EsecurityCo
2.72K subscribers
1.24K photos
303 videos
138 files
1K links
کانال رسمی سایت Esecurity.ir

رایگان ببینید و بیاموزید،
از دوره های حضوری مطلع شوید،
در کلاس ها شرکت کنید،
و حرفه ای شوید...

مرکز تربیت متخصص امنیت سایبری

با ما در ارتباط باشید:
@Forensics

ادمین تبادل:
@Forensics
Download Telegram
Forwarded from cissp (Alireza Ghahrood)
Videos
• The Future of Incident Response - Presented by Bruce Schneier at OWASP AppSecUSA 2015.

Windows Evidence Collection
• AChoir - Framework/scripting tool to standardize and simplify the process of scripting live acquisition utilities for Windows.
• Crowd Response - Lightweight Windows console application designed to aid in the gathering of system information for incident response and security engagements. It features numerous modules and output formats.
• DFIR ORC - DFIR ORC is a collection of specialized tools dedicated to reliably parse and collect critical artifacts such as the MFT, registry hives or event logs. DFIR ORC collects data, but does not analyze it: it is not meant to triage machines. It provides a forensically relevant snapshot of machines running Microsoft Windows. The code can be found on GitHub.
• FastIR Collector - Tool that collects different artifacts on live Windows systems and records the results in csv files. With the analyses of these artifacts, an early compromise can be detected.
• Fibratus - Tool for exploration and tracing of the Windows kernel.
• Hoarder - Collecting the most valuable artifacts for forensics or incident response investigations.
• IREC - All-in-one IR Evidence Collector which captures RAM Image, $MFT, EventLogs, WMI Scripts, Registry Hives, System Restore Points and much more. It is FREE, lightning fast and easy to use.
• Invoke-LiveResponse - Invoke-LiveResponse is a live response tool for targeted collection.
• IOC Finder - Free tool from Mandiant for collecting host system data and reporting the presence of Indicators of Compromise (IOCs). Support for Windows only. No longer maintained. Only fully supported up to Windows 7 / Windows Server 2008 R2.
• IRTriage - Incident Response Triage - Windows Evidence Collection for Forensic Analysis.
• KAPE - Kroll Artifact Parser and Extractor (KAPE) by Eric Zimmerman. A triage tool that finds the most prevalent digital artifacts and then parses them quickly. Great and thorough when time is of the essence.
• LOKI - Free IR scanner for scanning endpoint with yara rules and other indicators(IOCs).
• MEERKAT - PowerShell-based triage and threat hunting for Windows.
• Panorama - Fast incident overview on live Windows systems.
• PowerForensics - Live disk forensics platform, using PowerShell.
• PSRecon - PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained locally.
• RegRipper - Open source tool, written in Perl, for extracting/parsing information (keys, values, data) from the Registry and presenting it for analysis
Forwarded from SecCode (Meisam Monsef)
دوره برنامه نویسی Android با جاوا به مناسبت ولادت با سعادت امام علی (ع) رایگان شد


کُلُّ وِعاءٍ یَضیقُ بِما جُعِلَ فیهِ إِلاّ وِعاءُ العِلمِ فَإِنَّهُ یَتَّسِعُ بِهِ؛

فضای هر ظرفی در اثر محتوای خود تنگ‏تر می‏شود مگر ظرف دانش که با تحصیل علوم، فضای آن بازتر می‏گردد.

