Micropatching Unknown 0days in Windows Type 1 Font Parsing
π£dielel
so this micropatching thing... why do that as opposed to relying only on the official Microsoft patches? pros/cons?
π€PotatOS_Cannon
π@malwr
π£dielel
so this micropatching thing... why do that as opposed to relying only on the official Microsoft patches? pros/cons?
π€PotatOS_Cannon
π@malwr
0patch - Better Security Patches
Micropatching Unknown 0days in Windows Type 1 Font Parsing
Tiny reboot-less security patches for critical vulnerabilities in Windows, Microsoft Office, and other Windows products
Forensic tools in your lab
Good morning, say were evaluating our current toolset and seeing if there is any good tools look into purchasing in our lab. We currently do hr investigations, security incidents and ediscovery. Our current tool sets include fex, axiom, encase, nuix, cellebrite, and blacklight. What do you guys use?
Thanks!
π£doob89
X-Ways.
Both for acquiring and in the lab.
π€Goremageddon08
I really need to take a look at X-Ways- I see it constantly recommended.
π€no_sushi_4_u
We use encase for acquiring, but then investigate the data with Axiom. At the moment our environment is not compatible with the remote acquisition process of Axiom and the lawyers like E01 files instead of zip, but I guess Axiom is addressing that in Cyber. I hope it ends up working because encase is a very powerful tool, but the layout and flow are far from being as user friendly and convenient as Axiom. Plus when it comes to support, encase...well..it sucks. Magnet is immediately on the task when we have any problems.
π€barleyhogg1
π@malwr
Good morning, say were evaluating our current toolset and seeing if there is any good tools look into purchasing in our lab. We currently do hr investigations, security incidents and ediscovery. Our current tool sets include fex, axiom, encase, nuix, cellebrite, and blacklight. What do you guys use?
Thanks!
π£doob89
X-Ways.
Both for acquiring and in the lab.
π€Goremageddon08
I really need to take a look at X-Ways- I see it constantly recommended.
π€no_sushi_4_u
We use encase for acquiring, but then investigate the data with Axiom. At the moment our environment is not compatible with the remote acquisition process of Axiom and the lawyers like E01 files instead of zip, but I guess Axiom is addressing that in Cyber. I hope it ends up working because encase is a very powerful tool, but the layout and flow are far from being as user friendly and convenient as Axiom. Plus when it comes to support, encase...well..it sucks. Magnet is immediately on the task when we have any problems.
π€barleyhogg1
π@malwr
reddit
Forensic tools in your lab
Good morning, say were evaluating our current toolset and seeing if there is any good tools look into purchasing in our lab. We currently do hr...
Zero Day Initiative β CVE-2020-0729: Remote Code Execution Through .LNK Files
π£thracky
π@malwr
π£thracky
π@malwr
Zero Day Initiative
Zero Day Initiative β CVE-2020-0729: Remote Code Execution Through .LNK Files
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, John Simpson and Pengsu Cheng of the Trend Micro Research Team detail a recent remote code execution bug in Microsoft Windows .LNK files. The following is a portion of theirβ¦
Crash course on x86_64 Assembly
π£icebp
Found this on the /r/reverseengineering subreddit and thought it was really good. It takes some C examples and breaks them down in a pretty detailed and easy to understand manner. the examples are pretty simple but he covers a lot of nuances of reading assembly and I felt like I got better at some things. Hope someone finds it useful!
π€icebp
π@malwr
π£icebp
Found this on the /r/reverseengineering subreddit and thought it was really good. It takes some C examples and breaks them down in a pretty detailed and easy to understand manner. the examples are pretty simple but he covers a lot of nuances of reading assembly and I felt like I got better at some things. Hope someone finds it useful!
π€icebp
π@malwr
Reverse Engineering
Applied Reverse Engineering: Accelerated Assembly [P1] - Reverse Engineering
Part 1 of the x86_64 assembly crash course for people looking to learn how to reverse engineer, read assembly, and understand how exploits work.
ScoutSuite 5.8.0 Released - multi-cloud security-auditing tool with AWS, Azure and GCP improvements
π£digicat
π@malwr
π£digicat
π@malwr
NCC Group Research Blog
Tool Release β ScoutSuite 5.8.0
Quick note to say weβve released ScoutSuite 5.8.0 on Github with the following features: Improved support for AWS Added support for KMS Added basic support for Secrets Manager Simplified evalβ¦
Runtime Mobile Security (RMS), powered by FRIDA, is a powerful web interface that helps you to manipulate Android Java Classes and Methods at Runtime.
π£0xn3
π@malwr
π£0xn3
π@malwr
GitHub
GitHub - m0bilesecurity/RMS-Runtime-Mobile-Security: Runtime Mobile Security (RMS) π±π₯ - is a powerful web interface that helpsβ¦
Runtime Mobile Security (RMS) π±π₯ - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime - m0bilesecurity/RMS-Runtime-Mobile-Security
[DrayTek - Unauthenticated RCE in Draytek Vigor 2960, 3900 and 300B (CVE-2020-8515)](https://www.skullarmy.net/2020/01/draytek-unauthenticated-rce-in-draytek.html)
π£cyberg0100
π@malwr
π£cyberg0100
π@malwr