Six new challenges have been added to DFIR LABS, focused on complex malware analysis, high-fidelity threat hunting and advanced DFIR investigation. Designed to push your expertise.
If you haven’t explored DFIR LABS yet, now is the time!
https://t.co/6lgoxMDt8f
New insane challenge: Android FBE-encrypted disk - extract masterkeys from cold booted kernel memory, decrypt userdata, analyze post-exploitation artifacts, C2 activity, and ransomware analysis.
If you haven’t explored DFIR LABS yet, now is the time!
https://t.co/6lgoxMDt8f
Three insane challenges have been added to DFIR LABS, focused on evidence tampered ransomware recovery, rootkit attack chain, and macOS memory investigations. Designed to push your expertise.
If you haven’t explored DFIR LABS yet,
now is the time!
https://t.co/6lgoxMDt8f
Introducing VolExoPass - Volatility 3 plugin that extracts potential Exodus Wallet passphrases. It analyzes process VAD to recover passphrases along with their VAD allocation address, passphrase memory location, and PID.
https://t.co/F5b7IGOz7p
#volatility3
Introducing DFIR Labs: A 24-challenge series by internationally acclaimed CTF authors, tailored for professionals, researchers and students. Master DFIR, Malware Analysis and Threat Hunting through challenges designed to push your expertise to new heights
https://t.co/6lgoxMDt8f
Introducing Rust-ProcHollow: a sophisticated and efficient implementation of process hollowing now in Rust ! Complete with support for Portable Executable (PE) relocation.
https://t.co/797IxUiyEc
#Rust#Malware#Maldev#OffensiveRust#Windows
Happy to share that we clinched 1st place at #niteCTF24 this past weekend! 🏆
A big thank you to the organizers #cryptonite for a great event and congratulations to all participating teams.
#teambi0s#CTF
Coauthored an article for @SANSInstitute with my friend Abdelrhman on "Analysis of Virtual Address Descriptors" for hunting malwares, ransomware keys, notepad abuse/data recovery and detailed windows internals of a process and its memory structure.
https://t.co/JzLPsFgELC
I had fun authoring 3 DFIR challenges for International Cybersecurity Challenge Edition III, Chile which went unsolved at the end of the CTF, 2 Challenges with
@j0hith@sp3p3x
@mspr75
@hrippix_
and 1 solo.
Also Congratulations Team Europe for the victory #ICC#IC3
Just Published a tool to parse Ext4 File System of Android and Linux. it can File System, Superblock, Group Descriptor, inode, xattr, Directory, Blocks, Extent and hashtree informations. Just have to extend parsing journal and decrypting Android FBE.
https://t.co/xqWsTa3VHQ
Delve into Windows Memory Internals! Explore virtual address spaces, process internals and memory models for a deeper understanding of memory forensics & malware analysis! Third post of Malware Development, Analysis and DFIR Series
https://t.co/opkG0DZQMF
#DFIR#Memoryforensics
Start from the ground up! Learn the fundamentals of x86 assembly in my latest blog post, where I lay the groundwork for you to become a master of Malware Analysis!
Second post in Malware Development, Analysis and DFIR series out
https://t.co/66Cq2C3cp2
#MalwareAnalysis#DFIR#RE
Recruitment for upcoming freshers is now open!
Click here to get started: https://t.co/WmYuW4HgcB
*Note*: Recruitment is open only to freshers joining Amrita University, Amritapuri.
#recruitment#Cybersecurity#CTF#Security#teambi0s
Investigating and analyzing various Malwares like rootkit, ransomware, c2 and more. here is our writeup for the fourth challenge in Batman Investigation Series from bi0sctf 2024!
@sp3p3x@j0hith
@mspr75
https://t.co/DcHEI0xHRS
#dfir#malwareanalysis#windows#forensics
Investigating and analyzing various Malwares like rootkit, ransomware, c2 and more. here is our writeup for the fourth challenge in Batman Investigation Series from bi0sctf 2024!
@sp3p3x@j0hith @mspr75
https://t.co/jRfDCTKrla
#dfir#malwareanalysis
#bi0sctf 2024 has officially ended!
Congrats to the winners:
1. @thehackerscrew1
2. @r3kapig
3. @FlatNetworkOrg
We hope you enjoyed the challenges this edition, and hope to see everyone again for bi0sCTF 2025!
Please do leave your feedback at https://t.co/4zjydUflIs
Our DFIR team won first prize in The International Digital Forensics Challenge (DFC) 2023, organized by @KIISC_DFR@Azr43lKn1ght , @5h4rrK , @sp3p3x and @j0hith were invited to present at the DFRF ceremony in Seoul, South Korea.
Thank you @KIISC_DFR for this opportunity.