Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Forensic tools in your lab
Good morning, say were evaluating our current toolset and seeing if there is any good tools look into purchasing in our lab. We currently do hr investigations, security incidents and ediscovery. Our current tool sets include fex, axiom, encase, nuix, cellebrite, and blacklight. What do you guys use?

Thanks!
πŸ—£doob89

X-Ways.
Both for acquiring and in the lab.
πŸ‘€Goremageddon08

I really need to take a look at X-Ways- I see it constantly recommended.
πŸ‘€no_sushi_4_u

We use encase for acquiring, but then investigate the data with Axiom. At the moment our environment is not compatible with the remote acquisition process of Axiom and the lawyers like E01 files instead of zip, but I guess Axiom is addressing that in Cyber. I hope it ends up working because encase is a very powerful tool, but the layout and flow are far from being as user friendly and convenient as Axiom. Plus when it comes to support, encase...well..it sucks. Magnet is immediately on the task when we have any problems.
πŸ‘€barleyhogg1


πŸŽ–@malwr
Crash course on x86_64 Assembly
πŸ—£icebp

Found this on the /r/reverseengineering subreddit and thought it was really good. It takes some C examples and breaks them down in a pretty detailed and easy to understand manner. the examples are pretty simple but he covers a lot of nuances of reading assembly and I felt like I got better at some things. Hope someone finds it useful!
πŸ‘€icebp


πŸŽ–@malwr
Imperva WAF Bypass
πŸ—£kev-thehermit

Nice work.
πŸ‘€cryptogram

Wholesome stuff!
πŸ‘€crabique


πŸŽ–@malwr
[DrayTek - Unauthenticated RCE in Draytek Vigor 2960, 3900 and 300B (CVE-2020-8515)](https://www.skullarmy.net/2020/01/draytek-unauthenticated-rce-in-draytek.html)
πŸ—£cyberg0100


πŸŽ–@malwr
#Splunk Boss of the SOC v3 Dataset Released!
https://www.splunk.com/en_us/blog/security/botsv3-dataset-released.html

BOTS 3.0 includes a Tools and Training scenario to help less experienced folks gain a foothold and to help everyone get familiar with the environment. The dataset also includes a cloud scenario that illustrates security issues that organizations commonly encounter when moving workloads to Amazon AWS and Microsoft Azure.


πŸŽ–@malwr
Reading content of RAM
I was looking at the way to read what kind of data is stored in my ram. But can't find a definitive answer. Can anyone help me out?
πŸ—£sahil098

Reading the data isn't so hard. You'd need a tool which can image and dump the data...ftk imager can do it for you and is free. There are loads of others.

Deciphering it on the other hand is more difficult. You might want to read up on volatility, or you could try running a scan across the memory image for file types of interest.
πŸ‘€Briggykins


πŸŽ–@malwr