It was such a great workshop with our amazing IR team. Discuss RootKit topics with an expert team led to trying different ways of thinking and approaching new hunting techniques. (examining the code is under your responsibility :).
https://t.co/byIEaNgk89
Cryptography concepts introduction for beginners with practical examples in Linux (openssl) (@sergioprado)
Part 1: https://t.co/2GoJH5Uqdp
Part 2: https://t.co/mhkaDWoQ5J
Part 3: https://t.co/HR5lsJThb9
Part 4: https://t.co/XsDOnPzOP6
#cryptography#infosec
🚀Just published a new blog post comparing telemetry on Linux vs. Windows! Dive into the differences in how these platforms handle telemetry for incident response operations.
🔍 It provides answers to the below questions and many more:
•Why is Windows telemetry easier to manage than Linux?
•How do Linux and Windows differ in capturing and interpreting telemetry?
•What are the challenges of aligning telemetry strategies across both platforms?
‼️Plus, exciting news about my EDR Telemetry project expanding to Linux! Check it out here: https://t.co/ZEdmnxf8y7
The conference website is live!
https://t.co/MMaX9RganZ
CFP is now open and training tickets are open as well. General ticket sales live in three weeks!
I decided to create a tutorial called "Reversing Windows Internals" and explain about Windows Internals.
The first part describes about Handles, Callbacks and Hidden Callbacks and ObjectTypes in Windows
Thanks to @Dark_Puzzle for answering my questions.
https://t.co/wF0q7qlbiX
Understanding the #pe file format is key to #reverse#engineering windows executables. If you need help, I have a playlist with over 4 hours of content covering many of the most important aspects on #youtube 👇
▶️ https://t.co/qZYG8qbARC
سنقدم أنا وصالح بن محيسن @saleh_muhaysin
تدريب متقدم للاستجابة للحوادث في مؤتمر #blackhatmea و سنغطي الأساليب الحديثة للاستجابة للحوادث واسعة النطاق والحوادث المؤسسية.
حيث سكبنا جل خبرة سنوات طويلة في تقديم خدمات ال #DFIR محليًا ودوليًا بتدريب عملي
https://t.co/s9m5StSC4x
اشكر الزملاء في اكاديمية طويق على تنظيم هذا اللقاء..
ننتظركم..
ملاحظات:
- يفضل وجود خلفية تقنية
- معرفة عامة بالبرمجة ويفضل Python
- خبرة ولو بسيطة في ال Reverse Engineering وال Binary Analysis
Hi!
I updated my artifact collection tool (Fennec 🦊) by rewriting most of the artifact configuration file for MacOS. I also added a job to the pipeline to build Fennec for MacOS Apple silicon
Check it our here:
https://t.co/MDVNtXurTc
كل عام و أنتم بخير جميعًا، أعادة الله عليكم و من تحبون بالخير و الصحة 🌹
رمضان هذا بأكتب thread كل يوم عن artifact مختلف، ال artifacts الي بتكلم عنها بتكون من Windows و Linux. اذا فيه Artifact معن تبوني أتكلم عنه عطوني خبر
#رمضانيات_dfir#dfir#BlueTeam
#ESETResearch analyze first in-the-wild UEFI bootkit bypassing UEFI Secure Boot even on fully updated Windows 11 systems. Its functionality indicates it is the #BlackLotus UEFI bootkit, for sale on hacking forums since at least Oct 6, 2022. @smolar_m https://t.co/mXSXksRisG 1/11
MemProcFS v5.3 released! Fast memory forensics in virtual file system! Now supports Hyper-V (Normal VM, WSL, SandBox, Container, VMware/VirtualBox on Hyper-V, nested VMs), PE version info, and forwarded functions.
https://t.co/inOM3l2eyd
Kind Microsoft Employee Soul that finally added the Thread Pool data structures to the public symbols... you are loved, appreciated, and thanked beyond your wildest dreams. This will have meaningful impact on so many troubleshooting scenarios, deadlocks, race conditions, etc...
Threat hunting تصيد التهديدات
يعمل عليه جميع الفرق الدفاعية والهجومية بنطاقات مختلفة وجدت الكثير من الناس يبحث عن threat hunters وفي الواقع هي ليست تخصص و إنما تعني بكل بساطة أن لا تنتظر تنبيه من منصات المراقبة و التكنولوجيا الدفاعية لديك أو أن تحصل لك حادثة سيبرانية ولكن...
نحمد الله سبحانه أن رأينا حجاج بيته، من مختلف دول العالم، يؤدون مناسكهم بكل يسر وسهولة.
وإننا ونحن نفخر بشرف خدمة الحجاج ؛ نهنئ جميع المسلمين بعيد الأضحى المبارك، سائلين المولى أن يجعل هذا العيد، عيد خير وسلام على العالم أجمع.
وكل عام وأنتم بخير.