CSIRT-Collect - PowerShell Script To Collect Memory And (Triage) Disk Forensics
A PowerShell script to collect memory and (triage) disk forensics for incident response investigations. The script leverages a network share, from which it will access and copy the required executables and subsequently upload the acquired evidence to the same share post-collection. Permission requirements for said directory will be dependent on the nuances of the environment and what credentials are used for the script execution (interactive vs. automation) In the demonstration code, a network location of \Synology\Collections can be seen. This should be changed to reflect the specifics of your environment. Collections folder needs to include: subdirectory KAPE; copy the directory from existing install subdirectory MEMORY; 7za.exe command line version of 7zip and winpmem.exeCSIRT-Collect Maps to existing network drive - Subdir 1: “Memory” – Winpmem and 7zip executables Subdir 2: ”KAPE” – directory (copied from local install) Creates a local directory on asset Copies the Memory exe files to local directory Captures memory with Winpmem When complete, ZIPs the memory image Renames the zip file based on hostname Documents the OS Build Info (no need to determine profile for Volatility) Compressed image is copied to network directory and deleted from host after transfer complete New temp Directory on asset for KAPE output KAPE !SANS_Triage collection is run using VHDX as output format $hostname.vhdx VHDX transfers to network Removes the local KAPE directory after completion Writes a “Process complete” text file to network to signal investigators that collection is ready for analysis. CSIRT-Collect_USB Essentially the same functionality as CSIRT-Collect.ps1 with the exception that it is intented to be run from a USB device. The extra compression operations on the memory image and KAPE .vhdx have been removed. There is a slight change to the folder structure for the USB version. On the root of the USB: CSIRT-Collect_USB.ps1 folder (empty to start) titled 'Collections' folders for KAPE and Memory - same as above Execution: -Open PowerShell as Adminstrator -Navigate to the USB device -Execute ./CSIRT-Collect_USB.ps1 Download CSIRT-Collect
Read more...
___________________________
@hacking_Attack
@Hacking_Video
A PowerShell script to collect memory and (triage) disk forensics for incident response investigations. The script leverages a network share, from which it will access and copy the required executables and subsequently upload the acquired evidence to the same share post-collection. Permission requirements for said directory will be dependent on the nuances of the environment and what credentials are used for the script execution (interactive vs. automation) In the demonstration code, a network location of \Synology\Collections can be seen. This should be changed to reflect the specifics of your environment. Collections folder needs to include: subdirectory KAPE; copy the directory from existing install subdirectory MEMORY; 7za.exe command line version of 7zip and winpmem.exeCSIRT-Collect Maps to existing network drive - Subdir 1: “Memory” – Winpmem and 7zip executables Subdir 2: ”KAPE” – directory (copied from local install) Creates a local directory on asset Copies the Memory exe files to local directory Captures memory with Winpmem When complete, ZIPs the memory image Renames the zip file based on hostname Documents the OS Build Info (no need to determine profile for Volatility) Compressed image is copied to network directory and deleted from host after transfer complete New temp Directory on asset for KAPE output KAPE !SANS_Triage collection is run using VHDX as output format $hostname.vhdx VHDX transfers to network Removes the local KAPE directory after completion Writes a “Process complete” text file to network to signal investigators that collection is ready for analysis. CSIRT-Collect_USB Essentially the same functionality as CSIRT-Collect.ps1 with the exception that it is intented to be run from a USB device. The extra compression operations on the memory image and KAPE .vhdx have been removed. There is a slight change to the folder structure for the USB version. On the root of the USB: CSIRT-Collect_USB.ps1 folder (empty to start) titled 'Collections' folders for KAPE and Memory - same as above Execution: -Open PowerShell as Adminstrator -Navigate to the USB device -Execute ./CSIRT-Collect_USB.ps1 Download CSIRT-Collect
Read more...
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Where can I practice sql injections?
I have done some ctf's with sql but not enough, I need more practice.
Where can I practice more sql injections?
submitted by /u/yahboyelias
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Where can I practice sql injections?
I have done some ctf's with sql but not enough, I need more practice.
Where can I practice more sql injections?
submitted by /u/yahboyelias
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Where can I practice sql injections?
