Tuesday, July 16, 2013
Results of the 4cast Awards Nominations
As previously announced, I was nominated for 'Digital Forensics Examiner of the Year' at the Forensics 4cast Awards. The awards ceremony was held last week during the DFIR summit, and I voted the winner in the category. I am very grateful for this award and recognition and hope to have another strong showing next year!
Monday, July 8, 2013
Interview on the Healthy Paranoia podcast
I was recently interviewed on the Healthy Paranoia podcast about memory forensics during DFIR as well as other related topics. It was a really fun time, and I hope to be on the show again in the future. Read about the interview and listen to the MP3 here:
http://packetpushers.net/healthy-paranoia-show-14-digital-forensics-and-incident-response-with-andrew-case/
Please contact me if you any feedback or comments about the show.
Thanks,
Andrew (@attrc)
http://packetpushers.net/healthy-paranoia-show-14-digital-forensics-and-incident-response-with-andrew-case/
Please contact me if you any feedback or comments about the show.
Thanks,
Andrew (@attrc)
Thursday, June 13, 2013
Final Week of Month of Volatility Plugins II is posted
We are writing as the final week of the second installment of the Month of Volatility Plugins is now posted. Volatility 2.3 is currently
in beta, and the blog posts are focusing on new features in this version.
This week's posts discussed a number of new and updated plugins used to analyze Mac systems.
The first post demonstrated leveraging process cross-view analysis for Mac rootkit detection:
http://volatility-labs.blogspot.com/2013/06/movp-ii-41-leveraging-process-cross.html
The second post covered dumping, scanning, and searching process memory:
http://volatility-labs.blogspot.com/2013/06/movp-ii-42-dumping-scanning-and.html
The third post discussed how to recover networking information:
http://volatility-labs.blogspot.com/2013/06/movp-ii-43-recovering-mac-os-x-network.html
The fourth post showed a number of artifacts in Mac kernel memory:
http://volatility-labs.blogspot.com/2013/06/movp-ii-44-whats-in-your-mac-osx-kernel.html
The fifth post analyzed the Rubilyn kernel rootkit and detected it in a number of ways:
http://volatility-labs.blogspot.com/2013/06/movp-ii-45-mac-volatility-vs-rubilyn.html
We hope you have enjoyed this month's posts and will be trying 2.3 when its released!
Thanks,
Andrew (@attrc)
This week's posts discussed a number of new and updated plugins used to analyze Mac systems.
The first post demonstrated leveraging process cross-view analysis for Mac rootkit detection:
http://volatility-labs.blogspot.com/2013/06/movp-ii-41-leveraging-process-cross.html
The second post covered dumping, scanning, and searching process memory:
http://volatility-labs.blogspot.com/2013/06/movp-ii-42-dumping-scanning-and.html
The third post discussed how to recover networking information:
http://volatility-labs.blogspot.com/2013/06/movp-ii-43-recovering-mac-os-x-network.html
The fourth post showed a number of artifacts in Mac kernel memory:
http://volatility-labs.blogspot.com/2013/06/movp-ii-44-whats-in-your-mac-osx-kernel.html
The fifth post analyzed the Rubilyn kernel rootkit and detected it in a number of ways:
http://volatility-labs.blogspot.com/2013/06/movp-ii-45-mac-volatility-vs-rubilyn.html
We hope you have enjoyed this month's posts and will be trying 2.3 when its released!
