mirror of
https://github.com/autistic-symposium/sec-pentesting-toolkit.git
synced 2025-04-26 18:49:08 -04:00
Starting organizing my forensics material
This commit is contained in:
parent
c50d88d102
commit
0077bcf0bf
@ -1,22 +1,60 @@
|
||||
# Forensics
|
||||
|
||||
## Disk Forensics
|
||||
|
||||
## Tools
|
||||
### dd
|
||||
|
||||
### Scripts:
|
||||
### strings
|
||||
|
||||
```shell
|
||||
$ strings /tmp/mem.dump | grep BOOT_
|
||||
$ BOOT_IMAGE=/vmlinuz-3.5.0-23-generic
|
||||
```
|
||||
|
||||
### scalpel
|
||||
|
||||
### TrID
|
||||
|
||||
### binwalk
|
||||
|
||||
### foremost
|
||||
|
||||
### ExifTool
|
||||
|
||||
### Hex editors
|
||||
|
||||
### dff
|
||||
|
||||
### CAINE
|
||||
|
||||
### The Sleuth Kit
|
||||
|
||||
|
||||
----------
|
||||
|
||||
## Memory Forensics
|
||||
|
||||
### memdump
|
||||
|
||||
|
||||
|
||||
### Volatility: Analysing Dumps
|
||||
|
||||
* [I have a lot of material on Volatility and Memory Forensics here](volatility.md)
|
||||
* I highly reccomend their training.
|
||||
|
||||
---------------
|
||||
### Scripts
|
||||
|
||||
#### PDFs
|
||||
Tools to test a PDF file:
|
||||
|
||||
- memdump
|
||||
- pdfid
|
||||
- pdf-parser
|
||||
- dd
|
||||
- strings
|
||||
- scalpel
|
||||
- TrID
|
||||
- binwalk
|
||||
- foremost
|
||||
- ExifTool
|
||||
- Hex editors
|
||||
- DFF
|
||||
- CAINE
|
||||
- The Sleuth Kit
|
||||
- Volability
|
||||
|
||||
|
||||
-----------
|
||||
## References
|
||||
|
||||
* [File system analysis](http://wiki.sleuthkit.org/index.php?title=FS_Analysis)
|
||||
* [TSK Tool Overview](http://wiki.sleuthkit.org/index.php?title=Mactime)
|
||||
|
@ -1,6 +0,0 @@
|
||||
## memory dump
|
||||
|
||||
```
|
||||
strings /tmp/mem.dump | grep BOOT_
|
||||
BOOT_IMAGE=/vmlinuz-3.5.0-23-generic
|
||||
```
|
BIN
Forensics/readings/DFRWS-EU-2015-short-presentation-1.pdf
Normal file
BIN
Forensics/readings/DFRWS-EU-2015-short-presentation-1.pdf
Normal file
Binary file not shown.
BIN
Forensics/readings/DFRWS-EU-2015-short-presentation-2.pdf
Normal file
BIN
Forensics/readings/DFRWS-EU-2015-short-presentation-2.pdf
Normal file
Binary file not shown.
BIN
Forensics/readings/DFRWS2014-p1.pdf
Normal file
BIN
Forensics/readings/DFRWS2014-p1.pdf
Normal file
Binary file not shown.
9140
Forensics/readings/DFRWS2015-5.pdf
Normal file
9140
Forensics/readings/DFRWS2015-5.pdf
Normal file
File diff suppressed because one or more lines are too long
BIN
Forensics/readings/Detect_Malware_w_Memory_Forensics.pdf
Normal file
BIN
Forensics/readings/Detect_Malware_w_Memory_Forensics.pdf
Normal file
Binary file not shown.
BIN
Forensics/readings/ELF_Format.pdf
Normal file
BIN
Forensics/readings/ELF_Format.pdf
Normal file
Binary file not shown.
BIN
Forensics/readings/Facilitating-Fluffy-Forensics-Andrew-Hay.pdf
Normal file
BIN
Forensics/readings/Facilitating-Fluffy-Forensics-Andrew-Hay.pdf
Normal file
Binary file not shown.
BIN
Forensics/readings/THA-Deep-Dive-Analyzing-Malware-in-Memory.pdf
Normal file
BIN
Forensics/readings/THA-Deep-Dive-Analyzing-Malware-in-Memory.pdf
Normal file
Binary file not shown.
Binary file not shown.
BIN
Forensics/readings/sift_cheat_sheet.pdf
Normal file
BIN
Forensics/readings/sift_cheat_sheet.pdf
Normal file
Binary file not shown.
BIN
Forensics/readings/tmc_sjennings_linuxcon2013.pdf
Normal file
BIN
Forensics/readings/tmc_sjennings_linuxcon2013.pdf
Normal file
Binary file not shown.
0
Forensics/volatility.md
Normal file
0
Forensics/volatility.md
Normal file
Loading…
x
Reference in New Issue
Block a user