I have done some ctf's with sql but not enough, I need more practice. Where can I practice more sql injections?
hacking: security in practice
One of my first major hacks back when I was starting out what was your?
When I started to get into cybersecurity I remember the time that I hacked Dell to get a free Alienware laptop 😅
It worked but I was quickly caught because I used my real info
😬Someone from Dell calls me.
I answer to "hi I see here you were trying to hack dell, we would like to offer you an opportunity to work for us"
All I heard in my mind was, YOU GOING TO JAIL!
I hung up 🤣
submitted by /u/yahboyelias
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
One of my first major hacks back when I was starting out what was your?
When I started to get into cybersecurity I remember the time that I hacked Dell to get a free Alienware laptop 😅
It worked but I was quickly caught because I used my real info
😬Someone from Dell calls me.
I answer to "hi I see here you were trying to hack dell, we would like to offer you an opportunity to work for us"
All I heard in my mind was, YOU GOING TO JAIL!
I hung up 🤣
submitted by /u/yahboyelias
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
One of my first major hacks back when I was starting out what was...
When I started to get into cybersecurity I remember the time that I hacked Dell to get a free Alienware laptop 😅 It worked but I was quickly...
Tale of XSS in Angular
https://medium.com/@sicks3c/tale-of-xss-in-angular-c5c057a56156?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@sicks3c/tale-of-xss-in-angular-c5c057a56156?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tale of XSS in Angular
Automation helps get easy $$$ rXSS
Automation helps get easy $$$ rXSSContinue reading on Medium » (https://medium.com/@sicks3c/tale-of-xss-in-angular-c5c057a56156?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tale of XSS in Angular
Automation helps get easy $$$ rXSS
The journey from Google Honorable Mention to Hall of Fame.
https://medium.com/pentesternepal/the-journey-from-google-honorable-mention-to-hall-of-fame-f62d9d5882ea?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/pentesternepal/the-journey-from-google-honorable-mention-to-hall-of-fame-f62d9d5882ea?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
The journey from Google Honorable Mention to Hall of Fame.
Earlier I found a valid bug in google but that doesn’t meet the bar for reward & I have to satisfy myself to be Enlisted in Honorable…
Earlier I found a valid bug in google but that doesn’t meet the bar for reward & I have to satisfy myself to be Enlisted in Honorable…Continue reading on Pentester Nepal » (https://medium.com/pentesternepal/the-journey-from-google-honorable-mention-to-hall-of-fame-f62d9d5882ea?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
The journey from Google Honorable Mention to Hall of Fame.
Earlier I found a valid bug in google but that doesn’t meet the bar for reward & I have to satisfy myself to be Enlisted in Honorable…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking the Tenda AC10-1200 Router Part 1: CVE-2018–16334
https://cdn-images-1.medium.com/max/781/1*io-9ILto1hoJGWZ_p9jXgA.png
Hi. This would be another series of writeup where we will try to hack the tenda ac10 1200 and try to get a cve. Lets get started
Continue reading on Medium »
Hacking the Tenda AC10-1200 Router Part 1: CVE-2018–16334
https://cdn-images-1.medium.com/max/781/1*io-9ILto1hoJGWZ_p9jXgA.png
Hi. This would be another series of writeup where we will try to hack the tenda ac10 1200 and try to get a cve. Lets get started
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
FACEBOOK, TWITTER, SNAPCHAT, SOCIAL MEDIA AND ITS MANY VULNERABILITIES
Okay its true, i admit it, having a social media account is fun and sometimes an escape from reality.At least its like that with most…
Continue reading on Medium »
FACEBOOK, TWITTER, SNAPCHAT, SOCIAL MEDIA AND ITS MANY VULNERABILITIES
Okay its true, i admit it, having a social media account is fun and sometimes an escape from reality.At least its like that with most…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pegasus spyware explained (how to keep your device safe)
https://cdn-images-1.medium.com/max/739/1*5B-HaNnJDxyQijELkjDHsg.jpeg
'Pegasus' a spyware that knows no limit when it comes to bypassing smartphones security by injecting itself remotely in any operating…
Continue reading on Medium »
Pegasus spyware explained (how to keep your device safe)
https://cdn-images-1.medium.com/max/739/1*5B-HaNnJDxyQijELkjDHsg.jpeg
'Pegasus' a spyware that knows no limit when it comes to bypassing smartphones security by injecting itself remotely in any operating…
Continue reading on Medium »
Deep Web
link mirrored
good morning everyone! Does anyone know of any link mirrored in the onion of the site "Bloomberg" wall street jounaul" and The New York Times"?
