Nation State Quality OSINT on a Taco Bell Budget – Part 2
Welcome to the second post in our series on getting started using AWS services for OSINT. Last post we covered setting up an AWS account, getting the command line interface installed and configured...
View ArticleNation State Quality OSINT on a Taco Bell Budget – Part 1
I remember taking digital forensics classes years ago and at the very end of the class feeling like I had learned a ton, had a great time, but was also wondering “Ok, what’s next?” When I’m teaching...
View ArticleFilelocator Pro Tips and Tricks for Indexing Large Breach Data Sets
Tomorrow I’ll be giving a talk on breach data including: Places where it’s locatedHow to make large data sets searchable in a reasonable amount of timeHow some organizations are using breach data to...
View ArticleUsing Bulk Extractor for Quick OSINT Wins
Early this week, Archive.org hosted a dump of a SQL database hacked from a neo nazi forum online known as Iron March at https://archive.org/details/iron_march_201911. While there were some .CSV files,...
View ArticleA Quick Look at MDXFIND
Recently one of the SANS SEC504 labs updated and with the changes came a new set of hashes from the exercises. These hashes are a perfect opportunity to dive a bit deeper and try to determine what...
View ArticleA Quick Look at Seatbelt for System Enumeration
I’ve decided to write a few blog posts about tools that I think are really cool that not everyone knows about. First up on my list is Seatbelt which is part of the GhostPac suite recently released by...
View ArticleGhostwriting for Antivirus Evasion in 2018
One of the techniques we cover in the antivirus evasion section of the SANS SEC 504 course is ghost writing. The topic was covered brilliantly by Royce Davis on his blog back in 2012...
View ArticleIncorporating Facial Recognition into Your OSINT
Between multiple accounts, nicknames and fake names, an individual performing OSINT will often find themselves looking at two pictures and wondering, “Is this the same person?” Sometimes it’s obvious...
View ArticleUsing Burp Suite’s Collaborator to Find the True IP Address for a .Onion...
On this Thanksgiving day I’m going to write about something near and dear to all our hearts: stuffing. I’m not talking about the delicious pile of bread you’ll have on your plate this afternoon, I’m...
View ArticleResources to Help Identify Password Hash Formats
One question that I get asked a lot when I’m teaching the password cracking section in the SANS SEC504 class is “Once I get a password hash, how do I figure out what type of hash it is?” I mention a...
View ArticlePersistent Monitoring on a Budget
I am a huge fan of Justin Seitz and his blog. Last holiday season he let me know that pastebin was having a sale on it’s API access, and that he was planning on using it in a future project. He came...
View ArticleA Script to Help Automate Windows Enumeration for Privilege Escalation
Often when I want to learn a skill, I’ll think up a project for myself that forces me to improve that skill. Recently I wanted to improve my Windows post exploitation and privilege escalation so I...
View ArticlePython Script to Map Cell Tower Locations from an Android Device Report in...
Recently Ed Michael showed me that Cellebrite now parses cell tower locations from several models of Android phones. He said that this information has been useful a few times but manually finding and...
View ArticleHow to Guide for Getting Kali Linux Set Up on an AWS Instance
I’ve been using a “jump box” on Digital Ocean for a few years now and recently decided that I wanted to set up a Kali Linux instance on AWS. I ran into a few hiccups getting it up and running, so I...
View ArticleGREM Achievement Unlocked
I had been going through the SANS FOR610 Reverse Engineering Malware content OnDemand recently and last week I knocked out the GREM. I figured it would be a good time to post a few thoughts on it and...
View ArticleHow Long Do Truecrypt AES Keys Remain In Memory?
It’s been a bit since my last post and in that time I’ve been to two SANS conferences, Blackhat and Defcon. It’s been a great but busy few months. A few weeks ago I was presenting at a local forensics...
View ArticleA Quick Guide to Using Clutch 2.0 to Decrypt iOS Apps
A few days ago someone told me that they weren’t able to install Crackulous on their jailbroken iOS device and asked if I could recommend an alternative they could use to decrypt iOS apps. Since...
View ArticleNew Video Preview Utility to Help With Forensics Analysis
Earlier this week I walked into a friend’s office and he had just finished examining an iPhone using Cellebrite. The good news is that the acquisition went flawlessly. The bad news was that the device...
View ArticleLong Overdue 2015 Update
It’s been an extremely busy start to the year but I wanted to make a quick post to talk about what I’ve been up to so far. Last month I got to attend my first SANS DFIR specific event when I took the...
View Article2015 is Upon Us
I planned on doing a few blog posts in December but due to a few great December surprises I wasn’t online much. My month started off by taking a much needed relaxing week of vacation in San Diego with...
View Article