نهج البلاغه،ص۵۰۵


لینک های دانلود :

http://uploadb.me/728srg0v7mpm.html
http://uploadb.me/zblubfodwutn.html
http://uploadb.me/1y0v4mc3nuu7.html
http://uploadb.me/ac5lw86ac92p.html
http://uploadb.me/sud4wls7bns0.html
http://uploadb.me/e7c218fv56ru.html
http://uploadb.me/603u5wtp5l5z.html
http://uploadb.me/k8wo2enjxf9f.html

Password Zip : meisamAnd0rid$

دوستانی که از دوره استفاده میکنند برای سلامتی تمامی بیماران
یک صلوات بفرستند
با آرزوی سلامتی تمامی بیماران


@dorsateam
Khepri 
Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang and C++.
https://github.com/geemion/Khepri
Evil-WinRM: The ultimate WinRM shell for hacking/pentesting
Features

Load in memory Powershell scripts

Load in memory dll files bypassing some AVs

Load in memory C# (C Sharp) assemblies bypassing some AVs

Load x64 payloads generated with awesome donut technique

AMSI Bypass

Pass-the-hash support

Kerberos auth support

SSL and certificates support

Upload and download files

List remote machine services without privileges

Command History

WinRM command completion

Local files completion

Colorization on output messages (can be disabled optionally)

Docker support (prebuilt images available at Dockerhub)

https://hakin9.org/evil-winrm-the-ultimate-winrm-shell-for-hacking-pentesting/
لیست از ابزارهای شکار تهدیدات اوپن سورس
Windows_PowerShell_Tutorial_for_Beginners_9.pdf
240.6 KB
افرادی که در حوزه blue Team کار میکنند، نیاز به دانش در خصوص پاورشل دارند،
یک راهنمای خوب برای کسانی که تازه کارتر هستند
Windows_PowerShell_Tutorial_for_Beginners - Page ۹.pdf
Blinding EDR On Windows


My understanding of EDRs would not be possible without the help of many great security researchers. Below are some write-ups and talks that really helped me gain the understanding needed and hit the ground running on the research that will be presented here. If you are interested to go deeper, be sure to check out the following research (in no particular order):

https://synzack.github.io/Blinding-EDR-On-Windows/
#فرصت_همکاری کارشناس تحلیل رخدادهای امنیتی در شرکت پرداخت الکترونیک سداد

- تسلط به مبانی عمومی امنيت اطلاعات (تسلط بر پروتکلهای رمزنگاری، امضا، تبادل کلید و مکانیزم­های کنترل دسترسی)
- تسلط به مفاهیم فرایند رسیدگی به حادثه
- تسلط در تحلیل لاگ­های حملات شناسایی شده توسط سیستم­های تشخیص نفوذ، و ضد بدافزار
- تسلط در تحلیل لاگ­های حملات شناسایی شده توسط تجهیزات امنیت شبکه در لایه­‌های مختلف
- توانایی شناسایی و تحلیل تغییرات ثبت شده بر روی سیستم­‌ها
- آشنا با نحوه عملکرد سامانه SIEM
- آشنا با صنعت پرداخت الکترونیک، حساسیت­‌ها و مخاطرات این حوزه

علاقمندان رزومه خود را به ایمیل زیر ارسال نمایند.

🔹 security@sadadpsp.ir
کتاب رایگان و بی نظیر یادگیری ماشین و علم داده. 490 صفحه.
اگر به دنبال منبع فارسی و رایگان جهت یادگیری علم داده و یادگیری ماشین هستید، این کتاب فوق العاده می تواند منبع بسیار خوبی براتون باشه که مفاهیم رو خیلی خوب و ساده توضیح داده.
لینک دسترسی :
https://www.researchgate.net/publication/358263339_yadgyry_mashyn_w_lm_dadh_mbany_mfahym_algwrytmha_w_abzarha

با هشتگ
#BigDataWorldLearn
به همه ی فایل های آموزشی دسترسی دارید.

🌐 ما را در تلگرام، اینستاگرام و یوتیوب دنبال کنید
PeStudio 

PeStudio is a free tool performing the static investigation of any Windows executable binary. A file being analyzed with PeStudio is never launched.

Professional software for reviewing and analyzing file types EXE, DLL, CPL, OCX, AX, SYS, etc.

https://www.winitor.com/
برای علاقمندان به:
SillyRAT - a Cross Platform multifunctional (Windows/Linux/Mac) RAT

https://hakin9.org/sillyrat-a-cross-platform-multifunctional-windows-linux-mac-rat/