• FastIR Collector - Tool that collects different artifacts on live Windows systems and records the results in csv files. With the analyses of these artifacts, an early compromise can be detected.
• Fibratus - Tool for exploration and tracing of the Windows kernel.
• Hoarder - Collecting the most valuable artifacts for forensics or incident response investigations.
• IREC - All-in-one IR Evidence Collector which captures RAM Image, $MFT, EventLogs, WMI Scripts, Registry Hives, System Restore Points and much more. It is FREE, lightning fast and easy to use.
• Invoke-LiveResponse - Invoke-LiveResponse is a live response tool for targeted collection.
• IOC Finder - Free tool from Mandiant for collecting host system data and reporting the presence of Indicators of Compromise (IOCs). Support for Windows only. No longer maintained. Only fully supported up to Windows 7 / Windows Server 2008 R2.
• IRTriage - Incident Response Triage - Windows Evidence Collection for Forensic Analysis.
• KAPE - Kroll Artifact Parser and Extractor (KAPE) by Eric Zimmerman. A triage tool that finds the most prevalent digital artifacts and then parses them quickly. Great and thorough when time is of the essence.
• LOKI - Free IR scanner for scanning endpoint with yara rules and other indicators(IOCs).
• MEERKAT - PowerShell-based triage and threat hunting for Windows.
• Panorama - Fast incident overview on live Windows systems.
• PowerForensics - Live disk forensics platform, using PowerShell.
• PSRecon - PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained locally.
• RegRipper - Open source tool, written in Perl, for extracting/parsing information (keys, values, data) from the Registry and presenting it for analysis
• The Future of Incident Response - Presented by Bruce Schneier at OWASP AppSecUSA 2015.
Windows Evidence Collection
• AChoir - Framework/scripting tool to standardize and simplify the process of scripting live acquisition utilities for Windows.
• Crowd Response - Lightweight Windows console application designed to aid in the gathering of system information for incident response and security engagements. It features numerous modules and output formats.
• DFIR ORC - DFIR ORC is a collection of specialized tools dedicated to reliably parse and collect critical artifacts such as the MFT, registry hives or event logs. DFIR ORC collects data, but does not analyze it: it is not meant to triage machines. It provides a forensically relevant snapshot of machines running Microsoft Windows. The code can be found on GitHub.
• FastIR Collector - Tool that collects different artifacts on live Windows systems and records the results in csv files. With the analyses of these artifacts, an early compromise can be detected.
• Fibratus - Tool for exploration and tracing of the Windows kernel.
• Hoarder - Collecting the most valuable artifacts for forensics or incident response investigations.
• IREC - All-in-one IR Evidence Collector which captures RAM Image, $MFT, EventLogs, WMI Scripts, Registry Hives, System Restore Points and much more. It is FREE, lightning fast and easy to use.
• Invoke-LiveResponse - Invoke-LiveResponse is a live response tool for targeted collection.
• IOC Finder - Free tool from Mandiant for collecting host system data and reporting the presence of Indicators of Compromise (IOCs). Support for Windows only. No longer maintained. Only fully supported up to Windows 7 / Windows Server 2008 R2.
• IRTriage - Incident Response Triage - Windows Evidence Collection for Forensic Analysis.
• KAPE - Kroll Artifact Parser and Extractor (KAPE) by Eric Zimmerman. A triage tool that finds the most prevalent digital artifacts and then parses them quickly. Great and thorough when time is of the essence.
• LOKI - Free IR scanner for scanning endpoint with yara rules and other indicators(IOCs).
• MEERKAT - PowerShell-based triage and threat hunting for Windows.
• Panorama - Fast incident overview on live Windows systems.
• PowerForensics - Live disk forensics platform, using PowerShell.
• PSRecon - PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained locally.
