Meta tags:
description= Increase security awareness. Promote, reinforce and learn security skills.;
Headings (most frequently used words):
security, and, on, analysis, plugx, intro, to, american, fuzzy, lop, fuzzing, count, upon, increase, awareness, promote, reinforce, learn, skills, fireeye, endpoint, hx, supplementary, tools, notes, linux, memory, lime, volatility, lkm, six, years, ago, digital, forensics, artifacts, left, behind, malware, part, with, asan, beyond, in, steps, follow, me, twitter, recent, posts, archives, categories, tags, authors,
Text of the page (most frequently used words):
the (747), and (348), that (171), you (119), this (114), with (109), for (92), from (88), memory (72), can (72), system (70), use (65), afl (65), could (62), are (54), have (46), will (44), file (43), using (43), was (43), #security (41), analysis (40), #fuzzing (40), plugx (39), used (39), volatility (34), different (34), tools (33), windows (33), time (32), attacker (32), but (32), kernel (31), about (30), which (30), perform (30), artifacts (29), might (29), one (29), case (29), incident (28), after (28), some (28), start (27), https (27), code (27), other (26), fireeye (26), com (25), linux (25), how (25), data (25), not (25), forensics (24), ntfs (24), when (24), then (24), version (24), help (24), iocs (24), asan (23), article (22), your (22), response (21), 2018 (21), has (21), there (21), create (21), analyze (21), files (21), github (21), new (20), capture (20), into (20), address (20), technique (20), event (20), lime (19), target (19), written (19), crash (19), controller (19), payload (19), hxtool (19), tcpdump (18), directory (18), because (18), run (18), example (18), need (18), plugin (18), its (17), also (17), logs (17), module (17), shimcache (16), cve (16), 2017 (16), part (16), look (16), would (16), should (16), find (16), input (16), such (16), following (16), were (16), real (16), them (15), executed (15), detect (15), exe (15), reptile (15), techniques (14), digital (14), 2014 (14), prefetch (14), fuzz (14), step (14), done (14), been (14), operating (14), tool (14), allows (14), process (14), environment (14), below (14), set (14), scenario (14), threat (13), 2015 (13), order (13), endpoint (13), see (13), all (13), shows (13), command (13), what (13), more (13), function (13), another (13), able (13), ioc (13), network (12), malware (12), steps (12), bug (12), session (12), things (12), where (12), understand (12), like (12), operator (12), registry (12), amcache (12), now (11), may (11), 2016 (11), buffer (11), source (11), running (11), get (11), likely (11), packet (11), released (11), good (11), modules (11), access (10), 2013 (10), stack (10), left (10), pdf (10), today (10), open (10), first (10), want (10), specify (10), compile (10), execution (10), they (10), systems (10), binary (10), information (10), mft (10), logfile (10), available (10), script (10), editor (10), red (9), search (9), enterprise (9), record (9), american (9), lop (9), results (9), before (9), increase (9), crashes (9), each (9), check (9), corpus (9), work (9), last (9), under (9), many (9), compiler (9), control (9), point (9), two (9), bit (9), created (9), features (9), settings (9), persistence (9), description (9), disk (9), parse (9), team (8), november (8), based (8), master (8), fuzzy (8), next (8), print (8), over (8), read (8), screen (8), finally (8), test (8), needs (8), uses (8), going (8), download (8), size (8), looking (8), downloaded (8), install (8), condition (8), leave (8), user (8), remote (8), addition (8), picture (8), previous (8), these (8), track (8), obtained (8), forensic (8), server (8), timeline (8), contains (8), production (8), website (7), comment (7), intrusion (7), dll (7), change (7), behind (7), notes (7), guide (7), improve (7), hncp (7), number (7), started (7), across (7), michal (7), node (7), fuzzer (7), inside (7), make (7), having (7), directories (7), program (7), path (7), well (7), known (7), www (7), service (7), image (7), among (7), leverage (7), however (7), domain (7), versions (7), builder (7), mechanism (7), functionality (7), superfetch (7), evidence (7), metadata (7), audit (7), application (7), microsoft (7), records (7), python (7), attribute (7), acquisition (7), rootkit (7), plugins (7), rootkits (7), profile (7), framework (7), terms (7), live (7), name (6), count (6), upon (6), january (6), april (6), june (6), journal (6), years (6), lkm (6), 13044 (6), tagged (6), org (6), let (6), variety (6), due (6), allow (6), found (6), three (6), important (6), deterministic (6), paths (6), most (6), captures (6), bytes (6), sample (6), installed (6), clang (6), llvm (6), his (6), cause (6), via (6), list (6), than (6), between (6), obtain (6), mode (6), determine (6), maintain (6), why (6), compromised (6), active (6), database (6), old (6), ntdsutil (6), space (6), still (6), either (6), timestamps (6), scale (6), introduced (6), api (6), syscall (6), market (6), write (5), report (5), log (5), testing (5), openioc (5), hacker (5), december (5), october (5), february (5), indx (5), indicators (5), intro (5), html (5), format (5), small (5), parser (5), discovered (5), quick (5), means (5), cases (5), without (5), output (5), identify (5), against (5), coverage (5), don (5), easy (5), way (5), better (5), release (5), interesting (5), compiled (5), share (5), any (5), particular (5), related (5), being (5), http (5), support (5), fault (5), during (5), msan (5), debug (5), symbols (5), few (5), instead (5), just (5), worth (5), tell (5), give (5), dependencies (5), free (5), others (5), actions (5), perspective (5), interface (5), folder (5), hide (5), malicious (5), online (5), method (5), several (5), acquired (5), regripper (5), filename (5), hve (5), applications (5), joakim (5), schicht (5), etc (5), attributes (5), diaphormine (5), threats (5), acquire (5), side (5), volshell (5), hat (5), goauditparser (5), awareness (5), ability (5), apps (5), loading (4), comments (4), view (4), blog (4), intelligence (4), log2timeline (4), infrastructure (4), 2012 (4), august (4), march (4), reports (4), hunting (4), appcompatprocessor (4), sessions (4), six (4), posts (4), click (4), documentation (4), references (4), fun (4), catch (4), bugs (4), causes (4), leak (4), show (4), status (4), stages (4), very (4), reading (4), properly (4), instructions (4), cpu (4), ramdisk (4), starting (4), unique (4), line (4), only (4), same (4), essentially (4), had (4), does (4), practice (4), contents (4), defined (4), gcc (4), easily (4), powerful (4), software (4), entry (4), targets (4), out (4), given (4), specially (4), trace (4), addresssanitizer (4), 2011 (4), fast (4), reported (4), quickly (4), fix (4), value (4), state (4), therefore (4), right (4), illustration (4), skills (4), while (4), programs (4), compiling (4), installing (4), works (4), existing (4), management (4), functions (4), table (4), deploy (4), laterally (4), utility (4), hijacking (4), volume (4), organization (4), upload (4), execute (4), dropped (4), admin (4), tab (4), define (4), specific (4), including (4), web (4), build (4), thing (4), logged (4), won (4), here (4), identifying (4), leads (4), eric (4), zimmerman (4), kas (4), ballenthin (4), feature (4), mandiant (4), stored (4), recover (4), investigation (4), special (4), articles (4), didn (4), loadable (4), detection (4), research (4), walters (4), android (4), post (4), patched (4), pristine (4), structures (4), dump (4), additional (4), installation (4), rich (4), hooking (4), sys_call_table (4), handler (4), hooks (4), proc (4), dwarf (4), sweeps (4), product (4), 100 (4), objects (4), 6401 (4), required (3), site (3), wordpress (3), account (3), sogu (3), training (3), handling (3), common (3), anniversary (3), september (3), july (3), yara (3), rig (3), exploit (3), kit (3), extract (3), compromise (3), beyond (3), supplementary (3), follow (3), papers (3), job (3), library (3), stay (3), tuned (3), presented (3), corruption (3), maintainers (3), seems (3), hangs (3), writes (3), consider (3), least (3), metric (3), performs (3), second (3), much (3), nodes (3), within (3), queue (3), sure (3), tuning (3), performed (3), checking (3), bits (3), cores (3), invoke (3), suffix (3), cmin (3), toolkit (3), amount (3), needed (3), reduce (3), ideal (3), instrumentation (3), feed (3), instrument (3), aka (3), assembly (3), engineering (3), knowledge (3), observe (3), thus (3), finding (3), visibility (3), vulnerability (3), triage (3), topics (3), learn (3), richard (3), google (3), sanitizers (3), wiki (3), material (3), exploitability (3), strings (3), who (3), triggers (3), break (3), error (3), produce (3), addresses (3), even (3), those (3), kind (3), generate (3), details (3), continue (3), sake (3), options (3), hopefully (3), illustrates (3), add (3), leveraging (3), combine (3), keep (3), try (3), malloc (3), shadow (3), keeps (3), regions (3), summary (3), move (3), shell (3), delete (3), copy (3), commands (3), form (3), capability (3), svchost (3), hive (3), string (3), previously (3), usnjrnl (3), listed (3), named (3), creating (3), creation (3), sys (3), modification (3), proper (3), sysmon (3), appcompat (3), experience (3), compatibility (3), stores (3), wealth (3), plaso (3), called (3), unallocated (3), main (3), placed (3), transaction (3), operations (3), contain (3), tree (3), reused (3), originally (3), wrote (3), reference (3), diamorphine (3), 2008 (3), prologue (3), jmp (3), port (3), since (3), modified (3), match (3), visible (3), profiles (3), necessary (3), andrew (3), published (3), sylve (3), responders (3), sweep (3), openioc2hxioc (3), alerts (3), bulk (3), redline (3), analyst (3), flask (3), 2020 (3), extend (3), content (2), sign (2), subscribed (2), subscribe (2), angel (2), alonso (2), ricardo (2), dias (2), sans (2), penetration (2), monitoring (2), essentials (2), exploitation (2), blockchain (2), 2019 (2), 2021 (2), unleashing (2), journaling (2), dridex (2), loader (2), interactive (2), ago (2), older (2), 12989 (2), effective (2), comes (2), project (2), soon (2), compilers (2), speed (2), bigger (2), resp (2), infinite (2), loop (2), initially (2), taking (2), fixed (2), dhcpv4_print (2), frame (2), couple (2), increasing (2), analyzing (2), week (2), simple (2), structure (2), non (2), future (2), stage (2), rounds (2), whatsup (2), executes (2), printout (2), core_pattern (2), scaling (2), governor (2), slave (2), reduced (2), per (2), instance (2), manager (2), indicate (2), save (2), flag (2), headers (2), large (2), exercise (2), quantity (2), fuzzed (2), changed (2), around (2), collect (2), key (2), 1024 (2), mandatory (2), readme (2), writing (2), researcher (2), versatile (2), level (2), doesn (2), background (2), goal (2), lead (2), combined (2), traditional (2), makes (2), broad (2), take (2), likelihood (2), reach (2), hard (2), perhaps (2), tested (2), luckily (2), algorithm (2), performance (2), changes (2), zalewski (2), discovery (2), automation (2), shared (2), harder (2), never (2), johnson (2), peruvian (2), rabbit (2), 8754 (2), 8050 (2), page (2), memorysanitizer (2), conference (2), atc12 (2), blackhat (2), docs (2), chromium (2), questions (2), libevt (2), bounds (2), values (2), promptly (2), analyzed (2), segmentation (2), described (2), weeks (2), sleuthkit (2), faults (2), gdb (2), setting (2), debugging (2), noteworthy (2), attempt (2), wanted (2), something (2), prefix (2), length (2), listing (2), conditions (2), 0x98 (2), nonetheless (2), somehow (2), saved (2), pointer (2), boundary (2), purposes (2), exploration (2), overflow (2), degree (2), root (2), overall (2), aspect (2), nowadays (2), professional (2), produced (2), chance (2), occurred (2), skill (2), mention (2), sanitizer (2), helps (2), allocated (2), brevity (2), newer (2), happened (2), asan_options (2), instances (2), rather (2), libpcap (2), flags (2), respectively (2), wrapper (2), did (2), faster (2), txt (2), requires (2), lot (2), possible (2), option (2), replaces (2), custom (2), properties (2), apt (2), briefly (2), looked (2), speak (2), built (2), course (2), capabilities (2), payloads (2), display (2), relevant (2), pictures (2), unc (2), perflogs (2), workstation (2), formats (2), array (2), deploying (2), call (2), itself (2), communicate (2), inject (2), binaries (2), dns (2), connect (2), specified (2), decode (2), gives (2), group (2), paranoid (2), actor (2), url (2), scope (2), saw (2), reconnaissance (2), foothold (2), established (2), accomplish (2), lifecycle (2), please (2), activities (2), ones (2), findings (2), proxy (2), identified (2), activity (2), pagefile (2), dates (2), harlan (2), carvey (2), services (2), standart_information (2), copies (2), achieve (2), willi (2), mattias (2), bevilacqua (2), ensure (2), recently (2), hash (2), shimcacheparser (2), remains (2), overview (2), app (2), stuff (2), customer (2), technology (2), advance (2), vista (2), enhanced (2), extension (2), longer (2), present (2), william (2), consistent (2), both (2), raw (2), poorbillionaire (2), usn (2), carver (2), grows (2), developed (2), mind (2), recovery (2), every (2), recorded (2), transactions (2), commit (2), i30 (2), names (2), searches (2), until (2), mft2csv (2), resides (2), seen (2), stamps (2), collected (2), community (2), useful (2), short (2), people (2), art (2), detecting (2), mac (2), advanced (2), nist (2), dfir (2), dfrws (2), fatkit (2), paper (2), repeat (2), further (2), looks (2), tcp4_seq_show (2), hook (2), acquiring (2), mentioned (2), linux_hidden_modules (2), ighor (2), augusto (2), khook (2), presentation (2), linux_check_kernel_inline (2), processes (2), linux_check_syscall (2), hooked (2), sys_kill (2), bad (2), linux_check_modules (2), sysfs (2), appear (2), hiding (2), supports (2), message (2), interested (2), zip (2), redhat (2), transfer (2), removable (2), media (2), come (2), requirements (2), phase (2), directly (2), happens (2), exact (2), building (2), packages (2), aaron (2), book (2), added (2), moment (2), devices (2), joy (2), represent (2), develop (2), uploaded (2), gui (2), xml (2), customized (2), designed (2), require (2), mainthread (2), info (2), 