Category Archives: DFIR

Hunting Pastebin with PasteHunter

      5 Comments on Hunting Pastebin with PasteHunter

From a security analytics and Threat Intelligence perspective Pastebin is a treasure trove of information. All content that is uploaded to pastebin and not explicitly set to private (which requires an account) is listed and can be viewed by anyone. tl;dr Using Yara Rules to find and save interesting data from pastebin https://github.com/kevthehermit/PasteHunter Hackers and script kiddies are quick to… Read more »

VolUtility Release v1.2 – With Authentication Module

VolUtilty 1.2 has now been released. If your not sure what VolUtility is – https://techanarchy.net/tag/volutility/ The main addition here is the new optional Authentication module. It is disabled by default and can be enabled via the config file. Before enabling the Auth module it will need a small amount of setup that is detailed on the wiki, basic steps are: cd… Read more »

VolUtility Version 1.0 Release

      2 Comments on VolUtility Version 1.0 Release

It’s a week late but I finally have enough testing done that I’m happy to call this a 1.0 release. :) If you’re not sure what VolUtility is then read some of the earlier posts: VolUtility a web front end VolUtility release 0.2 Solving GrrCon 2015 Solving GrrCon 2016 tldr; It’s a web front end for the Volatility memory analysis… Read more »

Solving GrrCon 2016 DFIR Challenge

      6 Comments on Solving GrrCon 2016 DFIR Challenge

It’s that time of year again and Wyatt Roersma has released the 2016 GrrCon DFIR Challenge. At the time of writing it’s still available to register and download the images from https://ir.e-corp.biz. Once again as these are memory images I am going to try to solve the challenge solely using VolUtility. Word of warning I reveal all the answers :p For the… Read more »

Extracting LastPass Site Credentials from Memory

      12 Comments on Extracting LastPass Site Credentials from Memory

Let me start by stating this is not an exploit or a vulnerability in LastPass. This is just extracting any data that may remain in memory during a forensics acquisition. At some point the data must be in clear. I was reading the Art Of Memory Forensics, (if you don’t own this i highly recommend it. ) On one of the… Read more »

Solving GrrCon15 Memory Challenge with VolUtility

After seeing that Brian Baskin and Tony Cook had published a writeup solving the GrrCon 2015 Memory challenges I thought this would be an ideal way of testing VolUtility, A way to make sure that i have covered all the features, and if not then how to try and add them so it does. Plus it looked like fun :)… Read more »

VolUtility Release 0.2

      2 Comments on VolUtility Release 0.2

Just a quick update on the new VolUtility release. If you missed the first post telling you what VolUtility is you can read it here. VolUtility a web front end for the volatility framework. Along with several bug fixes and general code tidy the following features have been added or improved. Support Linux and Mac memory images. Adds a config file… Read more »

VolUtility a web front end for the volatility framework.

Several months ago i finally managed to attend the SANS memory forensics course (FOR526) . Taught by the very knowledgeable @sibertor. The course covers memory structures and focuses on the two key frameworks for memory analysis, Volatility and Rekall. Im not going to get in to which is best, each has their uses and most times I will flip between… Read more »

Welcome to 2015

      No Comments on Welcome to 2015

Hello and welcome to 2015. Hope you all had a great Christmas and a Happy New Year. As I said in my last post of 2014 this year I plan to get more content on the blog on a more regular basis. Starting with the Home Lab build. Santa, AKA my wonderful wife, delivered me new hardware and so I am going to rebuild… Read more »

Update to Image Mount Script

      No Comments on Update to Image Mount Script

Several Months ago I wrote a python script that helped me mount Disk and partition images. You can read the original post here. It worked but was lacking in some areas. Mostly in that it didn’t support GPT partition tables. Thanks to @robtlee for poking me and @ChipRAFP for the support I have rewritten the script and added a couple more features. It now… Read more »