Meta tags:
Headings (most frequently used words):
and, 2023, july, tuesday, sunday, malware, courses, tools, may, monday, 2022, blog, learning, research, no, pryor, knowledge, november, 26, 2024, 25, saturday, 22, forensic, 21, december, 19, 30, search, this, archive, followers, importing, remnux, sift, ova, into, proxmox, new, way, to, do, it, winfe, course, review, ideas, forensics, jobparer, py, qu1cksc0pe, events, ripper, accomplishments, goals, little, homelab, life, update, setting, up, my, environment, more, training, thinking, about,
Text of the page (most frequently used words):
the (251), and (152), you (67), this (60), for (53), that (44), with (40), was (37), course (37), have (33), but (33), time (31), from (28), ago (24), can (24), winfe (24), about (23), file (21), windows (21), share (21), well (21), more (20), all (19), malware (19), just (19), get (19), ova (18), #forensics (18), now (18), one (18), things (17), also (17), not (17), remnux (16), years (16), learning (16), are (16), use (16), server (16), post (16), new (15), work (15), network (15), then (15), really (15), like (15), out (15), blog (14), other (14), still (14), what (14), little (14), there (14), training (14), files (14), class (14), may (13), into (13), both (13), your (13), started (13), proxmox (12), analysis (12), forensic (12), lot (12), take (12), when (12), had (12), how (12), them (11), home (11), pryor (11), much (11), working (11), set (11), using (11), first (11), some (11), going (11), done (11), july (10), good (10), back (10), very (10), virtual (10), tools (10), got (10), different (10), been (10), events (10), import (10), another (9), brett (9), two (9), decided (9), need (9), environment (9), through (9), great (9), last (9), same (9), test (9), computer (8), digital (8), posted (8), learn (8), domain (8), machine (8), pve (8), linux (8), once (8), while (8), many (8), always (8), which (8), only (8), used (8), sift (7), security (7), pinterest (7), facebook (7), blogthis (7), email (7), comments (7), ken (7), they (7), than (7), available (7), name (7), couple (7), wasn (7), has (7), again (7), run (7), case (7), evtx (7), few (7), adapter (7), december (6), part (6), before (6), here (6), will (6), controller (6), storage (6), running (6), were (6), over (6), related (6), those (6), worked (6), recently (6), thing (6), topics (6), since (6), finally (6), completed (6), next (6), courses (6), might (6), november (5), 2023 (5), importing (5), check (5), knowledge (5), help (5), most (5), posts (5), doing (5), created (5), setup (5), build (5), microsoft (5), because (5), own (5), wanted (5), servers (5), videos (5), interest (5), though (5), everything (5), lab (5), enjoyed (5), start (5), writing (5), right (5), goal (5), python (5), far (5), way (5), made (5), something (5), know (5), tool (5), ripper (5), qu1cksc0pe (5), called (5), author (5), never (5), any (5), instructor (5), ways (5), where (5), various (5), pre (5), actually (5), january (4), march (4), april (4), june (4), investigation (4), year (4), dfir (4), weeks (4), information (4), soon (4), fun (4), stuff (4), networking (4), too (4), instead (4), zentyal (4), disk (4), pretty (4), active (4), directory (4), having (4), thought (4), best (4), could (4), place (4), old (4), full (4), job (4), later (4), sure (4), love (4), think (4), off (4), try (4), after (4), found (4), included (4), quite (4), until (4), long (4), each (4), being (4), txt (4), github (4), see (4), does (4), tried (4), find (4), https (4), script (4), manually (4), such (4), taught (4), covered (4), based (4), final (4), did (4), isn (4), display (4), imported (4), virtualbox (4), feature (4), february (3), 2022 (3), show (3), detail (3), response (3), why (3), virustotal (3), triage (3), group (3), month (3), shavers (3), questions (3), product (3), future (3), hopefully (3), better (3), pfsense (3), second (3), settings (3), blocking (3), would (3), yet (3), downloaded (3), ram (3), hard (3), works (3), allows (3), didn (3), separate (3), making (3), interested (3), online (3), these (3), anything (3), harlan (3), focus (3), looking (3), setting (3), keep (3), trying (3), stored (3), cisco (3), added (3), else (3), goes (3), haven (3), however (3), needed (3), morning (3), say (3), left (3), come (3), update (3), grc (3), halfway (3), ever (3), enjoying (3), tcm (3), academy (3), practical (3), output (3), plugins (3), data (3), plugin (3), cases (3), want (3), value (3), should (3), page (3), pulls (3), analyze (3), point (3), com (3), conversion (3), short (3), jamie (3), laptop (3), mentioned (3), gotten (3), finished (3), pmat (3), encourage (3), past (3), covering (3), versions (3), research (3), mini (3), covers (3), general (3), topic (3), lessons (3), required (3), certificate (3), photo (3), easy (3), steps (3), extra (3), across (3), workstation (3), enable (3), vmdk (3), qcow2 (3), awesome (2), august (2), october (2), september (2), 2024 (2), archive (2), call (2), history (2), thoughts (2), others (2), incident (2), executables (2), video (2), examples (2), journal (2), current (2), our (2), times (2), missed (2), day (2), finding (2), initial (2), access (2), project (2), end (2), ideas (2), policy (2), getting (2), plans (2), include (2), router (2), firewall (2), addition (2), simple (2), dns (2), hole (2), install (2), iso (2), gave (2), gigabyte (2), enough (2), distribution (2), compatible (2), administer (2), option (2), free (2), local (2), nice (2), backup (2), connected (2), device (2), knew (2), machines (2), involved (2), watched (2), reading (2), eventually (2), around (2), builds (2), areas (2), comes (2), computers (2), fortunate (2), opportunity (2), attention (2), enjoy (2), carvey (2), couldn (2), boring (2), main (2), liked (2), said (2), talk (2), monday (2), college (2), break (2), posting (2), make (2), several (2), nextcloud (2), guacamole (2), reach (2), removed (2), power (2), built (2), months (2), interesting (2), initially (2), gone (2), school (2), basis (2), high (2), degree (2), days (2), evening (2), semester (2), technical (2), glad (2), down (2), allow (2), direction (2), life (2), won (2), written (2), nothing (2), above (2), signed (2), auger (2), explains (2), matt (2), kiely (2), taken (2), goals (2), graduated (2), week (2), everyone (2), drive (2), sunday (2), longer (2), tips (2), terminal (2), text (2), erip (2), along (2), requires (2), create (2), batch (2), event (2), 4operational (2), regripper (2), according (2), deal (2), report (2), fixed (2), rest (2), tasks (2), she (2), add (2), put (2), follow (2), pwf (2), known (2), talks (2), flarevm (2), occasionally (2), basics (2), including (2), material (2), activities (2), student (2), version (2), completing (2), anyway (2), reports (2), autopsy (2), yesterday (2), basistech (2), beginning (2), brian (2), even (2), tell (2), his (2), experience (2), followed (2), validation (2), either (2), appreciated (2), lesson (2), testifying (2), court (2), happy (2), testing (2), software (2), changes (2), media (2), methods (2), method (2), ready (2), problems (2), suite (2), section (2), write (2), offered (2), site (2), practitioner (2), anyone (2), support (2), necessary (2), review (2), tuesday (2), mostly (2), generally (2), hardware (2), typed (2), sudo (2), ens18 (2), process (2), default (2), changed (2), vmware (2), shows (2), number (2), problem (2), debian (2), uploaded (2), gzip (2), directly (2), image (2), outdated (2), inc, theme, powered, blogger, followers, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2018, 2020, 2021, cell, phone, tracking, via, records, forensis, deconstructing, catalog, random, blaming, journey, livejournal, geek, raised, wolves, encase, enscript, investigations, sar, uavs, optical, challenges, integriography, broken, locks, ethics, browser, extensions, vivaldi, firefox, chromium, grand, stream, dreams, collection, timeline, generation, kape, settling, relaxation, bean, pivoting, cyber, community, stay, strong, uncertainty, sans, 4cast, inside, look, nsa, equation, ttps, china, lense, inversecos, gotta, captcha, sketchymoose, daily, 815, hacking, exposed, forbidden, freebsd, released, advisories, 2026, taosecurity, overview, content, published, didier, stevens, five, answer, buying, lenny, zeltser, search, subscribe, atom, older, barely, scratched, surface, understanding, admins, adding, vlans, opnsense, ubuntu, raspberry, duplicate, between, forwarders, care, mission, plus, ads, exist, gigabytes, 250, space, production, business, greater, paid, subscription, certainly, restore, anytime, mess, pbs, maintaining, backups, frequently, watching, books, hands, led, circle, enjoyment, repairs, every, loving, blue, team, ops, countless, environments, rangeforce, tryhackme, bad, interests, tech, repairing, deeply, fell, people, luby, novitovic, jimmie, weg, held, ctf, ali, hadi, rob, lee, mark, mckinnon, welcome, renamed, settled, granted, tweeted, suggested, change, wider, sometimes, featured, phill, moore, closed, timely, promises, cloudflare, argo, tunnel, anywhere, unstable, reason, replace, migrating, switches, friend, hook, noisy, hungry, fans, plan, spend, gateway, isp, fiber, modem, vlan, mikrotik, rb260gs, switch, completely, ignored, efforts, during, talked, return, someday, exercise, continuing, associate, decades, consisted, homework, fall, mathematics, speech, classes, bit, must, winter, spring, graduate, believe, blame, don, dive, sidetracked, promise, excuse, homelab, moment, spending, preparing, granddaughter, wedding, front, yard, weekend, hope, living, seems, precedence, maybe, regular, who, knows, continue, dabble, scripts, groundbreaking, easily, picked, feel, energy, exposure, governance, risk, compliance, gerald, definitive, analyst, master, nearly, authored, despite, giving, education, already, foremost, happened, originally, intended, honors, employer, regretted, accomplishing, lincoln, trail, hello, catch, accomplishments, expected, investigative, hints, helps, useful, indicative, certain, profile, single, quickly, printing, redirect, whatever, program, appropriate, syntax, wevtx, bat, relies, logparser, evtxparse, extract, following, logs, system, application, defender, terminalservices, localsessionmanager, sound, familiar, guess, creations, operated, except, parse, specifically, excellent, myself, iterates, examined, strings, yara, rule, matching, highlights, imports, patterns, date, stamp, hashes, provide, api, key, detections, osx, binaries, document, apk, capable, learned, edited, clarify, python2to3, convert, chatgpt, wrote, jobparser, parsing, cyber5w, investigating, scheduled, installed, converted, partially, able, sent, levy, jobparer, kind, hold, excited, aside, grabbing, bought, linkedin, contacts, recommendation, purchased, reverse, engineering, fundamentals, udemy, paul, chin, taking, intend, truly, ntfs, artifacts, usn, eric, zimmerman, markus, schober, serving, refresher, teaching, strongly, ran, inetsim, sample, connect, specs, absolute, designed, introduction, important, safely, multiple, samples, wannacry, ransomware, basic, dynamic, static, moved, advanced, binary, patching, maldocs, shell, code, mobile, worthwhile, lately, almost, forgotten, cool, give, doz, longest, idea, thinking, shown, ingest, modules, views, producing, hour, often, happens, distracted, went, squirrel, less, carrier, himself, psst, hey, extremely, unlikely, yes, saturday, pleased, instruction, top, notch, provided, developing, usage, outstanding, away, feeling, highly, requirements, eligible, question, aspects, score, pass, passed, received, consists, answering, providing, photographic, evidence, screen, booted, submit, pdf, documentation, allowed, lends, credibility, earn, watch, kudos, possibly, blow, weird, present, story, testified, hear, position, likely, dealing, bitlocker, troubleshooting, hashing, provides, casework, favorite, parts, validate, explained, boot, acquire, accidentally, introduced, subject, skip, assume, building, obtain, mistyfromreboot, terribly, difficult, fact, choice, sell, solution, discusses, keeping, words, meant, indeed, ftk, imager, etc, decide, doesn, office, zip, extractor, divided, resources, instrumental, continued, development, book, field, publications, guide, installation, troy, larson, charge, personal, commercial, absolutely, understand, slightly, modified, portable, capability, acquisition, please, leave, comment, wonder, house, scp, disable, helpful, increase, amount, memory, world, resource, naming, procedure, described, took, larger, updates, dhclient, dhcp, assigned, address, ifconfig, command, prompt, type, networkctl, named, desktop, enabled, upgrade, aware, showing, viewed, window, experiment, graphics, shut, minutes, fully, parameters, assign, numbers, turned, 212, signifies, assigning, defaults, selected, remote, sorted, exported, opened, discovered, further, compressed, removing, placing, uncompressed, pointed, error, container, templates, smb, shared, accessed, individually, seemed, upon, message, extemely, wished, ability, ovf, release, needs, folks, easier, download, without, detailed, options, previously, docs, org, distro, appliance, self, hosted, hyperv, edit, wouldn, rely, dead, read, adventures, cost, stupid, uninformed, occurred,
Text of the page (random words):
your forensic problems he discusses keeping it simple my words not his as far as what you include in a winfe build winfe is not meant to be a full forensic suite and indeed it is not while you can add various tools x ways forensics ftk imager etc to your build you need to decide what you really need and what is just extra stuff that doesn t need to be there such as an office suite zip file extractor and so on once you get to the point of actually building your own winfe two different methods are taught for doing so one is the mini winfe built with tools you can obtain from https github com mistyfromreboot mini winfe the second method requires a few more steps to get started but it isn t terribly difficult to get ready in fact both methods are pretty easy to do once you have the initial steps done you can build your own winfe from either method in just a short time brett also covers topics like dealing with bitlocker troubleshooting and hashing he provides casework examples as well one of my favorite parts of the class however is the lesson on testing and validation the need to test and validate winfe and all your software tools is explained and i was very happy about that it s easy to make a winfe boot disk and use it to acquire a drive but do you know that everything worked right do you know if any changes were accidentally introduced to the subject media i m so glad this topic was covered because it s just so easy to skip testing and assume all is well something else i really appreciated was the lesson on report writing and testifying i enjoy writing reports i m weird like that because it present the opportunity to tell a story i ve testified in court related to forensic cases i ve worked as well with both of those things i m always happy to hear tips on doing them better even though i m not in a position where i m likely to be testifying in court these days possibly the best part of the course is that you actually have to show your work you can t just blow through the videos take a little test and get a certificate you actually have to build both versions of winfe to get past the pre test before you can take the final the pre test consists of answering a few questions followed by providing photographic evidence that you did the winfe builds photo of screen booted to each version you also have to submit a pdf of your validation documentation for either one of the two versions you made i love that these things were required before the student is allowed to take the final test i think it lends a lot of credibility to the course certificate you earn when you can say that you actually did something other than watch a few videos to get it kudos to brett for making this part of the course after completing the pre test requirements you are eligible to take the final test the 17 question final covered various aspects of the training material a score of 90 is required to pass i passed and received my certificate my next goal is to take the winfe instructor training course as you can tell i was very pleased with this class the instruction from brett was top notch he provided the information based on his own developing and usage experience he does an outstanding job covering each topic i didn t come away from any of the lessons feeling like he left anything out if you have the interest i highly encourage you to take this course posted by ken pryor at 11 58 am 3 comments email this blogthis share to x share to facebook share to pinterest saturday july 22 2023 learning and research ideas what s this two yes two posts not just in the same year but even in the same month what has gotten into me more training yesterday i completed a course i started a long while back but never finished i signed up for the autopsy 8 hour course from basistech https dfir training basistech com and got around halfway through it but as often happens with me i got distracted and went off in another direction squirrel since it had been a long time since i started it i decided to start over from the beginning i enjoyed the course which was taught by no less than brian carrier himself psst hey brian in the extremely unlikely event you re reading this i d love to see some more online training from you anyway the course covers general setup and then goes through the various included ingest modules and views you can use to analyze the data it also covers the various ways of producing reports if you re interested in autopsy but haven t used it i encourage you to check out this course also this week i started the windows forensic environment winfe training taught by brett shavers at dfir training i m only a little ways into this course but i m enjoying it so far one thing that i really like is how much brett goes into great detail on each thing he explains very well why and when to use winfe as well as when you should not use it i ve just gotten to the part of the course where the student is shown how to create a version of winfe called mini winfe it s my goal after completing this training to then go through the winfe instructor training as well thinking about research something i ve wanted to do for a long time is find a good research project to work on there are so many fun things to learn and do in digital forensics and i know there is much still to learn i ve been trying to come up with an idea but i m still not sure what i want to work on that s all i ve got for now be well and i ll hopefully be back soon with a new post posted by ken pryor at 6 24 pm no comments email this blogthis