8080 (2), ctrl (2), itsdangerous (2), markupsafe (2), jinja2 (2), werkzeug (2), pycryptodome (2), tinydb (2), dateutil (2), numpy (2), pytz (2), pandas (2), 4337 (2), mib (2), delta (2), rights (2), ring (2), endpoints (2), provides (2), takes (2), alerting (2), ioce (2), msi (2), hand (2), artefacts (2), products (2), freeware (2), subscription (2), tend (2), edr (2), promote (2), reinforce (2), email, collapse, bar, manage, subscriptions, reader, privacy, already, join, 175, subscribers, parrizas, luis, rocha, authors, sql, injection, hands, remnux, honeypot, gaining, 2551, cryptowall, botnet, tags, uncategorized, gamification, criteria, categories, archives, retefe, banking, trojan, evolution, overflows, abc, cyber, brainwallet, cracking, offensive, boot, eternalpetya, recent, tweets, twitter, collection, workflows, finish, gdssecurity, labs, mbed, tls, jurczyk, thoughts, tarball, tutorial3, permits, enter, resp_get_length, otto, airamo, antti, levomäki, bhargava, shastry, fuzzers, wait, lucky, seeing, hours, slowly, came, stop, cycles, plays, role, completed, favored, pending, third, quite, indicating, isn, explicit, intent, copied, core, parallelize, jobs, terminal, followed, separated, verbose, parameter, replace, minimized, prepared, onto, pcaps, minimization, concluded, 273, instrumented, ready, prepare, mangled, collecting, gigabytes, sources, containing, protocols, editcap, exported, chunks, packets, allowed, factor, matter, tough, wireshark, decided, tcpump, mainly, extracted, variables, replacement, latest, 52b, ubuntu, magic, store, quality, anyone, renowned, respected, polish, brilliant, piece, reduces, significantly, someone, scalable, intelligent, random, inputs, genetic, algorithms, whatsoever, expects, especially, suited, flow, constantly, adapt, calibrate, grow, trigger, dynamic, deep, less, bottom, thoroughly, deliver, box, far, superior, blind, lcamtuf, attending, workshop, rolled, sleeves, practicing, coder, grasp, late, mar, 10105, 10104, 10103, adresssanitizer, usenix, final39, materials, branco, dptrace, dual, purpose, devstreaming, apple, videos, wwdc, 413eflf3lrh1tyo, 413, 413_advanced_debugging_and_the_address_sanitizer, credits, thanks, aleksey, cherepanov, enthusiasm, valued, willingness, ending, ideas, rui, reis, libevt_record_values_read_event, libevt_record_values, sid, joachim, metz, af_get_page, lib, afflib_pages, cpp, afflib, afflibv3, through, attackers, denial, corrupt, aff, unexpected, pagesize, phillip, hellewell, various, affutils, respective, update, disclosed, acknowledged, episode, plus, exploitable, printscreen, breakpoint, responsible, load, __asan_report_error, peda, debugger, changing, byte, mapped, protocol, question, rfc7788, trial, field, hex, mapping, 0x1f, ndo_printf, range, 0x25, couldn, printed, merged, return, bypass, aslr, overrun, sizes, adjacent, printf_common, cve2017, pcap, minutes, myself, controlling, outcomes, reached, vendor, maintainer, entity, provide, greater, reporting, economical, incentives, significant, opinion, race, measures, adopted, depth, internals, assess, remarkable, apart, uninitialized, reads, occur, tries, showing, symbolized, symbolize, asan_symbolizer_path, usr, bin, symbolizer, grep, outlined, put, fact, intensive, eventually, lifetime, drive, ssd, m32, produces, fsanitize, fno, omit, traces, correct, architecture, freshly, resolve, architectures, showed, notes_for_asan, document, virtual, certain, circumstances, consumption, instability, suggests, enforce, limit, hard_rss_limit_mb, detector, konstantin, serebryany, derek, bruening, alexander, potapenko, dmitry, vyukov, runtime, errors, heap, leaks, marks, areas, zones, sort, poisons, surrounding, fuzy, apr, buider, focusing, uncover, hidden, traits, configured, noted, accomplished, md5, 534d28ad55831c04f4a7a8ace6dd76c3, lenovo, rgb, lcd, thinkpad, tplcdclr, steve, gibson, benchmarking, sep_ne, kaspersky, outlines, apologetic, consequence, ntds, dit, goals, illustrate, choice, wmi, browse, executable, shellcode, plugged, delivery, powershell, msbuild, enable, keylogger, self, schedule, recording, screenshots, frequency, encrypted, injected, choose, hollowing, telling, fails, reason, simplicity, campaing, password, fetched, pastebin, turn, redirect, dzksafaahhhhhhoccgfhjgmgegfgchocdgpgngdzjs, fabien, perigaud, palo, alto, unit42, ilustrates, cedric, pernet, winnti, abuses, communications, uncovered, points, say, impacted, block, controls, normal, reaction, concerns, ttp, tactics, procedures, conducting, efficient, containment, eradication, unknown, campaigns, preferred, hosts, english, fetch, campaign, diagram, mimic, know, normally, predictable, sequence, events, initial, establish, escalate, privileges, internal, complete, mission, skip, focus, lateral, movement, simulate, moved, operate, attack, happy, dealt, answer, investigative, depending, greatly, complement, firewall, router, ids, networking, clearing, bat, clean, illustrated, tom, lancaster, esmid, idrizovic, unit, interactively, enabled, usefull, interactions, long, parent, little, big, endian, leaves, accessed, producing, keys, 