• RegRipper - Open source tool, written in Perl, for extracting/parsing information (keys, values, data) from the Registry and presenting it for analysis
YouTube
OWASP AppSecUSA 2014 - Keynote: Bruce Schneier - The Future of Incident Response
Live from AppSecUSA 2014 in Denver
http://2014.appsecusa.org/
Thursday, September 18 • 8:00am - 9:00am
Keynote: Bruce Schneier - The Future of Incident Response
Network attacks are inevitable. Protection and detection can only take you so far, and response…
http://2014.appsecusa.org/
Thursday, September 18 • 8:00am - 9:00am
Keynote: Bruce Schneier - The Future of Incident Response
Network attacks are inevitable. Protection and detection can only take you so far, and response…
Tool-X is a Kali Linux hacking tools installer for Termux and linux system
https://hakin9.org/tool-x-is-a-kali-linux-hacking-tools-installer-for-termux-and-linux-system/
https://hakin9.org/tool-x-is-a-kali-linux-hacking-tools-installer-for-termux-and-linux-system/
Hakin9 - IT Security Magazine
Tool-X is a Kali Linux hacking tools installer for Termux and linux system
Tool-X was developed for Termux and other android terminals. Using Tool-X, you can install almost 370+ hacking tools in Termux (android) and other Linux...
Forwarded from SecCode (Meisam Monsef)
دوره برنامه نویسی Android با جاوا به مناسبت ولادت با سعادت امام علی (ع) رایگان شد
کُلُّ وِعاءٍ یَضیقُ بِما جُعِلَ فیهِ إِلاّ وِعاءُ العِلمِ فَإِنَّهُ یَتَّسِعُ بِهِ؛
فضای هر ظرفی در اثر محتوای خود تنگتر میشود مگر ظرف دانش که با تحصیل علوم، فضای آن بازتر میگردد.
نهج البلاغه،ص۵۰۵
لینک های دانلود :
http://uploadb.me/728srg0v7mpm.html
http://uploadb.me/zblubfodwutn.html
http://uploadb.me/1y0v4mc3nuu7.html
http://uploadb.me/ac5lw86ac92p.html
http://uploadb.me/sud4wls7bns0.html
http://uploadb.me/e7c218fv56ru.html
http://uploadb.me/603u5wtp5l5z.html
http://uploadb.me/k8wo2enjxf9f.html
Password Zip : meisamAnd0rid$
دوستانی که از دوره استفاده میکنند برای سلامتی تمامی بیماران
یک صلوات بفرستند
با آرزوی سلامتی تمامی بیماران
@dorsateam
کُلُّ وِعاءٍ یَضیقُ بِما جُعِلَ فیهِ إِلاّ وِعاءُ العِلمِ فَإِنَّهُ یَتَّسِعُ بِهِ؛
فضای هر ظرفی در اثر محتوای خود تنگتر میشود مگر ظرف دانش که با تحصیل علوم، فضای آن بازتر میگردد.
نهج البلاغه،ص۵۰۵
لینک های دانلود :
http://uploadb.me/728srg0v7mpm.html
http://uploadb.me/zblubfodwutn.html
http://uploadb.me/1y0v4mc3nuu7.html
http://uploadb.me/ac5lw86ac92p.html
http://uploadb.me/sud4wls7bns0.html
http://uploadb.me/e7c218fv56ru.html
http://uploadb.me/603u5wtp5l5z.html
http://uploadb.me/k8wo2enjxf9f.html
Password Zip : meisamAnd0rid$
دوستانی که از دوره استفاده میکنند برای سلامتی تمامی بیماران
یک صلوات بفرستند
با آرزوی سلامتی تمامی بیماران
@dorsateam
Khepri
Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang and C++.
https://github.com/geemion/Khepri
Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang and C++.
https://github.com/geemion/Khepri
GitHub
GitHub - roadwy/RIP
Contribute to roadwy/RIP development by creating an account on GitHub.