share to x share to facebook share to pinterest sunday july 2 2023 forensics malware courses and tools i ve been working hard on forensic and malware related courses lately and having a lot of fun with it i had almost forgotten how cool it was working on and learning this material i thought i d give a little update on my activities so here it is take your no doz this may be the longest post i ve ever done forensic and malware courses in my last post i mentioned that i was working on the practical malware analysis and triage pmat class over at the tcm academy i finished the course recently and found it was a very worthwhile course to take pmat was a lot of fun for me i ve always enjoyed looking at malware but i had never taken a course or really tried to get past the absolute basics this course was a well designed and taught introduction to malware analysis the course author instructor is matt kiely the course covered the important topics of setting up your lab and covering how to use it safely multiple malware samples were made available for analysis including wannacry ransomware the course started off with basic dynamic and static analysis and then moved into advanced versions also covered were binary patching maldocs shell code mobile device malware the course involved the use of both windows and linux investigation tools the lab was setup so that you ran both the windows flarevm and the remnux linux vm for different tasks occasionally you needed to run both at the same time such as using inetsim on remnux for the malware sample running on flarevm to connect to so you need a computer with high enough specs to run both at the same time if you re interested in learning more about malware analysis i strongly encourage you to check out this course now that i m done with pmat i m working on another course also at tcm this class is called practical windows forensics pwf the course author instructor is markus schober i m over halfway through it and enjoying it very much in my case it s serving as both a refresher on things i used to know and teaching me things i never knew as well one of the things i ve really enjoyed working with in the class is using the eric zimmerman tools i had never used any of them before and i see now why everyone talks about them so much in pwf to this point i ve really liked learning again about ntfs artifacts i had never really known much about the usn journal and it s forensic value so finding out how to access this information has been great i ll follow up when i ve completed the class i intend to go back over some topics again before truly being done with it i bought another malware related course this morning on a linkedin contacts recommendation i purchased reverse engineering and malware analysis fundamentals on udemy the course author is paul chin i m not going to start it until i ve finished the other courses i m taking i m kind of on hold with the grc class i mentioned last time i ve gotten so excited about forensic and malware training that i just put that one aside for the time being it s a great class and i ll get back to it but i ve just got too many other things grabbing my attention right now tools jobparer py some years ago jamie levy wrote jobparser py for parsing windows job files the script was written for python 2 x recently i have been working on a short course on cyber5w academy called investigating windows scheduled tasks and it called for the use of jamie s script in one part i like many only have python 3 installed on my linux laptop so this morning i converted the script to work in python 3 the conversion was partially done with a conversion tool and i manually fixed what it wasn t able to i sent it to jamie and she said she would add it to the github page edited to clarify that i used an online python at https python2to3 com conversion tool to help me convert the script it missed quite a few things so i manually fixed the rest no it wasn t chatgpt or anything like that qu1cksc0pe i wanted to talk about a couple investigation tools i only recently learned about the first one is called qu1cksc0pe and you can find it here according to the github page qu1cksc0pe is and all in one malware analysis tool for analyze windows linux osx binaries document files apk files and archive files to this point i ve only tried qu1cksc0pe with windows executables but as you can see it s capable of far more qu1cksc0pe iterates through the file being examined and pulls out a great deal of information it pulls strings and does yara rule matching highlights interesting imports and other patterns pulls out the time date stamp and file hashes and much more if you provide your virustotal api key it can also check for