Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @forensic_matt
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @forensic_matt
-
It's no
@EricRZimmerman GUI, but, it does allow you to reformat and filter JSONL on the fly! Use it with the#rustlang#dfir listener tools to make output a little easier to read! What does it look like when a file is wiped with tool x? Get binaries here: https://github.com/forensicmatt/JsonlTools/releases …pic.twitter.com/AgvKaHVkA2
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Matthew Seyer proslijedio/la je Tweet
#FF#DFIR MUS speakers:@AlexisBrignoni@i_am_the_gia@binaryz0ne@tmesick1@bigt252002@warren_kruse @SJC_CyberCrime@BriannaDrummon4@OSINTlabworks@CindyMurph@jtrajewski@brianjmoran@Stanley142@SwiftForensics@nerdiosity@LitMoose@Forensic_matt@HECFBlogPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Matthew Seyer proslijedio/la je Tweet
I updated my APFS 010 hex editor template for my students doing APFS research. Will be beneficial for others too. Almost all known structures are in there now including encryption ones. https://github.com/ydkhatri/APFS_010 …
#mac4n6#apfsPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The event, usn, and mft listeners are now all in one spot and better than ever! Get them all here: https://github.com/forensicmatt/RsWindowsThingies/releases/tag/v0.4.0-alpha-4 …
#DFIR#rustlangHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
More major thanks to
@OBenamram! He helped me restructure some listening back end things so in the near future I will be able to pass values in real time to a@EricRZimmerman GUI tool!! Beats seeing the JSON values fly by on the CLI.#DFIR#rustlangHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Matthew Seyer proslijedio/la je Tweet
Super grateful for the opportunity to speak about chaos with one of my favorite humans and partner in crime(fighting),
@nerdiosity ! Also live music & DFIRfit shenanigans with@B1N2H3X ,@CindyMurph ,@brianjmoran ,@AlexisBrignoni@i_am_the_gia,@KevinPagano3 &@forensic_matthttps://twitter.com/MagnetForensics/status/1219694750829285379 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Matthew Seyer proslijedio/la je Tweet
This Friday 1/24/20 the
#forensiclunch live at Noon CST (UTC -6) with@_RyanBenson talking about Unfurl and@B1N2H3X@OSINTlabworks talking about automation workflows and the Magnet User Summit 2020#MUS2020!#DFIRhttps://youtu.be/Vh6lhKWwIS8Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Matthew Seyer proslijedio/la je Tweet
Honored to be a part of the
#DFIRSummit advisory board and to get to work with some of those who will be sharing their work. The CFP for the@sansforensics#DFIR Summit is open: http://www.sans.org/u/YDc https://twitter.com/SANSJen/status/1217891304291651585 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Added USN monitoring to trigger when an MFT entry gets touched to allow for real-time MFT entry watching. The more I do this the more I realize how interdependent all these components are. In this example, I create a hardlink and see the MFT changes.
#DFIR#rustlangpic.twitter.com/MqVdA8Wq8jHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Matthew Seyer proslijedio/la je Tweet
#DFIR PSA: https://github.com/omerbenamram/evtx … just got even faster on 0.6.5. Especially if you are running it under windows (3x increase for `evtx_dump`)! Linux is also faster by 30-40%!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Matthew Seyer proslijedio/la je Tweet
Friday wisdom: Find friends that want to geek out on the sort of stuff that everyone else says "um, so what" about.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thanks
@HECFBlog and@lee_whitfield for the good time! If you want to play with the MFT comparison tool as featured, you can find it here: https://github.com/forensicmatt/RsWindowsThingies/releases/tag/v0.4.0-alpha-3 … Special shout-out to@OBenamram. He makes cool things possible.#DFIR#rustlanghttps://twitter.com/HECFBlog/status/1214374729269891077 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Want to play with the listen_mft tool? Get the compiled binary here: https://github.com/forensicmatt/RsWindowsThingies/releases/tag/v0.4.0-alpha-3 … What attributes changed when I used Python to change the file handle's timestamps? It does require vcruntime140... sorry. Will get static compiling one of these days.
#rustlang#DFIRpic.twitter.com/pibJYjEL2R
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Matthew Seyer proslijedio/la je Tweet
This Friday 1/10/20 at Noon CST (UTC -6) the
#forensiclunch with all your#DFIR goodness.https://youtu.be/6FaeuxT89CkHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
When doing MFT entry comparison. Separating the attributes by type.attribute_id does a better job at showing when an attribute of a certain type gets deleted/created and its new values. Next up? Use USN monitor to monitor MFT entry. Right now its user invoked.
#DFIR#rustlangpic.twitter.com/7PHEVUNFWF
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The MFT entry comparison tool is getting there! Changes in attributes before and after a rename was performed. Still lots to do, but I already like it. Better formatting next.
#DFIR#rustlangpic.twitter.com/18gFlwFKwR
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Matthew Seyer proslijedio/la je Tweet
Updated spotlight_parser to read iOS databases today! https://github.com/ydkhatri/spotlight_parser …
#mac4n6#DFIRPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I'm planning to make a MFT differencing tool. It will allow you to view differences in MFT attribute values as you interact/make changes to the file/entry.
@OBenamram's mft lib + Win API for the win.#DFIR#rustlangHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I have been enjoying getting to know the Windows API creating my
#rustlang#dfir monitors. USN is great! But, it doesnt contain full paths. How do I enumerate them on the fly? I use DeviceIoControl + FSCTL_GET_NTFS_FILE_RECORD!#DailyDFIR https://github.com/forensicmatt/RustyUsn …pic.twitter.com/bN0JLFoCJK
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Added the ability to listen to events remotely using EVT_RPC_LOGIN. EvtOpenSession allows you to use the Windows event log api functions on a remote machine. Fun for seeing what actions generate what events without needing to run locally!
#rustlang#dfir https://github.com/forensicmatt/RsWindowsThingies/releases/tag/v0.4.0-alpha-2 …pic.twitter.com/yqDWB03Rf7
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

