Automated approach to Memory Analysis
Hello all,
So we’re on a Project and being the sole one to do the task, I was wondering if there’s to some extent we can automate the Memory Analysis part!
Currently, I do it using Volatility Framework! I came across Volatility Bot, but saw it was last pushed 5 years back, so step aside!
Any leads could really help me in!
Thanks
🗣GloryHunter9
I usually keep a shell script to run the volatility commands I know I’ll need to run and save the output. It’s also easy to tell volatility to save in a format that you can upload to other tools for analysis. VolDiff used to have a malware-checks option that also did some cool automation, but it’s older at this point.
👤sumdude1849
Hi!
Check Crowdstrike SuperMem. I use my own script and haven’t used SuperMem like a lot but I’d say it extracts pretty much everything you need in order for you to analyze.
👤delerium46
🎖@malwr
Hello all,
So we’re on a Project and being the sole one to do the task, I was wondering if there’s to some extent we can automate the Memory Analysis part!
Currently, I do it using Volatility Framework! I came across Volatility Bot, but saw it was last pushed 5 years back, so step aside!
Any leads could really help me in!
Thanks
🗣GloryHunter9
I usually keep a shell script to run the volatility commands I know I’ll need to run and save the output. It’s also easy to tell volatility to save in a format that you can upload to other tools for analysis. VolDiff used to have a malware-checks option that also did some cool automation, but it’s older at this point.
👤sumdude1849
Hi!
Check Crowdstrike SuperMem. I use my own script and haven’t used SuperMem like a lot but I’d say it extracts pretty much everything you need in order for you to analyze.
👤delerium46
🎖@malwr
reddit
Automated approach to Memory Analysis
Hello all, So we’re on a Project and being the sole one to do the task, I was wondering if there’s to some extent we can automate the Memory...
👍1
Staging Cobalt Strike with mTLS using Caddy — blegh - client cert auth from beacons - will frustrate discovery if adopted
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
itm8.dk
Skal vi skabe nutidens og fremtidens IT sammen? itm8
Hvad er en itm8? Vi er præcis, hvad navnet siger: Din m8* (*mate), der er ekspert i IT. Vi er din partner til 360 graders IT.
New Zloader Campaign exploits Microsoft’s Signature Verification putting users at risk
🗣digicat
Dang that's dangerous
👤ItsMiggity
🎖@malwr
🗣digicat
Dang that's dangerous
👤ItsMiggity
🎖@malwr
Check Point Research
Can You Trust a File’s Digital Signature? New Zloader Campaign exploits Microsoft’s Signature Verification putting users at risk…
Research by: Golan Cohen Introduction Last seen in August 2021, Zloader, a banking malware designed to steal user credentials and private information, is back with a simple yet sophisticated infection chain. Previous Zloader campaigns, which were seen in…
NY Attorney General James Alerts 17 Companies to “Credential Stuffing” Cyberattacks Impacting More Than 1.1 Million Consumers
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
New York State Attorney General
Attorney General James Alerts 17 Companies to “Credential Stuffing” Cyberattacks Impacting More Than 1.1 Million Consumers
Click to read more.
Excited to share Part 1 of Malware RE for Beginners!
Learn about basic computing terms and assembly language from 0x0
https://www.intezer.com/blog/malware-analysis/malware-reverse-engineering-beginners/
@IntezerLabs
🗣AbbyMCH
🎖@malwr
Learn about basic computing terms and assembly language from 0x0
https://www.intezer.com/blog/malware-analysis/malware-reverse-engineering-beginners/
@IntezerLabs
🗣AbbyMCH
🎖@malwr
🔥2
Analysis of #Evilnum new attack activity (report is in chinese 🇨🇳)
http://blog.nsfocus.net/agentvxapt-evilnum/
🗣Cyber_O51NT
🎖@malwr
http://blog.nsfocus.net/agentvxapt-evilnum/
🗣Cyber_O51NT
🎖@malwr
🍎👾 Just published my annual "Mac Malware of the Year" report, for 2021:
An in-depth technical analysis of the year's new Mac malware, covering each:
💉 Infection vector
💾 Persistence mechanism
🛰 Payload and capabilities
+ samples for download! 🦠
https://objective-see.com/blog/blog_0x6B.html
🗣patrickwardle
🎖@malwr
An in-depth technical analysis of the year's new Mac malware, covering each:
💉 Infection vector
💾 Persistence mechanism
🛰 Payload and capabilities
+ samples for download! 🦠
https://objective-see.com/blog/blog_0x6B.html
🗣patrickwardle
🎖@malwr
👍1
Subdomain enumeration on your phone?
1. Install Termux.
2. pkg update && pkg insta findomain -y
3. findomain -t example.tld
You can use the same options such as -i, -r, --http-status or even perform monitoring from there.
