Top 50 Digital Forensics Tools
Network Forensic Tools
- Nmap
- Wireshark
- Xplico
- Snort
- TCPDump
- The Slueth Kit
Mobile Forensics Tools
- Elcomspoft iOS Forensic Toolkit
- Mobile Verification Toolkit
- Oxygen Forensic
- MOBILedit
- Cellebrite UFED
- MSAB XRY
Malware Analysis Tools
- Wireshark
- YARA
- Malwarebytes
- VirusTotal
- Cuckoo Sandbox
- IDA Pro
Data Recovery Tools
- Recuva
- EaseUS Data Recovery
- TestDisk
- Stellar Data Recovery
- PhotoRec
- Disk Drill
Email Forensic Tools
- MailXaminer
- MailPro+
- Xtraxtor
- Aid4Mail
- eMailTrackerPro
- Autopsy
OSINT Tools
- Maltego
- Nmap
- OSINT Framework
- Shodan
- Recon-ng
- TheHavester
Live Forensics Tools
- OS Forensics
- Encase Live
- CAINE
- F-Response
- Kali Linux Forensic Mode
Memory Forensics Tools
- Volatility
- DumpIt
- memDump
- Access data FTK Imager
- Hibernation Recon
- WindowSCOPE
Cloud Forensic Tools
- Magnet AXIOM
- MSAB XRY Cloud
- Azure CLI
Network Forensic Tools
- Nmap
- Wireshark
- Xplico
- Snort
- TCPDump
- The Slueth Kit
Mobile Forensics Tools
- Elcomspoft iOS Forensic Toolkit
- Mobile Verification Toolkit
- Oxygen Forensic
- MOBILedit
- Cellebrite UFED
- MSAB XRY
Malware Analysis Tools
- Wireshark
- YARA
- Malwarebytes
- VirusTotal
- Cuckoo Sandbox
- IDA Pro
Data Recovery Tools
- Recuva
- EaseUS Data Recovery
- TestDisk
- Stellar Data Recovery
- PhotoRec
- Disk Drill
Email Forensic Tools
- MailXaminer
- MailPro+
- Xtraxtor
- Aid4Mail
- eMailTrackerPro
- Autopsy
OSINT Tools
- Maltego
- Nmap
- OSINT Framework
- Shodan
- Recon-ng
- TheHavester
Live Forensics Tools
- OS Forensics
- Encase Live
- CAINE
- F-Response
- Kali Linux Forensic Mode
Memory Forensics Tools
- Volatility
- DumpIt
- memDump
- Access data FTK Imager
- Hibernation Recon
- WindowSCOPE
Cloud Forensic Tools
- Magnet AXIOM
- MSAB XRY Cloud
- Azure CLI
Today's Bug Bounty Blogs #18
1)Hitting the jackpot with RCE!
https://medium.com/@gokulsspace/hitting-the-jackpot-with-rce-43755cac1415
2)How I Discovered a Critical Vulnerability that Most Bug Hunters Missed….🧐
https://dkcyberz.medium.com/how-i-discovered-a-critical-vulnerability-that-most-bug-hunters-missed-b00f87cfb8b2
3)“Like” Bypass on Customer Reviews — €500 bounty
https://medium.com/@asharm.khan7/like-bypass-on-customer-reviews-500-bounty-b8d45a98c096
4)Juniper Networks RCE - Shodan - CVE Automation
https://www.youtube.com/watch?v=LNUGAxphelE
5)Critical Command Injection : CVE-2024-1212 | bug bounty poc
https://www.youtube.com/watch?v=JIhURKlnwbk
6)How to Hack Android Device | Ghost | Shodan
https://www.youtube.com/watch?v=klba8l6BngI
7)[#E05] Secure Code Review for Beginners: XML External Entity (XXE)
https://www.youtube.com/watch?v=HKDe1z7_AII
8)BTS Challenge: XSS Contexts and Polyglots
https://www.youtube.com/watch?v=UAPs18qBQzo
9)The Cartel Connection — Walkthrough
https://medium.com/@unkn0wnus3r91/the-cartel-connection-3246fba35bbc
10)FFUF Web Parser
https://github.com/VikzSharma/ffufwebparser
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
1)Hitting the jackpot with RCE!
