Finding File Data in a Disk Image from an XFS Inode
How to decode the extent record in an XFS inode by hand and convert it to the exact byte offset of file data in a disk image, with a script to speed it up.
How to decode the extent record in an XFS inode by hand and convert it to the exact byte offset of file data in a disk image, with a script to speed it up.
Reflective code injection lets attackers execute code directly in process memory, leaving minimal file-system traces. This overview explains the technique on Windows and Linux, then covers detection methods for incident responders: VAD tree inspection, /proc analysis, RWX memory anomalies, suspicious system calls, and tools such as MemProcFS, Volatility and YARA.
EDR and Forensics tools can be very expensive. This post looks at some cheap, or free, DFIR alternatives you absolutely should consider. Even if you have a good budget for high-end professional tools, it's worth building these into a toolbox you can use to solve problems or unexpected situations.
Cybersecurity is big news with governments and businesses suffering at the hands of cyber attacks. As a result of this, the University of Chester (UoC) STEMs society is hosting a Cybersecurity…
The North Wales Cyber Security Cluster is meeting on 21 April at Solvings Ltd, in Mold, Flintshire. Solvings provide a great location and the cluster is a wonderful opportunity to learn…
As the news often shows, Information Security (infosec) is a big part of any organisation. From the small business with just a couple of computers to the global enterprise, infosec…