7009, 7030, 7035, 7036, 7040, 7023, 7045, recmd, console, history, cmdscan, consoles, discrepancy, spot, anomalies, processor, stomp, entries, outside, syswow64, folders, matching, manipulated, ntdll, signatures, resulted, combination, 4688, amcacheparser, stand, alone, replaced, recentfilecache, bcf, similar, predecessor, full, sha1, commonly, location, standard, exist, shimcachemem, appcompatcacheparser, backward, erating, legacy, acts, layer, tim, newton, demystifying, shims, compat, valuable, cache, tracks, adam, witt, win, dows, 2003, analyses, frequently, preloads, booting, launching, improved, systemroot, original, times, policy, success, failures, deletes, possibility, evtxtract, explorer, evtx, libevtx, utils, depends, turned, impacting, system32, winevt, 4624, 4625, answers, usnjrnl2csv, shouldn, overlooked, allocates, deallocates, overwritten, unlike, carve, logfileparser, kept, redo, undo, inconsistencies, consulted, chkdsk, default, 65536, our, deletion, renaming, consists, index_root, index_allocation, bitmap, sorted, balances, deleted, slack, gets, once, existed, indxparse, kristinn, gudjonsson, brian, carrier, partition, accessible, hierarchical, series, indicates, physical, inactive, usually, standard_information, mace, action, conducts, artifact, past, mounting, processing, images, super, timelines, meaningful, jun, hobby, spare, illustrations, thought, till, 112, friends, took, akismet, statistics, 208k, views, 135k, visitors, months, reasons, really, appreciate, incentive, 2024, hope, contributing, alley, internet, always, evolving, fascinating, industry, 4th, born, weekend, 6th, nov, for526, h2hconference, f0rb1dd3n, m0nad, volatilityfoundation, nvlpubs, gov, nistpubs, specialpublications, 800, 61r2, halpomeranz, lmg, omfw, volatilesystems, blogspot, pyflagvolatility, wins, 4tphi, net, fatkit_journal, presentations, 504ensicslabs, youtube, watch, owkoyphlmm8, nothing, experiences, feedback, satisfied, filleonedir, detected, adjustable, checks, comparison, jump, linux_check_inline_kernel, investigate, shown, futher, compromising, static, knocking, hood, ilya, matveychikov, h2hc, são, paulo, brasil, patches, instruction, linux_check_syscal, fillonedir, filldir, filldir64, compat_fillonedir, compat_filldir, compat_filldir64, __d_lookup, tgid_iter, next_tgid, connections, udp4_seq_show, syscalls, 217, kallsyms, corresponds, sys_getdents, sys_getdents64, loaded, compare, basically, captured, ran, linux_moddump, worked, tried, uncertain, linux_volshell, brendan, dolan, gavitt, ilustration, usage, 128, ascii, insertion, pid, referent, bash, victor, mello, kernels, specifically, kill, getdents, getdents64, making, infecting, inline, ret, lists, pointers, compares, displayed, discrepancies, region, scans, appearing, laying, determining, backdoored, publicly, review, map, zipped, together, place, dealing, rpm, libdwarf, contained, met, insmod, told, sent, remove, rmmod, package, retrieved, made, copying, commercial, business, santiago, world, preparation, prepares, trains, volaility, pre, hardly, staging, pivot, segments, yes, acquires, aid, efforts, driver, interpret, matches, straightforward, dwardfump, sometimes, libraries, elf, utilities, sensible, standpoint, hal, pomeranz, experienced, grabber, michael, hale, ligh, jamie, levy, wiley, subject, nick, petroni, volatools, 2007, challenge, modular, combines, month, samples, supported, back, joe, lodovico, marziale, golden, shmoocon, gave, titled, precursor, extractor, investigators, dmd, volatile, infected, oct, administration, increases, efficiently, serves, handle, incidents, intrusions, design, adopt, filters, conjunction, filter
Text of the page (random words):