https://medium.com/@gokulsspace/hitting-the-jackpot-with-rce-43755cac1415
2)How I Discovered a Critical Vulnerability that Most Bug Hunters Missed….🧐
https://dkcyberz.medium.com/how-i-discovered-a-critical-vulnerability-that-most-bug-hunters-missed-b00f87cfb8b2
3)“Like” Bypass on Customer Reviews — €500 bounty
https://medium.com/@asharm.khan7/like-bypass-on-customer-reviews-500-bounty-b8d45a98c096
4)Juniper Networks RCE - Shodan - CVE Automation
https://www.youtube.com/watch?v=LNUGAxphelE
5)Critical Command Injection : CVE-2024-1212 | bug bounty poc
https://www.youtube.com/watch?v=JIhURKlnwbk
6)How to Hack Android Device | Ghost | Shodan
https://www.youtube.com/watch?v=klba8l6BngI
7)[#E05] Secure Code Review for Beginners: XML External Entity (XXE)
https://www.youtube.com/watch?v=HKDe1z7_AII
8)BTS Challenge: XSS Contexts and Polyglots
https://www.youtube.com/watch?v=UAPs18qBQzo
9)The Cartel Connection — Walkthrough
https://medium.com/@unkn0wnus3r91/the-cartel-connection-3246fba35bbc
10)FFUF Web Parser
https://github.com/VikzSharma/ffufwebparser
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
Medium
Hitting the jackpot with RCE!
Hey, so everyone was pushing me to write another write-up after the acceptance of my first ever bug bounty write up. So if you haven’t…
Today's Bug Bounty Blogs #19
1)How I found My first P1 Bug which ended up ….$?
https://medium.com/@yashsomalkar/how-i-found-my-first-p1-bug-which-ended-up-5e6cffdbb066
2)Google Dork Mastery Part 1 : Finding Hidden Critical Files with Google Dorks Like a Pro
https://enigma96.medium.com/google-dork-mastery-part-1-finding-hidden-critical-files-with-google-dorks-like-a-pro-d28ad159e9ae
3)How to Hunt for Sensitive Directories in Bug Bounty Hunting
https://bughunteralltime.medium.com/how-to-hunt-for-sensitive-directories-in-bug-bounty-hunting-f61a7f61d8fb
4)CyberSpace2024 ZipZone CTF : ZipSlip Vulnerability
https://starlox.medium.com/cyberspace2024-zipzone-ctf-zipslip-vulnerability-00489669feec
5)3108 Bahtera Siber Capture The Flag (CTF)
https://medium.com/@rectifyq/3108-bahtera-siber-capture-the-flag-ctf-draft-ca1be1751665
6)CyberSpace2024 Memory CTF : Interesting Forensics Challenge
https://starlox.medium.com/cyberspace2024-memory-ctf-interesting-forensics-challenge-0a76eb00f027
7)CyberSpace CTF 2024 — sole
https://medium.com/@amiremohamadi/cyberspace-ctf-2024-sole-fc58c0566576
8)TryHackME Hammer WriteuP- By YoussefHossam
https://medium.com/@yh55694/tryhackme-hammer-writeup-by-youssefhossam-d4d625fdaa70
9)Jurassic Park Tryhackme writeup
https://bevijaygupta.medium.com/jurassic-park-tryhackme-writeup-fb2b53c4b202
10)Persistence TryHackme Writeup
https://bevijaygupta.medium.com/persistence-tryhackme-writeup-276165b948ec
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
1)How I found My first P1 Bug which ended up ….$?
