Open in app

Sign In

Write

Sign In

soji256
soji256

106 Followers

Home

About

Feb 14, 2021

How to permanently disable Microsoft Defender Antivirus on Windows 10

Windows 10 is equipped with a mechanism to automatically enable Microsoft Defender Antivirus after rebooting, even if it is set to be disabled. This mechanism generally helps to protect the device, but for security researchers, there are times when they want to disable it, such as when analyzing malware, verifying…

Malware Analysis

4 min read

How to permanently disable Microsoft Defender Antivirus on Windows 10
How to permanently disable Microsoft Defender Antivirus on Windows 10
Malware Analysis

4 min read


Jan 28, 2021

How to install ImHex on Ubuntu 20.04

ImHex is a relatively new Hex editor, released in December of 2020, for Reverse Engineers, Programmers and people that value their eye sight when working at 3 AM. GitHub — WerWolv/ImHex https://github.com/WerWolv/ImHex

Hex

4 min read

How to install ImHex on Ubuntu 20.04
How to install ImHex on Ubuntu 20.04
Hex

4 min read


Jan 15, 2020

Advanced Persistent Threat Groups

Here are some useful sites to get a quick overview of relevant Advanced Persistent Threat Groups (APT) groups from APT group names or malware names. Threat Group Cards: A Threat Actor Encyclopedia An APT encyclopedia published by ThaiCERT around 2019/06. It is very useful to get information about APT from APT group names and malware names. https://www.thaicert.or.th/downloads/files/A_Threat_Actor_Encyclopedia.pdf

Cybersecurity

3 min read

Advanced Persistent Threat Groups
Advanced Persistent Threat Groups
Cybersecurity

3 min read


Oct 25, 2019

EXIST with MISP Auto-Installer

I made a script that automatically installs the cyber threat intelligence aggregation and analyzing system EXIST with MISP. soji256/exist_with_misp_autoinstall https://github.com/soji256/exist_with_misp_autoinstall

Cybersecurity

4 min read

EXIST with MISP Auto-Installer
EXIST with MISP Auto-Installer
Cybersecurity

4 min read


Oct 5, 2019

List of Windows 10 Timeline analysis articles

Introduction — Windows 10 Timeline Forensic Artefacts — CCL Group https://cclgroupltd.com/2018/05/03/windows-10-timeline-forensic-artefacts/ Analysis Article WindowsTimeline | SQLite query & Powershell scripts to parse the Windows 10 (v1803+) ActivitiesCache.db https://kacos2000.github.io/WindowsTimeline/ Windows 10 ActivitiesCache.db examination https://kacos2000.github.io/WindowsTimeline/WindowsTimeline.pdf

Windows 10

1 min read

Windows 10

1 min read


Sep 29, 2019

DFIR & Malware Analysis Resources(April to September 2019)

I made this list from my tweets (April to September 2019). DFIR A quick set of anomalies to look for to identify a compromised Linux system https://www.linkedin.com/pulse/quick-set-anomalies-look-identify-compromised-linux-system-b-/ 15 Linux commands ready to try. Threat hunting using DNS firewalls and data enrichment | blog.redteam.pl https://blog.redteam.pl/2019/08/threat-hunting-dns-firewall.html Useful content based on the author’s experience.

Dfir

3 min read

DFIR & Malware Analysis Resources(April to September 2019)
DFIR & Malware Analysis Resources(April to September 2019)
Dfir

3 min read


Jun 20, 2019

Evidence Collecting Tools for Fast Forensics

I used several evidence collection tools for fast forensics to see what the differences were. I check the function mainly from the viewpoint of dumping the file. The following table shows the results in a Windows environment. (*1, *2, *6). *1: What can be obtained without changing the setting. *2…

Forensics

8 min read

Evidence Collecting Tools for Fast Forensics
Evidence Collecting Tools for Fast Forensics
Forensics

8 min read


Jun 16, 2019

How to Get a Log of DNS Queries with Sysmon

Sysmon — Sysmon — Windows Sysinternals | Microsoft Docs https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon Sysmon now supports logging DNS queries, so I tried to get the logs. I checked this procedure with Windows 10 on VMware. Sysmon Installation Instructions Download Sysmon from the official site. Extract the files to a folder of your choice. Launch a command prompt with…

Microsoft

4 min read

How to Get a Log of DNS Queries with Sysmon
How to Get a Log of DNS Queries with Sysmon
Microsoft

4 min read


Jun 12, 2019

Where can I get the images to learn DFIR?

Here’s a list of images that might be appropriate for a “I want to learn forensics, but I don’t have an image for analysis.”. I’m preferentially collecting images with scenarios and answers. The list includes many PC disk images, but also memory images, network packets, mobile phone and drone image…

Cybersecurity

6 min read

Where can I get the images to learn DFIR?
Where can I get the images to learn DFIR?
Cybersecurity

6 min read


Jun 5, 2019

Which versions of vim are affected by the modeline vulnerability (CVE-2019-12735)?

A vulnerability (CVE-2019–12735) has been found in 2019/06/04 that could allow arbitrary code execution via modeline when vim opens a specially crafted text file. Vim < 8.1.1365 …

Vim

4 min read

Which versions of vim are affected by the modeline vulnerability (CVE-2019–12735)?
Which versions of vim are affected by the modeline vulnerability (CVE-2019–12735)?
Vim

4 min read

soji256

soji256

106 Followers

Loves cats and CTFs. …ᓚᘏᗢ… [twitter:@soji256]

Following
  • Matthew.Rosenquist

    Matthew.Rosenquist

  • Curtis Brazzell

    Curtis Brazzell

  • Eliya Stein

    Eliya Stein

  • Roger Galobardes

    Roger Galobardes

  • Eduard Kiiko

    Eduard Kiiko

See all (22)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech