-
I updated my APFS 010 hex editor template for my students doing APFS research. Will be beneficial for others too. Almost all known structures are in there now including encryption ones. https://github.com/ydkhatri/APFS_010 …
#mac4n6#apfsPrikaži ovu nit -
Unified Logging parser is now updated to python3. Been a while since last release, so some bugs squashed and minor update for new changes seen in catalina. Added windows exe too. https://github.com/ydkhatri/UnifiedLogReader/releases …
#mac4n6Prikaži ovu nit -
3rd tool: A parsing tool for backgrounditems.btm. This file is stored the entries of "Login Items". https://github.com/mnrkbys/bgiparser …
#DFIR#mac4n6 (3/3)Prikaži ovu nit -
2nd tool: macOS Artifact Collector is a Forensic Artifact Collection Tool for macOS. It can collect artifacts in Time Machine backups and extended attributes too. https://github.com/mnrkbys/macosac
#DFIR#mac4n6 (2/3)Prikaži ovu nit -
Hello,
#DFIR guys! Finally, I have released new 3 tools for#mac4n6 and#MalwareAnalysis for macOS. Please try them and have a nice weekend :) 1st tool: Norimaci is malware analysis sandbox for macOS. This tool was inspired Noriben sandbox. https://github.com/mnrkbys/norimaci … (1/3)Prikaži ovu nit -
Providing Context to iOS App Usage with knowledgeC.db and APOLLO http://www.mac4n6.com/blog/2020/1/13/apollo-into-the-details-with-application-activities …
#DFIR#mac4n6 -
New Year New APOLLO – Officially out of Beta iOS 13 Module Updates! http://www.mac4n6.com/blog/2020/1/13/new-year-new-apollo-officially-out-of-beta …
#DFIR#mac4n6 -
Very thorough info on the Apple Notes Protobufs! Thank you for putting it together!
#mac4n6
https://twitter.com/CiofecaForensic/status/1216689967700889600 … -
[On-Demand Webinar] Solution Engineers Tim Thorne & Stephanie Thompson use MacQuisition to walk through acquiring various Mac computers installed with APFS and/or a T2 secured Mac computer, taking the mystery away of imaging. Watch now: http://bit.ly/2sNTJjt
#DFIR#Mac4n6 pic.twitter.com/39dtQZKd1m
-
When you spend all night on a call-out and nothing seems to work but at least you set up your shiny new Macs
#mac4n6#DFIR#NERDpic.twitter.com/1bYLXazXch
-
Today is the day! I’ll be speaking about all things pattern of life and APOLLO today at 3pm Eastern! Register and join me!
#mac4n6 https://twitter.com/sansforensics/status/1179881335151824897 …
-
This is an awesome work well done @williballenthin... looks like I may have few additions to make to my#mac4n6 artifact collection https://github.com/pstirparo/mac4n6 … thanks :) Big shout also to@nicastronaut@HighViscosity@FireEye#DFIRhttps://twitter.com/williballenthin/status/1182332383783088129 … -
So, it seems that we have a “universal” jailbreak for (almost) all the iPhones.... It means the we will have soon a forensic solution for a full file system acquisition of iOS devices! Curious to see who will be the first implementing it :)
#dfir#mobileforensics#for585#mac4n6 -
-
What a coincidence! I was decoding the same artifact (SavedState) last week too.. Good writeup!
#mac4n6#DFIRhttps://www.crowdstrike.com/blog/reconstructing-command-line-activity-on-macos/ … -
Just Call Me Buffy the Proto Slayer – An Initial Look into Protobuf Data in Mac and iOS Forensics http://www.mac4n6.com/blog/2019/9/27/just-call-me-buffy-the-proto-slayer-an-initial-look-into-protobuf-data-in-mac-and-ios-forensics …
#DFIR#mac4n6 -
Congrats to the newest Mac Lethal Forensicators! Team Mac N’ Cheese!
#mac4n6#SANSNetworkSecuritypic.twitter.com/Pbq9mKaidq
-
Siri is so eager to learn about Mac forensics with
@blackbagtech#DFIRk9#mac4n6 pic.twitter.com/jkZe8ILtFA
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.