submitted by /u/Trader_Kamikaze
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
link mirrored
good morning everyone! Does anyone know of any link mirrored in the onion of the site "Bloomberg" wall street jounaul" and The New York Times"?
submitted by /u/Trader_Kamikaze
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
link mirrored
good morning everyone! Does anyone know of any link mirrored in the onion of the site "Bloomberg" wall street jounaul" and The New York Times"?
How do you measure "noise" in attacks?
https://www.reddit.com/r/redteamsec/comments/ovv794/how_do_you_measure_noise_in_attacks/
How do you measure "noise" in attacks? Also how to you compare attack techniques regarding noise? How do you choose an attack technique if stealth is priority? How do you test your technique before using it? submitted by /u/FOSS_Lover (https://www.reddit.com/user/FOSS_Lover)
[link] (https://www.reddit.com/r/redteamsec/comments/ovv794/how_do_you_measure_noise_in_attacks/) [comments] (https://www.reddit.com/r/redteamsec/comments/ovv794/how_do_you_measure_noise_in_attacks/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ovv794/how_do_you_measure_noise_in_attacks/
How do you measure "noise" in attacks? Also how to you compare attack techniques regarding noise? How do you choose an attack technique if stealth is priority? How do you test your technique before using it? submitted by /u/FOSS_Lover (https://www.reddit.com/user/FOSS_Lover)
[link] (https://www.reddit.com/r/redteamsec/comments/ovv794/how_do_you_measure_noise_in_attacks/) [comments] (https://www.reddit.com/r/redteamsec/comments/ovv794/how_do_you_measure_noise_in_attacks/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the redteamsec community on Reddit
Explore this post and more from the redteamsec community
hacking: security in practice
Friend and I received spoofed calls from each other last night
So this morning I woke up to a couple of missed calls and a VM from a friend/coworker last night. The Google transcription basically said my name, said his name, that he had been drinking, and that he always wanted to thumb my drive. At that point, I hadn't actually listened to the message, and assumed the bizarreness was due to the transcription process and that he was really asking me for a ride home. So I texted him to ask if he got home alright, and he responded that he didn't know what I was talking about, and that he received a missed call and VM from me last night at the same time, basically saying the same thing.
We're on different wireless networks and use different phones (android and iphone). All my important accounts use unique passwords and multifactor auth. We both work IT for the same company, so the part of the message, "thumb your drive" is a little on the nose, which makes everything a little more disconcerting. When I actually listened to the VM, it's clearly not him, but it doesn't sound like a robo call either...it's clearly a real person.
What other steps should we take to mitigate things from escalating and how is this even possible?
submitted by /u/kwaalude
[link] [comments]
Friend and I received spoofed calls from each other last night
So this morning I woke up to a couple of missed calls and a VM from a friend/coworker last night. The Google transcription basically said my name, said his name, that he had been drinking, and that he always wanted to thumb my drive. At that point, I hadn't actually listened to the message, and assumed the bizarreness was due to the transcription process and that he was really asking me for a ride home. So I texted him to ask if he got home alright, and he responded that he didn't know what I was talking about, and that he received a missed call and VM from me last night at the same time, basically saying the same thing.
We're on different wireless networks and use different phones (android and iphone). All my important accounts use unique passwords and multifactor auth. We both work IT for the same company, so the part of the message, "thumb your drive" is a little on the nose, which makes everything a little more disconcerting. When I actually listened to the VM, it's clearly not him, but it doesn't sound like a robo call either...it's clearly a real person.
What other steps should we take to mitigate things from escalating and how is this even possible?
submitted by /u/kwaalude
[link] [comments]
reddit
Friend and I received spoofed calls from each other last night
So this morning I woke up to a couple of missed calls and a VM from a friend/coworker last night. The Google transcription basically said my...