Been a long while since Story Time…
I don’t know why this popped into my head, but perhaps there’s something in it someone will find helpful.
So here goes
Recovering a Linux backdoor that is still running but was deleted off disk:
• Check the /𝗽𝗿𝗼𝗰/𝗣𝗜𝗗 directory for the running process
• If 𝐫𝐞𝐜𝐨𝐯𝐞𝐫𝐞𝐝_𝐞𝐱𝐞 is in it, thats the reconstructed executable.
#linux#forensics#dfir
On 𝗔𝘂𝗴 𝟭𝟯 𝟭𝟮 𝗣𝗠 𝗘𝗦𝗧, I am presenting on MS Quick Assist and how we're seeing it used in attacks. More importantly, how to perform investigations and forensics on MSQA attacks.
Register here: https://t.co/JDObtGHBDy
#DFIR#forensics
A friend of mine - @OpenHeartGames - is running a D&D game all day for Extra Life. Drop by their stream and donate to a good cause!
https://t.co/JzroIhmkSb
#dnd#rpg