hat patches a function prologue with a jmp instruction with the volatility linux_check_syscal plugin we can t detect this hooking technique since the syscall handler addresses have not been modified but it can be identified with linux_check_kernel_inline among other things reptile hooks fillonedir filldir filldir64 compat_fillonedir compat_filldir compat_filldir64 __d_lookup to hide processes it hooks tgid_iter and next_tgid to hide network connections it hooks tcp4_seq_show and udp4_seq_show the following illustration shows as an example the reptile installation on a red hat 6 10 system after compromising a system with reptile and acquiring a memory capture i executed the mentioned plugins i started with linux_hidden_modules to look for lkm structures in the kernel memory volatility was able to find the reptile lkm then we could dump the module to disk and perform additional static analysis the other plugin executed is linux_check_inline_kernel it was able to detect several network related functions that were patched by the reptile code i didn t had time to further investigate why the hook address is not shown but we can get futher details with volshell the following picture shows a comparison of a good tcp4_seq_show function on the left side from a memory capture of a pristine system and on the right it shows the same function but as we could see it has been patched to jump jmp to the reptile code another function that is patched by reptile code in order to hide directories is the filleonedir not sure why volatility didn t detected this but the plugin might be easily adjustable to perform further checks and detect it on the image below on the left side i used volshell to check the function prologue on a pristine system on the right side we can see how the patched function looks like that s it for today in this post i shared some notes on how to use different volatility plugins to detect known rootkits that leverage linux kernel modules the memory capture was obtained using lime and and instructions were given on how to acquire the memory capture and create a volatility profile nothing new but practice these kind of skills share your experiences get feedback repeat the practice and improve until you are satisfied with your performance have fun 1 http www dfir org research android memory analysis di pdf 2 https www youtube com watch v owkoyphlmm8 3 https github com 504ensicslabs lime 4 https www blackhat com presentations bh dc 07 walters paper bh dc 07 walters wp pdf 5 http 4tphi net fatkit papers fatkit_journal pdf 6 http volatilesystems blogspot com 2008 08 pyflagvolatility team wins dfrws html 7 http dfir org research omfw pdf 8 https github com halpomeranz lmg 9 https nvlpubs nist gov nistpubs specialpublications nist sp 800 61r2 pdf 10 https github com volatilityfoundation volatility wiki linux command reference 11 https github com m0nad diamorphine 12 https github com f0rb1dd3n reptile 13 https github com h2hconference 2018 references sans for526 advanced memory forensics threat detection the art of memory forensics detecting malware and threats in windows linux and mac memory tagged diaphormine rootkit lime linux rootkit loadable kernel modules memory forensics reptile rootkit volatility nov 05 2018 4 comments anniversary six years ago on 4th of november 2012 count upon security was born this weekend was it s 6th anniversary i started this project has hobby in my spare time i wanted to share with the it security community material and illustrations which i thought could be useful till now i ve written 112 posts on a variety of security topics many with the help of good old friends some were short others took weeks to write also 3 articles were written by ricardo dias and 1 by angel alonso for what is worth akismet statistics reported that the site had 208k views and 135k visitors in 2017 in the last 5 months due to good reasons i didn t have the chance to write new posts articles however i really appreciate all the people who have read one or more articles or use it as reference or in some training material because it gives me incentive to continue hopefully in 6 years from now in 2024 i hope to still be here contributing to this small alley of the internet with new content on this always evolving and fascinating industry stay tuned and have fun jun 20 2018 leave a comment digital forensics and incident response intrusion analysis digital forensics plugx and artifacts left behind when an attacker conducts an intrusion using a b or c technique some of his actions leave artifact x y or z behind so based on the scenario from the last article about plugx i collected a disk image and memory image from the domain controller over the past years i wrote several articles on how to perform acquisition mounting and processing of such images and analyze them by creating super timelines look at different artifacts like event logs prefetch shimcache amcache etc or analyze ntfs metadata or look for artifacts related to interactive sessions today i m not going to perform analysis but i m going to list a quick overview about some of the windows endpoint artifacts that might give us evidence about the actions that were executed in the previous scenario and help us produce a meaningful timeline in addition i list some tools that could be used to analyze those artifacts scenario 1 the attacker placed the filename kas exe on the folder c perflogs admin which artifacts could record evidence