2014-01-01から1年間の記事一覧

[malware] Viper

sec

マルウェア管理、解析フレームワーク http://viper-framework.readthedocs.org/en/latest/index.html Viper is a binary analysis and management framework. sudo apt-get install gcc python-dev python-pip sudo pip install SQLAlchemy PrettyTable pyth…

nginx,elasticsearch,kibanaインストール

============================================================== nginxのインストール #vi /etc/yum.repos.d/nginx.repo[nginx] name=nginx repo baseurl=http://nginx.org/packages/centos/5/$basearch/ gpgcheck=0 enabled=1# yum update # yum search n…

[Mobile Forensics] [Android] Santoku-Linux

sec

https://santoku-linux.com/

[Memory Forensics] メモリフォレンジック

sec

lsass.exeの正しい位置 winlogon.exe | --- lsass.exe --- services.exe | --- Process_A.exe --- Process_B.exe --- Process_B.exe --- Process_B.exe --- Process_B.exe --- Process_B.exe ※「lsass.exe」は一つのみ、複数ある場合はおかしい。 ※「lsass.e…

[forensics] SuperTimeline

sec

【旧】 # mount -o loop,ro,show_files,streams_interface=windows,offset=32256 /mnt/hgfs/image.dd /mnt/windows_mount # log2timeline -z Japan -p -r -f winxp /mnt/windows_mount -w supertimeline.txt # l2t_process -b supertimeline.txt > supertime…

Fluentd mongodb

/etc/td-agent/td-agent.conf type tail path /var/log/httpd/access_log pos_file /var/log/td-agent/apache2.access_log.pos format apache2 tag mongo.apache.access type mongo database apache collection access host localhost port 27017

INetSim: Internet Services Simulation Suite

sec

偽サーバ,DNS,HTTPなど INetSim: Internet Services Simulation Suite - Project Homepage # Available service names are: # dns, http, smtp, pop3, tftp, ftp, ntp, time_tcp, # time_udp, daytime_tcp, daytime_udp, echo_tcp, # echo_udp, discard_tcp,…