virustotal detections and report on those this is an excellent tool i can see myself using a lot go check it out events ripper events ripper sound at all familiar it should if you ve ever used the great regripper then you might guess events ripper comes from the same place and you d be right both are the creations of harlan carvey and events ripper is operated in much the same way as regripper except it s goal is to parse evtx files for you specifically according to the github page the current plugins extract value from the following windows event logs security evtx system evtx application evtx microsoft windows windows defender 4operational evtx microsoft windows terminalservices localsessionmanager 4operational evtx using events ripper for the first time on an investigation requires you to create an events text file by running a batch file the batch file relies on logparser and evtxparse this might be done like this wevtx bat c case evtx c case events txt once the events txt file or whatever you want to call it is done you run the main program along with the appropriate plugin to get the data you re looking for the syntax is like this erip f c cases events txt p plugin name or erip f c cases events txt a to run all the plugins once also using r will allow you to run a profile instead of just a single plugin the tool works quickly printing the output to the terminal you re working in or you can redirect the output to a text file one thing that i love about this is how harlan included investigative tips or hints in the output of many plugins this helps you know how the data might be useful to you or indicative of certain things so this post has gone on far longer than i expected so i ll end it here i ll be posting again soon posted by ken pryor at 11 53 am 2 comments email this blogthis share to x share to facebook share to pinterest sunday may 21 2023 accomplishments and goals hello everyone i m back for yet another drive by blog post i ve had a lot going on since my last post in december and i thought i d catch you up a little first and foremost i graduated it happened 35 years later than i d originally intended to but i finally made it i graduated with honors from lincoln trail college also my awesome employer last week it wasn t something i needed to do but it s a goal i always regretted not accomplishing until now so now what despite being done with school i m not giving up education i ve already set some new learning goals and i m working on them as i have time i recently started a malware analysis course i m nearly halfway through the practical malware analysis triage course at the tcm security academy the course is authored by matt kiely i ve always had an interest in malware analysis but this is the first course i ve ever taken on it i m really enjoying it and learning a lot i also signed up for the definitive grc analyst master class by dr gerald auger the class is very good so far i ve had very little exposure to grc governance risk and compliance topics before and dr auger explains each of the topics very well i m still working my way through this class there are a couple other courses i picked up but i haven t decided yet which i m going to start once i m done with the two above i feel like it s good to always keep learning so i m sure i ll keep on with courses that interest me as long as i have the time and energy to do them i continue to dabble in python from time to time i ve written a couple little scripts to help with things i do at work but they re nothing groundbreaking just little things to help me get my work done more easily i still have the goal of writing on this blog more but it seems like so many other things take precedence i ve always enjoyed writing so maybe i ll eventually get back to it on a more regular basis hopefully it won t be another 5 months until my next post but who knows that s pretty much it for now at the moment i m spending most of my time preparing for my granddaughter s wedding which will take place in my front yard next weekend until next time i hope you all are well and living your best life posted by ken pryor at 10 09 am no comments email this blogthis share to x share to facebook share to pinterest monday december 19 2022 a little homelab and life update i m going to start writing more on my blog no really you do believe me right ok can t blame you if you don t i come back to this from time to time and think this time i m really going to dive into it only to get sidetracked in some other direction i promise i have a good excuse this time since i last posted i have gone back to school on a part time basis while continuing to work full time i decided it was high time to finally get tha...
|