Posts

Showing posts with the label SANS Digital Forensics and Incident Response Blog

SANS - "A few Ghidra tips for IDA users, part 4 - function call graphs"

One of the features of IDA that we use in FOR610 that can be helpful for detecting malicious patterns of API calls is the feature for creating a graph of all function calls called from the current function and any functions that it calls. The graph itself isn't all that pretty to look at, but … Continue reading A few Ghidra tips for IDA users, part 4 - function call graphs from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2019/06/14/a-few-ghidra-tips-for-ida-users-part-4-function-call-graphs

SANS - "Six Reasons You Don't Want to Miss SANS DFIR Summit & Training 2019"

The annualSANS DFIR Summit & Trainingis just around the corner! If you have attended in the past, you already know that we throw everything we have into making this the most action-packed Digital Forensics and Incident Response (DFIR) event of the year. If you have not yet attended, this is the year to change that. Here are six reasons (plus a bonus) to attend. from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2019/06/07/six-reasons-you-dont-want-to-miss-sans-dfir-summit-training-2019

SANS - "Design it. DFIR it. Win it. Wear it!"

Design it. DFIR it. Win it. Wear it! Are you excited about going to the DFIR Summit this July? Of course you are! We have worked hard to bring you an amazing Agenda, Networking opportunities and a bunch of other fun activities at the event. If you have attended before, you know how much fun … Continue reading Design it. DFIR it. Win it. Wear it! from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2019/05/22/dfir-summit-vans-contest-rules

SANS - "Finding Registry Malware Persistence with RECmd"

  If you have been keeping your forensic toolkit up to date, you have undoubtedly used Registry Explorer, a game-changing tool for performing Windows registry analysis. RECmd is the command line component of Registry Explorer and opens up a remarkable capability to script and automate registry data collection. My interest in this tool was recently … Continue reading Finding Registry Malware Persistence with RECmd from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2019/05/07/malware-persistence-recmd

SANS - "A few Ghidra tips for IDA users, part 3 - conversion, labels, and comments"

In this entry in my series, I'll look at a few more of the features I regularly use in IDA and how to accomplish the same in Ghidra. The first one is simple conversion. In this case, hex to ASCII characters (classic stack strings stuff that we cover in Day 5 of FOR610). I miss … Continue reading A few Ghidra tips for IDA users, part 3 - conversion, labels, and comments from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2019/05/06/a-few-ghidra-tips-for-ida-users-part-3-conversion-labels-and-comments

SANS - "Offline Autoruns Revisited - Auditing Malware Persistence"

I was digging through the archives recently and stumbled upon my old post, Autoruns and Dead Computer Forensics. Autoruns is an indispensable tool from Sysinternals that extracts data from hundreds of potential auto-start extensibility points (ASEPs), a fancy Microsoft term for locations that can grant persistence to malicious code. We leverage live Autoruns collection in … Continue reading Offline Autoruns Revisited - Auditing Malware Persistence from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2019/04/29/offline-autoruns-revisited

SANS - "A few Ghidra tips for IDA users, part 2 - strings and parameters"

Continuing with my preliminary exploration of Ghidra. If we continue with the call to RegOpenKeyExA from last time (yes, I know this code is unreachable as we discussed last time, but let's keep going anyway). Continue reading A few Ghidra tips for IDA users, part 2 - strings and parameters from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2019/04/22/a-few-ghidra-tips-for-ida-users-part-2-strings-and-parameters

SANS - "A few Ghidra tips for IDA users, part 1 - the decompiler\/unreachable code"

As I continue to explore NSA's new reversing tool, Ghidra, one of the features that I heard about and was excited to see in action was the decompiler. So, in this entry in the series, I'll start to delve into that some. In particular, I'll look at one particular option that turned out to be more useful than I originally thought, though I'm still not entirely certain how I'll use it going forward. I've long been a user of the Hex-Rays decompiler at $dayjob and I really like it, but I can't afford it for use in my personal/Storm Center research and we don't use it in FOR610, so I was really looking forward to giving the Ghidra one a try. I have to say, so far, I'm pretty impressed. As I explain to my FOR610 students, decompiling is a hard problem. A lot of context is lost during optimization, so except for very simple programs you shouldn't expect the decompiler to give you C code that looks like the original source. Having said that, for someone l...

