
Fourteen_Endpoints
Shell Companies Inside Apple's Privacy Relay

Shell Companies Inside Apple's Privacy Relay

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

CVE-2017-0199 XLS --> HTA --> VBS --> STEGANOGRAPHY --> DBATLOADER/GULOADER STYLE MALWARE

Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

Distributed & real time digital forensics at the speed of the cloud

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