The Leahy Center | Cyber5W
www.technosecurity.us/east/confere...
www.technosecurity.us/east/confere...
There was a sample of this script being distributed through a third party webapp, where it had been modified to include some suspicious enumeration techniques, and sent them back to a remote server.
(1/2)
There was a sample of this script being distributed through a third party webapp, where it had been modified to include some suspicious enumeration techniques, and sent them back to a remote server.
(1/2)
Join us on Dec 4th, 12 PM ET for Windows Forensic Investigation! Explore Windows artifacts & techniques critical for DFIR investigations. Perfect for investigators & forensic pros!
🎯 Don’t miss it; register now: bit.ly/c5w-webinar4
#DFIR #Cyber5W
Join us on Dec 4th, 12 PM ET for Windows Forensic Investigation! Explore Windows artifacts & techniques critical for DFIR investigations. Perfect for investigators & forensic pros!
🎯 Don’t miss it; register now: bit.ly/c5w-webinar4
#DFIR #Cyber5W
It was a tool to parse the NTFS $MTF file. I wrote it to solve problems I had with other GUI based tools, though this is CLI.
If you’d like to check it out, you can find it on my github!
github.com/cyberyom/MFT...
It was a tool to parse the NTFS $MTF file. I wrote it to solve problems I had with other GUI based tools, though this is CLI.
If you’d like to check it out, you can find it on my github!
github.com/cyberyom/MFT...