https://medium.com/@yashsomalkar/how-i-found-my-first-p1-bug-which-ended-up-5e6cffdbb066
2)Google Dork Mastery Part 1 : Finding Hidden Critical Files with Google Dorks Like a Pro
https://enigma96.medium.com/google-dork-mastery-part-1-finding-hidden-critical-files-with-google-dorks-like-a-pro-d28ad159e9ae
3)How to Hunt for Sensitive Directories in Bug Bounty Hunting
https://bughunteralltime.medium.com/how-to-hunt-for-sensitive-directories-in-bug-bounty-hunting-f61a7f61d8fb
4)CyberSpace2024 ZipZone CTF : ZipSlip Vulnerability
https://starlox.medium.com/cyberspace2024-zipzone-ctf-zipslip-vulnerability-00489669feec
5)3108 Bahtera Siber Capture The Flag (CTF)
https://medium.com/@rectifyq/3108-bahtera-siber-capture-the-flag-ctf-draft-ca1be1751665
6)CyberSpace2024 Memory CTF : Interesting Forensics Challenge
https://starlox.medium.com/cyberspace2024-memory-ctf-interesting-forensics-challenge-0a76eb00f027
7)CyberSpace CTF 2024 — sole
https://medium.com/@amiremohamadi/cyberspace-ctf-2024-sole-fc58c0566576
8)TryHackME Hammer WriteuP- By YoussefHossam
https://medium.com/@yh55694/tryhackme-hammer-writeup-by-youssefhossam-d4d625fdaa70
9)Jurassic Park Tryhackme writeup
https://bevijaygupta.medium.com/jurassic-park-tryhackme-writeup-fb2b53c4b202
10)Persistence TryHackme Writeup
https://bevijaygupta.medium.com/persistence-tryhackme-writeup-276165b948ec
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
Medium
How I found My first P1 Bug which ended up ….$?
Hello readers :)
Let me introduce Myself. I am a noob script kiddie. Trying my luck at Bug Bounty :) I also played CTFs for almost 3 years…
Let me introduce Myself. I am a noob script kiddie. Trying my luck at Bug Bounty :) I also played CTFs for almost 3 years…
Today's Bug Bounty Blogs #20
1)How I found a Broken Access Control by Reading API docs!
https://medium.com/@sanjaith3hacker/how-i-found-a-broken-access-control-by-reading-api-docs-e34219224076
2)Ultimate FFUF Cheatsheet: Advanced Fuzzing Tactics for Pro Bug Hunters!
https://medium.com/h7w/ultimate-ffuf-cheatsheet-advanced-fuzzing-tactics-for-pro-bug-hunters-492598750150
3)TryHackme — Jack Write up
https://bevijaygupta.medium.com/tryhackme-jack-write-up-fab8279fb15d
4)Tryhackme’s mKingdom Writeup by Alan Lundy
https://medium.com/@alanlundy23/tryhackmes-mkingdom-writeup-by-alan-lundy-afbc32278d97
5)Hardening Basics Part 1 TryHackme
https://systemweakness.com/hardening-basics-part-1-tryhackme-14ff5672d3d6
6)DriftingBlues: 6 Vulnhub Walkthrough
https://medium.com/@rzashirinov38/driftingblues-6-vulnhub-walkthrough-8db6ecdb3b46
7)Forensics Writeups | BlackHat MEA CTF Qualification 2024
https://medium.com/@mfaizanars/forensics-writeups-blackhat-mea-ctf-qualification-2024-648651defb26
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
1)How I found a Broken Access Control by Reading API docs!
https://medium.com/@sanjaith3hacker/how-i-found-a-broken-access-control-by-reading-api-docs-e34219224076
2)Ultimate FFUF Cheatsheet: Advanced Fuzzing Tactics for Pro Bug Hunters!
