mac_apt v0.6 is now available. Big new features-
🔐Encrypted APFS images supported
🔓T2 APFS AFF4 images supported
⏳FAST mode for quick results!
https://t.co/uPH3gTIbJH
#DFIR#mac4n6
Video demo of the NTUSER dot MAN trick I saw floating around before the new year -- I did not know this was a thing👀 Hat tip to DeceptIQ et al.... we showcase:
1. breaking a Windows login with an empty user profile,
2. getting initial access EZPZ with a Sliver C2 implant,
3. exporting, downloading, and hijacking an existing target user profile NTUSER.DAT or HKCU Registry hive,
4. converting hives from .reg plaintext to binary with the HiveSwarming.exe tool,
5. and establishing persistence with the new backdoored NTUSER dot MAN profile we upload!
No Registry writes, API calls or registry callbacks because it's just a single file placed on disk! Kinda neat.
This is my first recording after a month break for the holidays and it was _painful_ -- lots of fails and mistakes and it took many hours 😅
I'm experimenting with MEMES in the THUMBNAIL and SHORT video TITLES to MITIGATE against CLICKBAIT
Also experimenting with longer social text promos for video releases to add more preview details and context. I no longer have to just feed algorithms, but now LLMs, too!
Feels good to get something out the door again. I hope you take a look! YouTube link: https://t.co/z2mQ0m5rzq
QUANTUMSTRAND beta 1 released: built for analysts to quickly understand *where* strings are, *what* they might be, and *how* important they are, without getting lost in a sea of undifferentiated text.
Thanks @m_r_tz and the crew at @Mandiant FLARE
https://t.co/IKMi5fNM13
mac_apt v1.26.1 is here, now supports processing Velociraptor collections and compiled versions for macOS too. Many incremental updates and new plugins (we are at 52 plugins now!).
https://t.co/FB2icmZ5PZ #DFIR#macOS
Hi, #DFIR guys,
I am developing a new forensic tool for parsing journal data of #Linux filesystems (not systemd journal logs).
It can not only parse filesystem journals but also generate timeline events for DFIR.
This tool currently supports only EXT4, but I plan to add support for XFS as well.
Additionally, it can detect suspicious activities such as timestomping.
The tool is still incomplete, so it will take at least a few more weeks before the first release.
There seemed to be enough interest so I decided to do a write up on what I have found about OneDrive Offline Mode. Hate to burn a forensic artifact but I’m concerned about what Microsoft feels is secure. #DFIR
https://t.co/fMJhCCBWs5
Happy New Year! 🎉🥳 The first 13Cubed episode of 2025 is here! Let's explore some groundbreaking research from CyberCX on “rewinding the NTFS USN Journal.” https://t.co/I58MqTkg8n #DFIR
@Songrongn@KevinPagano3 No idea, but it does sometimes. Also, forgot to mention, I wrote a Velociraptor artifact to pull this information out.
https://t.co/qSJV74Ifx3
https://t.co/GfbjlvCNkv
Windows Thumbnail caches are a mostly unused artifact. Did you know they can point to paths on external systems? (Yes path embedded in thumbcache file, not from win search db) Can be helpful when threat actors actively delete logs and other artifacts! #DFIR
Hey #DFIR & #Malware community. A memory forensics case were you are required to analyze a memory dump of a Windows 10 system that has been hit with a #Ransomware. Let the games begin. Please share!
$100 bounty will be paid to whoever solves this case! https://t.co/5CCU5nDxWg