#bugbountytips #infosec #hacking #osint #automation
🗣FindomainApp
🎖@malwr
1. Install Termux.
2. pkg update && pkg insta findomain -y
3. findomain -t example.tld
You can use the same options such as -i, -r, --http-status or even perform monitoring from there.
#bugbountytips #infosec #hacking #osint #automation
🗣FindomainApp
🎖@malwr
KQL is a powerful tool to explore data and discover patterns, identify anomalies, and more.
In this post, Microsoft DART team explained how to leverage KQL for incident response!🤓
#DFIR #infosec cc: @DebugPrivilege @msftsecresponse
https://techcommunity.microsoft.com/t5/security-compliance-and-identity/leveraging-the-power-of-kql-in-incident-response/ba-p/3044795
🗣fr0gger_
🎖@malwr
In this post, Microsoft DART team explained how to leverage KQL for incident response!🤓
#DFIR #infosec cc: @DebugPrivilege @msftsecresponse
https://techcommunity.microsoft.com/t5/security-compliance-and-identity/leveraging-the-power-of-kql-in-incident-response/ba-p/3044795
🗣fr0gger_
🎖@malwr
Day 3 of #dailyyara for #100DaysofYARA
Malware authors often statically compile OpenSSL into Windows binaries. Let's hunt some artefacts.
https://github.com/secman-pl/yaras/blob/main/hunt_PE_openssl_statically_compiled.yar
🗣secman_pl
🎖@malwr
Malware authors often statically compile OpenSSL into Windows binaries. Let's hunt some artefacts.
https://github.com/secman-pl/yaras/blob/main/hunt_PE_openssl_statically_compiled.yar
🗣secman_pl
🎖@malwr
Can You Trust a File’s Digital Signature? New Zloader Campaign exploits Microsoft’s Signature Verification putting users at risk - Check Point Research
🗣dmchell
🎖@malwr
🗣dmchell
🎖@malwr
Check Point Research
Can You Trust a File’s Digital Signature? New Zloader Campaign exploits Microsoft’s Signature Verification putting users at risk…
Research by: Golan Cohen Introduction Last seen in August 2021, Zloader, a banking malware designed to steal user credentials and private information, is back with a simple yet sophisticated infection chain. Previous Zloader campaigns, which were seen in…
Another simple .NET executable to create and add a backdoor user
Another simple but useful .NET executable that creates and adds an arbitrary user or domain user to the Local Administrators groups. Very useful for privilege escalations on Windows (i.e. unquoted service path)
Repo: https://github.com/notdodo/LocalAdminSharp
🗣d_o_d_o_
🎖@malwr
Another simple but useful .NET executable that creates and adds an arbitrary user or domain user to the Local Administrators groups. Very useful for privilege escalations on Windows (i.e. unquoted service path)
Repo: https://github.com/notdodo/LocalAdminSharp
🗣d_o_d_o_
🎖@malwr
GitHub
GitHub - notdodo/LocalAdminSharp: .NET executable to use when dealing with privilege escalation on Windows to gain local administrator…
.NET executable to use when dealing with privilege escalation on Windows to gain local administrator access - notdodo/LocalAdminSharp
New Konni Campaign Kicks Off the New Year by Targeting Russian Ministry of Foreign Affairs
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
Lumen Blog
New Konni Campaign Kicks Off the New Year by Targeting Russian Ministry of Foreign Affairs
Black Lotus Labs, the Lumen threat research team, uncovered a series of targeted actions against the Russian Ministry of Foreign Affairs.
My blogs on EDR bypasses & evasions + fuzzing FoxitReader 9.7 + Emulating File I/O for snapshot-fuzzing have been migrated to my new site:
New posts coming soon
https://www.signal-labs.com/blog
🗣Kharosx0
🎖@malwr
New posts coming soon
https://www.signal-labs.com/blog
🗣Kharosx0
🎖@malwr
Signal Labs
Blog | Advanced Offensive Cybersecurity Training Articles | Signal Labs
Offensive cybersecurity blog topics on fuzzing, vulnerability research, EDRs, advanced offensive (red-team) tooling, reverse engineering & more.
Bypass Defender AV static detection:
If you name a malicious file DumpStack.log Defender doesn't scan it.
🗣mrd0x
🎖@malwr
If you name a malicious file DumpStack.log Defender doesn't scan it.
🗣mrd0x
🎖@malwr
Here is code that will detect threads which are impersonating on Windows via the TIB/TEB.
Turns out not many threads impersonate other users on Windows 10 it would seem.
The technique can be integrated in EDR sweeps as a indicator for implant injects.
https://gist.github.com/olliencc/df200e0049fa17036d9f867e024f57ad
🗣ollieatnccgroup
🎖@malwr
Turns out not many threads impersonate other users on Windows 10 it would seem.
The technique can be integrated in EDR sweeps as a indicator for implant injects.
https://gist.github.com/olliencc/df200e0049fa17036d9f867e024f57ad
🗣ollieatnccgroup
🎖@malwr