https://medium.com/h7w/ultimate-ffuf-cheatsheet-advanced-fuzzing-tactics-for-pro-bug-hunters-492598750150
3)TryHackme — Jack Write up
https://bevijaygupta.medium.com/tryhackme-jack-write-up-fab8279fb15d
4)Tryhackme’s mKingdom Writeup by Alan Lundy
https://medium.com/@alanlundy23/tryhackmes-mkingdom-writeup-by-alan-lundy-afbc32278d97
5)Hardening Basics Part 1 TryHackme
https://systemweakness.com/hardening-basics-part-1-tryhackme-14ff5672d3d6
6)DriftingBlues: 6 Vulnhub Walkthrough
https://medium.com/@rzashirinov38/driftingblues-6-vulnhub-walkthrough-8db6ecdb3b46
7)Forensics Writeups | BlackHat MEA CTF Qualification 2024
https://medium.com/@mfaizanars/forensics-writeups-blackhat-mea-ctf-qualification-2024-648651defb26
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
Medium
How I found a Broken Access Control by Reading API docs!
Hey everyone hope you all are doing good and I’m combing back with new blog After long time because of my busy schedule. This is th3sanjai…
Today's Bug Bounty Blogs #21
1)Meta Bug Bounty — Fuzzing “netconsd” for fun and profit — part 3
https://blog.fadyothman.com/meta-bug-bounty-fuzzing-netconsd-for-fun-and-profit-part-3-127bb01d6756
2)Automating Subdomain Enumeration to Discover Critical Vulnerabilities
https://shubhamrooter.medium.com/automating-subdomain-enumeration-to-discover-critical-vulnerabilities-aa6158d35a8f
3)Google Dorks for Bug Bounty Part 3: Exposing Hidden Admin Panels & Login Portals
https://enigma96.medium.com/google-dorks-for-bug-bounty-part-3-exposing-hidden-admin-panels-login-portals-52b600e3f10b
4)OverTheWire Bandit: Levels 14–33 Complete Walkthrough
https://medium.com/@KpCyberInfo/overthewire-bandit-levels-14-33-complete-walkthrough-dd36accef2f4
5)Log4j Exploit Lab: Reverse Shell with JNDI Exploit Kit
https://medium.com/@josh.beck2006/log4j-exploit-lab-reverse-shell-with-jndi-exploit-kit-21f015204e29
6)New methods of recon with OrwaGodfather
https://www.youtube.com/watch?v=5RyODeBjar4
7)SpideyX - A Web Reconnaissance Penetration Testing tool for Penetration Testers and Ethical Hackers that included with multiple mode with asynchronous concurrne performance.
https://github.com/RevoltSecurities/Spideyx
1)Meta Bug Bounty — Fuzzing “netconsd” for fun and profit — part 3
https://blog.fadyothman.com/meta-bug-bounty-fuzzing-netconsd-for-fun-and-profit-part-3-127bb01d6756
2)Automating Subdomain Enumeration to Discover Critical Vulnerabilities
https://shubhamrooter.medium.com/automating-subdomain-enumeration-to-discover-critical-vulnerabilities-aa6158d35a8f
3)Google Dorks for Bug Bounty Part 3: Exposing Hidden Admin Panels & Login Portals
https://enigma96.medium.com/google-dorks-for-bug-bounty-part-3-exposing-hidden-admin-panels-login-portals-52b600e3f10b
4)OverTheWire Bandit: Levels 14–33 Complete Walkthrough
https://medium.com/@KpCyberInfo/overthewire-bandit-levels-14-33-complete-walkthrough-dd36accef2f4
5)Log4j Exploit Lab: Reverse Shell with JNDI Exploit Kit
https://medium.com/@josh.beck2006/log4j-exploit-lab-reverse-shell-with-jndi-exploit-kit-21f015204e29
6)New methods of recon with OrwaGodfather
https://www.youtube.com/watch?v=5RyODeBjar4
7)SpideyX - A Web Reconnaissance Penetration Testing tool for Penetration Testers and Ethical Hackers that included with multiple mode with asynchronous concurrne performance.