Thanks,
Andrew (@attrc)
Wednesday, May 29, 2013
Second Week of Month of Volatility Plugins II is posted
We are writing as the second week of the second installment of the Month of Volatility Plugins is now posted. Volatility 2.3 is currently in beta, and the blog posts are focusing on new features in this version. This week's posts discussed a number of new and updated plugins used to analyze Windows systems. The first post discussed recovering RSA Private Keys and SSL Certificates from memory: http://volatility-labs.blogspot.com/2013/05/movp-ii-21-rsa-private-keys-and.html The second post discussed recovering information about unloaded kernel modules from memory: http://volatility-labs.blogspot.com/2013/05/movp-ii-22-unloaded-windows-kernel_22.html The third post showed how to create timelines with in-memory data using Volatility: http://volatility-labs.blogspot.com/2013/05/movp-ii-23-creating-timelines-with.html The fourth post demonstrated how to recover MFT entries and utilize them during investigations: http://volatility-labs.blogspot.com/2013/05/movp-ii-24-reconstructing-master-file.html The last post highlighted a number of new and updated plugins that are very useful during investigations: http://volatility-labs.blogspot.com/2013/05/movp-ii-25-new-and-improved-windows.html We hope you enjoy the posts, and the third week of posts will begin tomorrow and cover a number of new plugins to help analyze Linux and Android samples. If you have any questions or comments please comment on an individual blog post or reply to this email. Thanks, Andrew (@attrc)
First week of Month of Volatility Plugins II is posted
We are writing as the first week of the second installment of the Month of Volatility Plugins is now posted. Volatility 2.3 is currently in beta, and the blog posts are focusing on new features in this version. This week's posts discussed a number of new address spaces we have added to support new hardware architectures and file formats. The first one is the MachO address space used to support Mac Memory Reader: http://volatility-labs.blogspot.com/2013/05/movp-ii-11-mach-o-address-space.html The second is an address space used to support VirtualBox: http://volatility-labs.blogspot.com/2013/05/movp-ii-12-virtualbox-elf64-core-dumps.html The third address space allows for analysis of VMware snapshot files (.vmss and .vmsn): http://volatility-labs.blogspot.com/2013/05/movp-ii-13-vmware-snapshot-and-saved.html The fourth address space supports the hpak format of the HBGary Fast Dump acquisition tool: http://volatility-labs.blogspot.com/2013/05/movp-ii-14-new-hpak-address-space.html The final address space discussed adds support for the ARM architecture. This is leveraged by Volatility's Android support: http://volatility-labs.blogspot.com/2013/05/movp-ii-15-arm-address-space-volatility.html We hope you enjoy the posts, and the second installment of posts will begin tomorrow and cover a number of new plugins to help analyzing Windows samples. If you have any questions or comments please comment on an individual blog post or email the author. Thanks, Andrew (@attrc)
Tuesday, March 12, 2013
BSides New Orleans Speaker Lineup Published
We are writing to announce that the BSides New Orleans
speaker lineup is now released. For those unaware, BSides New Orleans is a
free, all day information security conference taking place on May 25th
in New Orleans. We received so many strong submissions, from companies such as
Google, Ernst & Young, Mad Security, and HP, that we have expanded the conference
to 3 tracks for a total of 18 presentations. Complete information about the
conference and speakers can be found here:
Between the strong lineup and the fact that the conference is
New Orleans, we expect the seats to fill fast. If you want to attend (free),
you must fill out the EventBrite form referenced on the wiki page. You only
have to give your name and email for registration, and we promise not to spam
you. If you have any questions about the event, please email bsidesnola [ @ ]
gmail.com.
Thanks,
Andrew (@attrc)
Friday, February 15, 2013
Memory Forensics Talk at RSA!
On Wednesday of RSA I will be giving a talk titled:
"Memory Forensics: Defeating Disk Encryption, Skilled Attackers and Malware"
This talk will focus on three key points:
1) Showcasing the power and usefulness of memory forensics
2) Distinguishing memory forensics from disk forensics
3) Highlighting why live forensics should not be used and instead analysts should switch to using offline memory forensics
Throughout the talk there will be many examples of powerful rootkits, techniques of advanced attackers, and looking at Android and software-based disk encryption.
If you are interested in the talk and plan on attending, please add it to your conference calendar:
https://ae.rsaconference.com/US13/connect/sessionDetail.ww?SESSION_ID=1885
If you have any questions about the talk or or want to meet up at RSA then please contact me or ping me on Twitter (@attrc).
"Memory Forensics: Defeating Disk Encryption, Skilled Attackers and Malware"
This talk will focus on three key points:
1) Showcasing the power and usefulness of memory forensics
2) Distinguishing memory forensics from disk forensics
3) Highlighting why live forensics should not be used and instead analysts should switch to using offline memory forensics
Throughout the talk there will be many examples of powerful rootkits, techniques of advanced attackers, and looking at Android and software-based disk encryption.
If you are interested in the talk and plan on attending, please add it to your conference calendar:
https://ae.rsaconference.com/US13/connect/sessionDetail.ww?SESSION_ID=1885
If you have any questions about the talk or or want to meet up at RSA then please contact me or ping me on Twitter (@attrc).
Subscribe to:
Posts (Atom)