Velociraptor & Loki

Velociraptor is a great DFIR tool that becomes more and more popular amongst Incident Handlers. Velociraptor works with agents that are deployed on endpoints. Once installed, the agent automatically “phones home” and keep s a connection with the server… exactly like a malware with it’s C2 server but this time

The post Velociraptor & Loki appeared first on /dev/random.

Continue reading Velociraptor & Loki

Does my jailbroken with root access iPad store any forensic evidence for usage of the lightning connector?

I am willing to give my iPad for a repair shop, but I would like to know whether they tamper with the OS in any way.

Is there any way with or without special software to gather forensic evidence about whether the lightning port was used t… Continue reading Does my jailbroken with root access iPad store any forensic evidence for usage of the lightning connector?

Any approach to copy the disk and take RAM shapshot of RouterOS (Mikrotik)?

everyone!
I have discovered suspicious activity on one of Mikrotik Routers. This device had an outdated version of RouterOS with open ports web, winbox, etc. I believe that it was infected by malware, and there is a need to analyze the con… Continue reading Any approach to copy the disk and take RAM shapshot of RouterOS (Mikrotik)?

New technique excels at lifting fingerprints from shell casings

It would be great if forensics teams could easily lift fingerprints off of bullet casings left at crime scenes, but unfortunately doing so is often quite difficult. A new technique developed at the University of Nottingham could change that.Continue Re… Continue reading New technique excels at lifting fingerprints from shell casings

Could "System Volume Information" be used to find out on which system the storage was used?

If one uses a storage device (USB stick or SD card) on Windows, then it leaves "System Volume Information" folder in the file system. Would there be a way so a forensic guy could definitely tell on which computer the storage devi… Continue reading Could "System Volume Information" be used to find out on which system the storage was used?

Are there differences on how storages are formatted between different OS?

If one formats the same USB stick (or SD card) to FAT32 file system on Windows, or on Linux, or on Android – would there be differences so a forensic guy could definitely tell on which OS or even on which specific machine the USB stick was… Continue reading Are there differences on how storages are formatted between different OS?