https://github.com/RevoltSecurities/Spideyx
Medium
Meta Bug Bounty — Fuzzing “netconsd” for fun and profit — part 3
Welcome to the final part in this series, this time we will talk about how to generate the test cases that we can use to fuzz netconsd, in…
Today's Bug Bounty Blogs #25
1)From an Android Hook to RCE: $5000 Bounty
https://blog.voorivex.team/from-an-android-hook-to-rce-5000-bounty
2)SOQL injection in SalesForce earned me $$$$$
https://rooted0x01.medium.com/soql-injection-in-salesforce-apex-earned-me-903e3e9d8268
3)OAuth Non-Happy Path to ATO
https://blog.voorivex.team/oauth-non-happy-path-to-ato
4)Breaking Down Multipart Parsers: File upload validation bypass
https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/
5)visit these website
https://lostsec.xyz/
https://ahmed-tarek.gitbook.io/sec-notes
6)The Blueprint to Your First $1,000+ Bounty
https://www.youtube.com/watch?v=8DnphDtFt3Y
7)Subdomain Enumeration ALL KINDS!
https://www.youtube.com/watch?v=6gY8cA3onkg
8)OTX_AlienVault_URL The OTX Scraper is a Bash script designed to fetch URLs associated with a given domain from AlienVault's Open Threat Exchange (OTX) platform.
https://github.com/Suryesh/OTX_AlienVault_URL
9)ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities.
https://github.com/rootDR/ex-param
10)QuickSSRF - CAIDO Plugin
https://github.com/caido-community/quickssrf
1)From an Android Hook to RCE: $5000 Bounty
https://blog.voorivex.team/from-an-android-hook-to-rce-5000-bounty
2)SOQL injection in SalesForce earned me $$$$$
https://rooted0x01.medium.com/soql-injection-in-salesforce-apex-earned-me-903e3e9d8268
3)OAuth Non-Happy Path to ATO
https://blog.voorivex.team/oauth-non-happy-path-to-ato
4)Breaking Down Multipart Parsers: File upload validation bypass
https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/
5)visit these website
https://lostsec.xyz/
https://ahmed-tarek.gitbook.io/sec-notes
6)The Blueprint to Your First $1,000+ Bounty
https://www.youtube.com/watch?v=8DnphDtFt3Y
7)Subdomain Enumeration ALL KINDS!
https://www.youtube.com/watch?v=6gY8cA3onkg
8)OTX_AlienVault_URL The OTX Scraper is a Bash script designed to fetch URLs associated with a given domain from AlienVault's Open Threat Exchange (OTX) platform.
https://github.com/Suryesh/OTX_AlienVault_URL
9)ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities.
https://github.com/rootDR/ex-param
10)QuickSSRF - CAIDO Plugin
https://github.com/caido-community/quickssrf
Voorivex Team
From an Android Hook to RCE: $5000 Bounty
An Android hook chained into a remote code execution — $5,000 bounty.
Today's Bug Bounty Blogs #27
1)How I Found My First Bug (RXSS)
https://medium.com/@a0xtrojan/how-i-found-my-first-bug-rxss-2ac44e94d628
2)Crack the Code: Master Default Admin Panel Passwords to Boost Your Bug Bounty Rewards
https://medium.com/infosecmatrix/a-list-of-default-admin-panel-passwords-to-boost-your-bug-bounty-67af4c4f45b2
3)Weird JavaScript files 🥴
https://infosecwriteups.com/weird-javascript-files-7e6e7296e914
4)Web Cache Poisoning: Exploiting Trust in Cached Content
https://osintteam.blog/web-cache-poisoning-exploiting-trust-in-cached-content-362bb7c0d901
5)Bug Bounty Hunting Prerequisites
https://it4chis3c.medium.com/bug-bounty-hunting-prerequisites-964560919547
6)Ehxb | The Hidden Gateway CTF TryHackMe WriteUp
https://medium.com/@Ehxb/ehxb-the-hidden-gateway-ctf-tryhackme-writeup-a88fffdc98cb
7)eJPT : Host & Network Penetration Testing: Exploitation CTF 1
https://medium.com/@murat_kuzucu/ejpt-host-network-penetration-testing-exploitation-ctf-1-85cd5078e400
8)eJPT Host & Network Penetration Testing: Exploitation CTF 2
https://medium.com/@murat_kuzucu/ejpt-host-network-penetration-testing-exploitation-ctf-2-055d2969f1fe
9)Try Hack Me — Brains Write-up
https://medium.com/@cyberboar/try-hack-me-brains-write-up-9a32e6b4d5d1
10)HTB: Sightless Writeup / Walkthrough
https://medium.com/@pk2212/htb-sightless-writeup-walkthrough-ea6f492c0b3c
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
1)How I Found My First Bug (RXSS)
https://medium.com/@a0xtrojan/how-i-found-my-first-bug-rxss-2ac44e94d628
2)Crack the Code: Master Default Admin Panel Passwords to Boost Your Bug Bounty Rewards
https://medium.com/infosecmatrix/a-list-of-default-admin-panel-passwords-to-boost-your-bug-bounty-67af4c4f45b2
3)Weird JavaScript files 🥴
https://infosecwriteups.com/weird-javascript-files-7e6e7296e914
4)Web Cache Poisoning: Exploiting Trust in Cached Content
https://osintteam.blog/web-cache-poisoning-exploiting-trust-in-cached-content-362bb7c0d901
5)Bug Bounty Hunting Prerequisites
https://it4chis3c.medium.com/bug-bounty-hunting-prerequisites-964560919547
6)Ehxb | The Hidden Gateway CTF TryHackMe WriteUp
https://medium.com/@Ehxb/ehxb-the-hidden-gateway-ctf-tryhackme-writeup-a88fffdc98cb
7)eJPT : Host & Network Penetration Testing: Exploitation CTF 1
https://medium.com/@murat_kuzucu/ejpt-host-network-penetration-testing-exploitation-ctf-1-85cd5078e400
8)eJPT Host & Network Penetration Testing: Exploitation CTF 2
https://medium.com/@murat_kuzucu/ejpt-host-network-penetration-testing-exploitation-ctf-2-055d2969f1fe
9)Try Hack Me — Brains Write-up
https://medium.com/@cyberboar/try-hack-me-brains-write-up-9a32e6b4d5d1
10)HTB: Sightless Writeup / Walkthrough
https://medium.com/@pk2212/htb-sightless-writeup-walkthrough-ea6f492c0b3c
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
Medium
How I Found My First Bug (RXSS)
بسم الله والصلاة والسلام على نبينا المجاهد الشهيد
SOC 2 Trust Services Criteria Checklist
Map your Security, Availability, Integrity, Confidentiality & Privacy controls with this simple, practical guide.
https://hetmehta.com/soc2-tsc
Map your Security, Availability, Integrity, Confidentiality & Privacy controls with this simple, practical guide.
https://hetmehta.com/soc2-tsc
Powershell For Hackers: Exploitation Essentials
Practical guide on how to use PowerShell for hacking and penetration testing.
https://hetmehta.com/posts/powershell-for-hackers
Practical guide on how to use PowerShell for hacking and penetration testing.
https://hetmehta.com/posts/powershell-for-hackers
hetmehta.com
PowerShell for Hackers: Exploitation Essentials | hetmehta.com
A red teamer’s guide to PowerShell for post-exploitation: enum, privesc, persistence, and C2
10 FREE courses with certificates to boost your SIEM skills!
https://x.com/hetmehtaa/status/1912962144729203108
https://x.com/hetmehtaa/status/1912962144729203108
X (formerly Twitter)
Het Mehta (@hetmehtaa) on X
Splunk is offering 10 FREE courses with certificates to boost your SIEM skills!
Check it out! 🧵
Check it out! 🧵