about this action ntfs mft description the master file table mft is a special system file that resides on the root of every ntfs partition the file is named mft and is not accessible via user mode api s but can been seen when you have raw access to the disk e g forensic image this special file is a hierarchical database and inside you have records that contains a series of attributes about a file directory and indicates where it resides on the physical disk and if is active or inactive the size of each mft record is usually 1024 bytes each record contains a set of attributes some of the most important attributes in a mft entry are the standart_information filename and data the first two are rather important because among other things they contain the file time stamps each mft entry for a given file or directory will contain 8 timestamps 4 in the standard_information and another 4 in the filename these time stamps are known as mace tools parse and analyze it with sleuthkit originally written by brian carrier mft2csv from joakim schicht or plaso log2timeline originally created by kristinn gudjonsson ntfs indx attribute description the mft records for directories contain a special attribute called i30 this attribute contains information about file names and directories that are stored inside a directory this special attribute is also known as indx and consists of three attributes the index_root index_allocation and bitmap so what well this attribute stores information in a b tree data structure that keeps data sorted so the operating system can perform fast searches in order to determine if a file is present in addition this attribute grows to keep track of file names inside the directory however when you delete a file from a directory the b tree re balances itself but the tree node with metadata about the deleted file remains in a form of slack space until it gets reused this means we can view the i30 attribute contents and we might find evidence of files that once existed in a directory but are no longer there tools o parse it and analyze it with indxparse from william ballenthin or mft2csv from joakim schicht ntfs logfile description ntfs has been developed over years with many features in mind one being data recovery one of the features used by ntfs to perform data recovery is the journaling the ntfs journal is kept inside ntfs metadata in a file called logfile this file is stored in the mft entry number 2 and every time there is a change in the ntfs metadata there is a transaction recorded in the logfile these transactions are recorded to be possible to redo or undo file system operations after the transaction has been logged then the file system can perform the change when the change is done another transaction is logged in the form of a commit the logfile allows the file system to recover from metadata inconsistencies such as transactions that don t have a commit the size of the logfile can be consulted and changed using chkdsk l and per default is 65536 kb why would logfile be important for our investigation because the logfile keeps record of all operations that occurred in the ntfs volume such as file creation deletion renaming copy etc therefore we might find relevant evidence in there tools parse it and analyze it with logfileparser from joakim schicht ntfs usnjrnl description the change journal contains a wealth of information that shouldn t be overlooked another interesting aspect of the change journal is that allocates space and deallocates as it grows and records are not overwritten unlike the logfile this means we can find old journal records in unallocated space on a ntfs volume how to obtain those luckily the tool usn record carver written by poorbillionaire can carve journal records from binary data and thus recover these records tools parse and analyze it with usnjrnl2csv from joakim schicht or from unallocated space with usn record carver from poorbillionaire scenario 2 which account did the attacker used to log into the system when he placed kas exe on the file system windows event logs description the windows event logs record activities about the operating system and its applications what is logged depends on the audit features that are turned thus impacting the information that one can obtain from a forensic perspective the event logs capture a wealth of information the main three windows event logs are application system and security and on windows vista and beyond they are saved on system32 winevt logs in a binary format for example the event id s 4624 4625 might give us answers tools parse it and analyze it with plaso log2timeline libevtx utils from joakim schicht python evtx from william ballenthin or event log explorer you likely get better