I am retiring this social media account. Find me as @hal_pomeranz@infosec.exchange

Orlando, FL
Joined November 2008
Filter
Exclude
Time range
-
Near
The problem is that while you control the entire data store, you have to give access to small pieces of info. Those pieces will be aggregated outside of your control, just as they are today.
2
Which means your password was not stored as a hash on at least some systems.
1
Replying to @v3rtig0
istat is just returning inode data, nothing else AFAIK
1
Replying to @v3rtig0
Also not clear on the context for your request. You could track file access in excessive detail using auditd on Linux, but it would have to be configured beforehand. Won’t help if you’re investigating activity that has already happened.
1
2
Replying to @v3rtig0
See extundelete and ext4magic. The source code here is probably the best documentation you are going to find on this. There is no USN equivalent for Linux file systems.
1
For the morning crowd...
Your most indispensable Windows app(s) and why? GO!
Your most indispensable Windows app(s) and why? GO!
30
1
3
15
Replying to @jtsylve
Not that I'm seeing.
Replying to @mykill
Good idea, not the execution mechanism in this case
2
Replying to @jtsylve
Good thought, but I'm not finding any
Replying to @phillmoore
Yeah, that's basically what I'm down to at this point
Replying to @MalwareJake
Sadly, Shell is set to explorer.exe
1
1
Replying to @DFIRSamurai
The file manager
I summon the collective #DFIR wisdom of Twitter. User attempts to launch Windows Explorer and another program starts instead. I'm assuming a registry setting, but which one?
15
6
10
Replying to @craiu @DfirNotes
“I don’t really understand Linux but the developers keep deploying their stuff on it.”
3
This content is evergreen volatility-labs.blogspot.com… -- Thanks again, @attrc!
7
10
Yeah, people are telling me it's loading for them. Guess I'm on the blocked list! :-)
Replying to @Colddemon00
Weird. Thanks.
Anybody know what happened to the FBI/NSA writeup on the the Drovorub Linux rootkit/malware that used to be at media.defense.gov/2020/Aug/1…
1