sec

[forensics] OpenIOC

sec

OpenIOC http://openioc.org/ PCから証跡を収集し、シグネチャと比較する事により インシデントの検知を行う IOC FINDER http://www.mandiant.com/resources/download/ioc-finder データ収集とレポーティング IOC EDITOR http://www.mandiant.com/resources/…

[forensic] Windows Registry: Application Compatibility Cache

sec

Windows Registry: Application Compatibility Cache | Forensic Methods

Defcon20Slides

sec

Defcon20Slides directory listing

[forensics] Analysis & Correlation of Mac Logs

sec

http://computer-forensics.sans.org/summit-archives/2012/analysis-and-correlation-of-macintosh-logs.pdf

[malware] Analyzing PDF Malware - Part 3D

sec

Analyzing PDF Malware - Part 3D

[malware] Inject your code to a Portable Executable file

sec

Programmers Heaven - Resources for Developers

[forensics] wtmp timeline efforts

sec

ZENA FORENSICS: wtmp timeline efforts

[memory] Mac Memory Analysis with Volatility

sec

Mac Memory Analysis with Volatility

[memory] Memoryze™ for the Mac 1.0

sec

http://www.mandiant.com/resources/download/mac-memoryze-1.0trade

[難読化] JSDetox

sec

A Javascript malware analysis tool using static analysis / deobfuscation techniques and an execution engine featuring HTML DOM emulation Relentless Coding

[NSRL] [Hash] ファイルハッシュセット

sec

NSRL Downloads

windows-8-forensic-guide

sec

http://propellerheadforensics.files.wordpress.com/2012/04/thomson_windows-8-forensic-guide.pdf

Computer Forensic Artifacts: Windows 7 Shellbags

sec

Computer Forensic Artifacts: Windows 7 Shellbags | Forensic Methods

An interesting case of Mac OSX malware

sec

An interesting case of Mac OSX malware - Microsoft Malware Protection Center - Site Home - TechNet Blogs

[forensics] Memory Forensics Cheat Sheet

sec

SANS Digital Forensics and Incident Response Blog | Memory Forensics Cheat Sheet | SANS Institute

Physical Memory Analysis with the LiME Linux Memory Extractor

sec

Physical Memory Analysis with the LiME Linux Memory Extractor | Linux.com

New Version of OSX.SabPub & Confirmed Mac APT attacks

sec

New Version of OSX.SabPub & Confirmed Mac APT attacks - Securelist

Malware Analysis Resources

sec

grand stream dreams: Malware Analysis Resources

Malware Analysis Tutorials: a Reverse Engineering Approach

sec

Dr. Fu's Security Blog: Malware Analysis Tutorials: a Reverse Engineering Approach

Quick Review: Redline with IOC Report

sec

http://cci.cocolog-nifty.com/blog/2012/03/quick-review-re.html [http://cci.cocolog-nifty.com/blog/2012/03/quick-review-re.html:image]

Hardening 要塞化 ハードニング

sec

Security Configuration Guides - NSA/CSS

ここが変だよ、グローバルスタンダードの脆弱性対策〜入力値の考え方〜

sec

ここが変だよ、グローバルスタンダードの脆弱性対策~入力値の考え方~

Introduction of Content-Security-Policy

sec

http://utf-8.jp/public/20120327/owaspj-csp.pptx

ファジング活用の手引き

sec

脆弱性対策:ファジング:IPA 独立行政法人 情報処理推進機構

[forensics] [memory]

sec

FATKit: The Forensic Analysis ToolKit - Memory Forensics Memparser download | SourceForge.net

Flash Exploitation Database

sec

http://web.appsec.ws/FlashExploitDatabase.php

デブサミ2012、講演スライド資料まとめ

sec

デブサミ2012、講演スライド資料まとめ:CodeZine(コードジン)

OllyDbg Plugins

sec

OllyDbg Plugins http://www.openrce.org/downloads/browse/OllyDbg_Plugins 導入プラグイン Olly Advanced Analyze This Bookmarks CommandBar Command Line DllBreakEx OllyBonE OllyDump OllyFlow OllyHeapTrace OllyScript OllySocketTrace OllyDbg PE D…

Crash Dump Analysis

sec

WordPress › Error Memory Dump File Samples http://www.dumpanalysis.org/blog/index.php/crash-dump-examples/

[memory] volafox

sec

Memory analyzer for Mac OS X & BSD http://code.google.com/p/volafox/SnowLeopardのメモリダンプ http://forensic.korea.ac.kr/volafox/files/SnowLeopard/MemoryImage.zip $ python volafox.py -i MemoryImage.mem -o proc_info [+] Memory Image: Memor…