Evil-WinRM: The ultimate WinRM shell for hacking/pentesting
Features
Load in memory Powershell scripts
Load in memory dll files bypassing some AVs
Load in memory C# (C Sharp) assemblies bypassing some AVs
Load x64 payloads generated with awesome donut technique
AMSI Bypass
Pass-the-hash support
Kerberos auth support
SSL and certificates support
Upload and download files
List remote machine services without privileges
Command History
WinRM command completion
Local files completion
Colorization on output messages (can be disabled optionally)
Docker support (prebuilt images available at Dockerhub)
https://hakin9.org/evil-winrm-the-ultimate-winrm-shell-for-hacking-pentesting/
Features
Load in memory Powershell scripts
Load in memory dll files bypassing some AVs
Load in memory C# (C Sharp) assemblies bypassing some AVs
Load x64 payloads generated with awesome donut technique
AMSI Bypass
Pass-the-hash support
Kerberos auth support
SSL and certificates support
Upload and download files
List remote machine services without privileges
Command History
WinRM command completion
Local files completion
Colorization on output messages (can be disabled optionally)
Docker support (prebuilt images available at Dockerhub)
https://hakin9.org/evil-winrm-the-ultimate-winrm-shell-for-hacking-pentesting/
Hakin9 - IT Security Magazine
404 - Hakin9 - IT Security Magazine
لیستی از ابزارهای شکار تهدیدات
Awesome Threat Detection and Hunting
https://github.com/0x4D31/awesome-threat-detection
Awesome Threat Detection and Hunting
https://github.com/0x4D31/awesome-threat-detection
GitHub
GitHub - 0x4D31/awesome-threat-detection: ✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️ - 0x4D31/awesome-threat-detection
FBI-tools Public
Tools for gathering information and actions forensic
https://github.com/danieldurnea/FBI-tools
Tools for gathering information and actions forensic
https://github.com/danieldurnea/FBI-tools
GitHub
GitHub - danieldurnea/FBI-tools: 🕵️ OSINT Tools for gathering information and actions forensics 🕵️
🕵️ OSINT Tools for gathering information and actions forensics 🕵️ - danieldurnea/FBI-tools
Welcome to FLARE VM - a fully customizable, Windows-based security distribution for malware analysis, incident response, penetration testing, etc.
https://github.com/mandiant/flare-vm
https://github.com/mandiant/flare-vm
GitHub
GitHub - mandiant/flare-vm: A collection of software installations scripts for Windows systems that allows you to easily setup…
A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM. - mandiant/flare-vm
Windows_PowerShell_Tutorial_for_Beginners_9.pdf
240.6 KB
افرادی که در حوزه blue Team کار میکنند، نیاز به دانش در خصوص پاورشل دارند،
یک راهنمای خوب برای کسانی که تازه کارتر هستند
Windows_PowerShell_Tutorial_for_Beginners - Page ۹.pdf
یک راهنمای خوب برای کسانی که تازه کارتر هستند
Windows_PowerShell_Tutorial_for_Beginners - Page ۹.pdf
Blinding EDR On Windows
My understanding of EDRs would not be possible without the help of many great security researchers. Below are some write-ups and talks that really helped me gain the understanding needed and hit the ground running on the research that will be presented here. If you are interested to go deeper, be sure to check out the following research (in no particular order):
https://synzack.github.io/Blinding-EDR-On-Windows/
My understanding of EDRs would not be possible without the help of many great security researchers. Below are some write-ups and talks that really helped me gain the understanding needed and hit the ground running on the research that will be presented here. If you are interested to go deeper, be sure to check out the following research (in no particular order):
https://synzack.github.io/Blinding-EDR-On-Windows/
Red Team Blog
Blinding EDR On Windows
Acknowledgements My understanding of EDRs would not be possible without the help of many great security researchers. Below are some write-ups and talks that really helped me gain the understanding needed and hit the ground running on the research that will…
نگاهی به شکار تهدیدات با بهره گیری sysmon
https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon
https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon
Shell is Only the Beginning
Operating Offensively Against Sysmon
Sysmon is a tool written by Mark Russinovich that I have covered in multiple blog post and even wrote a PowerShell module called Posh-Sysmon to help with the generation of configuration files for it. Its main purpose is for the tracking of potentially malicious…
#فرصت_همکاری کارشناس تحلیل رخدادهای امنیتی در شرکت پرداخت الکترونیک سداد
- تسلط به مبانی عمومی امنيت اطلاعات (تسلط بر پروتکلهای رمزنگاری، امضا، تبادل کلید و مکانیزمهای کنترل دسترسی)
- تسلط به مفاهیم فرایند رسیدگی به حادثه
- تسلط در تحلیل لاگهای حملات شناسایی شده توسط سیستمهای تشخیص نفوذ، و ضد بدافزار
- تسلط در تحلیل لاگهای حملات شناسایی شده توسط تجهیزات امنیت شبکه در لایههای مختلف
- توانایی شناسایی و تحلیل تغییرات ثبت شده بر روی سیستمها
- آشنا با نحوه عملکرد سامانه SIEM
- آشنا با صنعت پرداخت الکترونیک، حساسیتها و مخاطرات این حوزه
علاقمندان رزومه خود را به ایمیل زیر ارسال نمایند.
🔹 security@sadadpsp.ir
- تسلط به مبانی عمومی امنيت اطلاعات (تسلط بر پروتکلهای رمزنگاری، امضا، تبادل کلید و مکانیزمهای کنترل دسترسی)
- تسلط به مفاهیم فرایند رسیدگی به حادثه
- تسلط در تحلیل لاگهای حملات شناسایی شده توسط سیستمهای تشخیص نفوذ، و ضد بدافزار
- تسلط در تحلیل لاگهای حملات شناسایی شده توسط تجهیزات امنیت شبکه در لایههای مختلف
- توانایی شناسایی و تحلیل تغییرات ثبت شده بر روی سیستمها
- آشنا با نحوه عملکرد سامانه SIEM
- آشنا با صنعت پرداخت الکترونیک، حساسیتها و مخاطرات این حوزه
علاقمندان رزومه خود را به ایمیل زیر ارسال نمایند.
🔹 security@sadadpsp.ir
کتاب رایگان و بی نظیر یادگیری ماشین و علم داده. 490 صفحه.
اگر به دنبال منبع فارسی و رایگان جهت یادگیری علم داده و یادگیری ماشین هستید، این کتاب فوق العاده می تواند منبع بسیار خوبی براتون باشه که مفاهیم رو خیلی خوب و ساده توضیح داده.
لینک دسترسی :
https://www.researchgate.net/publication/358263339_yadgyry_mashyn_w_lm_dadh_mbany_mfahym_algwrytmha_w_abzarha
با هشتگ
#BigDataWorldLearn
به همه ی فایل های آموزشی دسترسی دارید.
🌐 ما را در تلگرام، اینستاگرام و یوتیوب دنبال کنید
اگر به دنبال منبع فارسی و رایگان جهت یادگیری علم داده و یادگیری ماشین هستید، این کتاب فوق العاده می تواند منبع بسیار خوبی براتون باشه که مفاهیم رو خیلی خوب و ساده توضیح داده.
لینک دسترسی :
https://www.researchgate.net/publication/358263339_yadgyry_mashyn_w_lm_dadh_mbany_mfahym_algwrytmha_w_abzarha
با هشتگ
#BigDataWorldLearn
به همه ی فایل های آموزشی دسترسی دارید.
🌐 ما را در تلگرام، اینستاگرام و یوتیوب دنبال کنید
ResearchGate
(PDF) یادگیری ماشین و علم داده: مبانی، مفاهیم، الگوریتمها و ابزارها
PDF | On Feb 1, 2022, Milad Vazan published یادگیری ماشین و علم داده: مبانی، مفاهیم، الگوریتمها و ابزارها | Find, read and cite all the research you need on ResearchGate
PeStudio
PeStudio is a free tool performing the static investigation of any Windows executable binary. A file being analyzed with PeStudio is never launched.
Professional software for reviewing and analyzing file types EXE, DLL, CPL, OCX, AX, SYS, etc.
https://www.winitor.com/
PeStudio is a free tool performing the static investigation of any Windows executable binary. A file being analyzed with PeStudio is never launched.
Professional software for reviewing and analyzing file types EXE, DLL, CPL, OCX, AX, SYS, etc.
https://www.winitor.com/
Backstab - a tool to kill antimalware protected processes
✅Kill EDR Protected Processes
https://hakin9.org/backstab-a-tool-to-kill-antimalware-protected-processes/
✅Kill EDR Protected Processes
https://hakin9.org/backstab-a-tool-to-kill-antimalware-protected-processes/
Hakin9 - IT Security Magazine
404 - Hakin9 - IT Security Magazine
برای علاقمندان به:
SillyRAT - a Cross Platform multifunctional (Windows/Linux/Mac) RAT
https://hakin9.org/sillyrat-a-cross-platform-multifunctional-windows-linux-mac-rat/
SillyRAT - a Cross Platform multifunctional (Windows/Linux/Mac) RAT
https://hakin9.org/sillyrat-a-cross-platform-multifunctional-windows-linux-mac-rat/
Hakin9 - IT Security Magazine
404 - Hakin9 - IT Security Magazine