SANS - "A few Ghidra tips for IDA users, part 0 - automatic comments for API call parameters"

If you haven't been living under a rock, you probably heard that the NSA released its reverse-engineering tool, Ghidra, at RSA last month. I've been an IDA user for years (it's the primary disassembler we use when I teach FOR610), but I've been trying out Ghidra over the last few days since it is free and other malware analysts have been talking about it. This is the first of several diaries I plan to write with suggestions on how to get Ghidra to do things I've come to rely on in IDA. And, being a good computer scientist, I start counting a 0, hence part 0.Let me state, right up front, I have only spent a couple of hours using Ghidra, so this is very preliminary. On first glance, one feature I missed from IDA was the comments where IDA gave me the names of parameters for Windows API calls (e.g., the first parameter to RegOpenKeyExA in MSDN is listed as hKey with a type HKEY). It turns out Ghidra can do this to. It requires changing one of the defaults in the AutoAn...

SANS - "SANS Threat Hunting and Incident Response Summit 2019 Call for Speakers - Deadline 5\/6"

Summit Dates: September 30 & October 1, 2019 Call for Presentations Closes on Monday, May 6, 2019 at 5 p.m. CST Submit your presentation here The Threat Hunting & Incident Response Summit will focus on specific hunting and incident response technique and capabilities that can be used to identify, contain, and eliminate adversaries targeting your … Continue reading SANS Threat Hunting and Incident Response Summit 2019 Call for Speakers - Deadline 5/6 from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2019/04/08/sans-threat-hunting-and-incident-response-summit-2019-call-for-speakers-deadline-56

SANS - "Investigating WMI Attacks"

  WMI as an attack vector is not new. It has been used to aid attacks within Microsoft networks since its invention. However, it has been increasingly weaponized in recent years, largely due to its small forensic footprint. In a world of greater enterprise visibility and advanced endpoint protection, blending in using native tools is … Continue reading Investigating WMI Attacks from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2019/02/09/investigating-wmi-attacks

SANS - "Shortcuts for Understanding Malicious Scripts"

You are being exposed to malicious scripts in one form or another every day, whether it be in email, malicious documents, or malicious websites. Many malicious scripts at first glance appear to be impossible to understand. However, with a few tips and some simple utility scripts, you can deobfuscate them in just a few minutes. … Continue reading Shortcuts for Understanding Malicious Scripts from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2018/11/14/shortcuts-for-understanding-malicious-scripts

SANS - "Tune in: How to build an Android application testing toolbox"

Mobile devices hold a trove a data that could be crucial to criminal cases, and they also can play a key role in accident reconstructions, IP theft investigations and more. It's not just investigators who care about examining a mobile device - so do those interested in application research and data, and enterprises who … Continue reading Tune in: How to build an Android application testing toolbox from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2018/11/13/tune-in-how-to-build-an-android-application-testing-toolbox

SANS - "Inhibiting Malicious Macros by Blocking Risky API Calls"

  Microsoft Office Macros have been the bane of security analysts' lives since the late 1990s. Their flexibility and functionality make them ideal for malware authors to use as a primary stage payload delivery mechanism, and to datethe challenge they pose remains unsolved. Many organisations refrain from blocking them completely due to the impact it … Continue reading Inhibiting Malicious Macros by Blocking Risky API Calls from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2018/04/15/inhibiting-malicious-macros-by-blocking-risky-api-calls

SANS - "Top 11 Reasons Why You Should NOT Miss the SANS DFIR Summit and Training this Year"

The SANSDFIR Summit and Training 2018is turning 11!The 2018 event marks 11 years since SANS started what is todaythedigital forensics and incident response event of the year, attended by forensicators time after time. Join us and enjoy the latest in-depth presentations from influential DFIR experts and the opportunity to take an array of hands-on SANS … Continue reading Top 11 Reasons Why You Should NOT Miss the SANS DFIR Summit and Training this Year from SANS Digital Forensics and Incident Response Blog http://digital-forensics.sans.org/blog/2018/04/13/top-11-reasons-why-you-should-not-miss-the-sans-dfir-summit-and-training-this-year