results if in your environment if you have consistent and enhanced audit policy settings defined that track both success and failures in case the attacker deletes the windows event logs there is the possibility to recover windows event log records from the pagefile sys or from unallocated space from volume shadow copies or even the system memory you could use evtxtract from willi ballenthin to attempt to recover event logs from raw data scenario 3 attacker executed the kas exe binary which artifacts might record this evidence windows prefetch superfetch description to improve customer experience microsoft introduced a memory management technology called prefetch this functionality was introduced into windows xp and win dows 2003 server this mechanism analyses the applications that are most frequently used and preloads them in advance in order speed the operating system booting and application launching on windows vista microsoft enhanced the algorithm and introduced superfetch which is an improved version of prefetch the prefetch files are stored in systemroot prefetch directory and have a pf extension the superfetch files have a db extension prefetch files keep track of programs that have been executed in the system even if the original file is no longer present in addition prefetch files can tell you when the program was executed how many times and from which path tools plaso log2timeline windows prefetch parser from adam witt prefetch parser from eric zimmerman for superfetch you could use superfetch tools shimcache either from registry or from kernel memory description microsoft introduced the shimcache in windows 95 and it remains today a mechanism to ensure backward compatibility of older binaries into new versions of microsoft op erating systems when new microsoft operating systems are released some old and legacy application might break to fix this microsoft has the shimcache which acts as a proxy layer between the old application and the new operating system a good overview about what is the shimcache is available on the microsoft blog on an article written by tim newton demystifying shims or using the app compat toolkit to make your old stuff work with your new stuff the interesting part is that from a forensics perspective the shimcache is valuable because the cache tracks metadata for binary that was executed and stores it in the shimcache tools from kernel memory you can parse it and analyze it with volatility shimcache and shimcachemem plugin from the registry you can use shimcacheparser https github com mandiant shimcacheparser you can also use regripper from harlan carvey or appcompatcacheparser from eric zimmerman in addition to analyze shimcache artifacts at scale you can use appcompatprocessor from mattias bevilacqua amcache description on windows 8 amcache hve replaced the recentfilecache bcf file a registry file used in windows 7 as part of the application experience and compatibility feature to ensure compatibility of existing software between different versions of windows similar to its predecessor amcache hve is a small registry hive that stores a wealth of information about recently run applications and programs including full path file timestamps and file sha1 hash value amcache hve is commonly found at the following location c windows appcompat programs amcache hve the amcache hve file is standard within the windows 8 operating system but has been found to exist on windows 7 systems as well tools to read the amcache hive you could use regripper or willi ballenthin stand alone script or eric zimmerman amcacheparser to analyze amcache artifacts at scale you can use appcompatprocessor from mattias bevilacqua windows event logs the windows event logs for example id 4688 could track binary execution if you have the proper audit settings or you use sysmon scenario 4 the execution of kas exe dropped three files on disk that used dll search order hijacking to achieve persistence and install the malicious payload which artifacts might help identifying this technique identifying evidence of dll search order hijacking is not easy if no other leads are available likely you need a combination of artifacts the following artifacts tools might help ntfs mft indx logfile usnjrnl prefetch superfetch shimcache either from registry or from kernel memory amcache windows event logs could track process execution and give you leads if you have the proper audit settings or you use sysmon volatility to perform memory analysis regripper one thing you could try among many others that this powerful tool allows is to identify different persistence mechanism that could have resulted as part of the dll search order hijacking technique appcompatprocessor to analyze shimcache and a...
|