Find malware running from temporary directories using procfs.
Category: CTF
Finding Masquerading Processes With procfs
Find masquerading processes using procfs.
Using procfs For Forensics and Incident Response
Using procfs For Forensics and Incident Response.
Installing evil-winrm on Ubuntu 20.04
Install evil-winrm on Ubuntu 20.04
CTF Triage Data Acquisition
A quick overview of triage data acquisition in the context of attack/defend CTFs.
Post-Exploitation With gawk
Some post exploitation techniques using gawk.
Accessing Alternate Data Streams on VMDK Images on Linux
Accessing Alternate Data Streams on VMDK Images on Linux.
Using finger.exe to Transfer Files
Abusing finger.exe to send data over the network
CTF Laptops
A common question that new CTF players have is what kind of hardware and software they should bring to an event. I am writing this post to have general-purpose documentation to point people to. The main takeaways from this write-up: Know the rules of the event.You don't need anything fancy.Your laptop should probably be capable …
Volatility Notes
Some notes and links related to the Volatility Framework
Volatility on Ubuntu 20.04
Quick and dirty way to get Volatility working on Ubuntu 20.04
Finding Bad With Package Managers
Learn how to use dpkg, rpm, and other related tools to find malware on your systems.