ScoutSuite 5.8.0 Released - multi-cloud security-auditing tool with AWS, Azure and GCP improvements
π£digicat
π@malwr
π£digicat
π@malwr
NCC Group Research Blog
Tool Release β ScoutSuite 5.8.0
Quick note to say weβve released ScoutSuite 5.8.0 on Github with the following features: Improved support for AWS Added support for KMS Added basic support for Secrets Manager Simplified evalβ¦
Runtime Mobile Security (RMS), powered by FRIDA, is a powerful web interface that helps you to manipulate Android Java Classes and Methods at Runtime.
π£0xn3
π@malwr
π£0xn3
π@malwr
GitHub
GitHub - m0bilesecurity/RMS-Runtime-Mobile-Security: Runtime Mobile Security (RMS) π±π₯ - is a powerful web interface that helpsβ¦
Runtime Mobile Security (RMS) π±π₯ - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime - m0bilesecurity/RMS-Runtime-Mobile-Security
[DrayTek - Unauthenticated RCE in Draytek Vigor 2960, 3900 and 300B (CVE-2020-8515)](https://www.skullarmy.net/2020/01/draytek-unauthenticated-rce-in-draytek.html)
π£cyberg0100
π@malwr
π£cyberg0100
π@malwr
CVE-2020-0863 - An Arbitrary File Read Vulnerability in Windows Diagnostic Tracking Service
https://itm4n.github.io/cve-2020-0863-windows-diagtrack-info-disclo/
π@malwr
https://itm4n.github.io/cve-2020-0863-windows-diagtrack-info-disclo/
π@malwr
itm4nβs blog
CVE-2020-0863 - An Arbitrary File Read Vulnerability in Windows Diagnostic Tracking Service
Although this vulnerability doesnβt directly result in a full elevation of privileges with code execution as NT AUTHORITY\SYSTEM, it is still quite interesting because of the exploitation βtricksβ involved. Diagnostic Tracking Service (a.k.a. Connected Userβ¦
#Splunk Boss of the SOC v3 Dataset Released!
https://www.splunk.com/en_us/blog/security/botsv3-dataset-released.html
π@malwr
https://www.splunk.com/en_us/blog/security/botsv3-dataset-released.html
BOTS 3.0 includes a Tools and Training scenario to help less experienced folks gain a foothold and to help everyone get familiar with the environment. The dataset also includes a cloud scenario that illustrates security issues that organizations commonly encounter when moving workloads to Amazon AWS and Microsoft Azure.π@malwr
Splunk
Boss of the SOC v3 Dataset Released! | Splunk
The tradition continues! We are happy to announce that the Boss of the SOC (BOTS) v3 dataset has been released under an open-source license and is available for download.
Reading content of RAM
I was looking at the way to read what kind of data is stored in my ram. But can't find a definitive answer. Can anyone help me out?
π£sahil098
Reading the data isn't so hard. You'd need a tool which can image and dump the data...ftk imager can do it for you and is free. There are loads of others.
Deciphering it on the other hand is more difficult. You might want to read up on volatility, or you could try running a scan across the memory image for file types of interest.
π€Briggykins
π@malwr
I was looking at the way to read what kind of data is stored in my ram. But can't find a definitive answer. Can anyone help me out?
π£sahil098
Reading the data isn't so hard. You'd need a tool which can image and dump the data...ftk imager can do it for you and is free. There are loads of others.
Deciphering it on the other hand is more difficult. You might want to read up on volatility, or you could try running a scan across the memory image for file types of interest.
π€Briggykins
π@malwr
Reddit
r/computerforensics on Reddit: Reading content of RAM
Posted by u/sahil098 - 7 votes and 6 comments
Cyber FastTrack Spring 2020 CTF Writeups
π£tsuto
Thank you so much! I made top 100 but with only about 50% complete and there were some that were on the "tip of my tongue" for hours but I couldn't secure the flag. First individual CTF for me so it was a learning experience but overall I had a blast.
This has been really helpful for me to learn from! Congrats on 1st and thanks a ton!
π€SentientOwl_
π@malwr
π£tsuto
Thank you so much! I made top 100 but with only about 50% complete and there were some that were on the "tip of my tongue" for hours but I couldn't secure the flag. First individual CTF for me so it was a learning experience but overall I had a blast.
This has been really helpful for me to learn from! Congrats on 1st and thanks a ton!
π€SentientOwl_
π@malwr
GitHub
GitHub - jselliott/CyberFastTrack_SP2020: A collection of writeups and solutions for the Cyber FastTrack Spring 2020 CTF
A collection of writeups and solutions for the Cyber FastTrack Spring 2020 CTF - jselliott/CyberFastTrack_SP2020