_abhiramkumar's profile picture. 🇮🇳 | DFIR @ Unit42| Former Captain @teambi0s | Author of MemLabs | GCFA | GREM | Views my own

Abhiram Kumar

@_abhiramkumar

🇮🇳 | DFIR @ Unit42| Former Captain @teambi0s | Author of MemLabs | GCFA | GREM | Views my own

Pushed the latest version of Volatility 3 2.26.0 Windows binary to GitHub. Also modified the batch file vol3-compile.bat present on the repository. Link: github.com/stuxnet999/vol…


Abhiram Kumar รีโพสต์แล้ว

TEAM bi0s SHINES AT #TUCTF 2024! 🏆 5th Place Globally 🎓 2nd Among Colleges Worldwide A remarkable performance at TUCTF 2024, organized by the University of Tulsa, #Oklahoma! Get more insights on India’s #1 CTF Team: @team_bi0s (X, Instagram, LinkedIn) #CTF #CyberSecurity

teambi0s's tweet image. TEAM bi0s SHINES AT #TUCTF 2024!
🏆 5th Place Globally 
🎓 2nd Among Colleges Worldwide
A remarkable performance at TUCTF 2024, organized by the University of Tulsa, #Oklahoma! 
Get more insights on India’s #1 CTF Team: @team_bi0s (X, Instagram, LinkedIn)
#CTF #CyberSecurity

Abhiram Kumar รีโพสต์แล้ว

Introducing VolExoPass - Volatility 3 plugin that extracts potential Exodus Wallet passphrases. It analyzes process VAD to recover passphrases along with their VAD allocation address, passphrase memory location, and PID. github.com/Azr43lKn1ght/V… #volatility3

Azr43lKn1ght's tweet image. Introducing VolExoPass - Volatility 3 plugin that extracts potential Exodus Wallet passphrases. It analyzes process VAD to recover passphrases along with their VAD allocation address, passphrase memory location, and PID.

github.com/Azr43lKn1ght/V…

#volatility3
Azr43lKn1ght's tweet image. Introducing VolExoPass - Volatility 3 plugin that extracts potential Exodus Wallet passphrases. It analyzes process VAD to recover passphrases along with their VAD allocation address, passphrase memory location, and PID.

github.com/Azr43lKn1ght/V…

#volatility3

Pushed the Windows binary for the latest version of Volatility-3 2.11.0 to my GitHub repo - github.com/stuxnet999/vol… I tested some of new Windows plugins and it seemed to work fine. Please let me know if any of the plugins crashes. #DFIR #IncidentResponse #cybersecurity


Awesome work by @Azr43lKn1ght on creating DFIR LABS. Those who are looking to get a good grip on DFIR via CTFs, this repository is great resource! Credits to all the CTF players involved in this nice project. @teambi0s. Absolutely worth checking out!

Introducing DFIR Labs: A 24-challenge series by internationally acclaimed CTF authors, tailored for professionals, researchers and students. Master DFIR, Malware Analysis and Threat Hunting through challenges designed to push your expertise to new heights github.com/Azr43lKn1ght/D…

Azr43lKn1ght's tweet image. Introducing DFIR Labs: A 24-challenge series by internationally acclaimed CTF authors, tailored for professionals, researchers and students. Master DFIR, Malware Analysis and Threat Hunting through challenges designed to push your expertise to new heights
github.com/Azr43lKn1ght/D…
Azr43lKn1ght's tweet image. Introducing DFIR Labs: A 24-challenge series by internationally acclaimed CTF authors, tailored for professionals, researchers and students. Master DFIR, Malware Analysis and Threat Hunting through challenges designed to push your expertise to new heights
github.com/Azr43lKn1ght/D…
Azr43lKn1ght's tweet image. Introducing DFIR Labs: A 24-challenge series by internationally acclaimed CTF authors, tailored for professionals, researchers and students. Master DFIR, Malware Analysis and Threat Hunting through challenges designed to push your expertise to new heights
github.com/Azr43lKn1ght/D…


Abhiram Kumar รีโพสต์แล้ว

2024-09-19 (Thurs): As early as 2024-09-10, this infection chain abuses steamerrorreporter64.exe to side-load vstdlib_s64.dll as a downloader to retrieve & run #LummaStealer. Details at bit.ly/3zrV0yY #DllSideLoading #Lumma #TimelyThreatIntel #Unit42ThreatIntel

Unit42_Intel's tweet image. 2024-09-19 (Thurs): As early as 2024-09-10, this infection chain abuses steamerrorreporter64.exe to side-load vstdlib_s64.dll as a downloader to retrieve & run #LummaStealer. Details at bit.ly/3zrV0yY

#DllSideLoading #Lumma #TimelyThreatIntel #Unit42ThreatIntel
Unit42_Intel's tweet image. 2024-09-19 (Thurs): As early as 2024-09-10, this infection chain abuses steamerrorreporter64.exe to side-load vstdlib_s64.dll as a downloader to retrieve & run #LummaStealer. Details at bit.ly/3zrV0yY

#DllSideLoading #Lumma #TimelyThreatIntel #Unit42ThreatIntel
Unit42_Intel's tweet image. 2024-09-19 (Thurs): As early as 2024-09-10, this infection chain abuses steamerrorreporter64.exe to side-load vstdlib_s64.dll as a downloader to retrieve & run #LummaStealer. Details at bit.ly/3zrV0yY

#DllSideLoading #Lumma #TimelyThreatIntel #Unit42ThreatIntel
Unit42_Intel's tweet image. 2024-09-19 (Thurs): As early as 2024-09-10, this infection chain abuses steamerrorreporter64.exe to side-load vstdlib_s64.dll as a downloader to retrieve & run #LummaStealer. Details at bit.ly/3zrV0yY

#DllSideLoading #Lumma #TimelyThreatIntel #Unit42ThreatIntel

Abhiram Kumar รีโพสต์แล้ว

.@bunsofwrath12 shared some incredibly useful PowerShell scripts with us for working with @thor_scanner in a forensic lab setting github.com/NextronSystems…

cyb3rops's tweet image. .@bunsofwrath12 shared some incredibly useful PowerShell scripts with us for working with @thor_scanner in a forensic lab setting
github.com/NextronSystems…

Relocated to Bengaluru!


Abhiram Kumar รีโพสต์แล้ว

We've released Process Monitor v4.0 with UI, performance and security improvements and bug fixes, and Sysmon 1.3.3 for Linux with fixes for kernel 6.6+. Get the tools at sysinternals.com. See what's new on the Sysinternals Blog: techcommunity.microsoft.com/t5/sysinternal…

techcommunity.microsoft.com

Process Monitor v4.0 and Sysmon 1.3.3 for Linux | Microsoft Community Hub

Learn about the latest updates to Process Monitor v4.0 and Sysmon 1.3.3 for Linux


Pushed the Windows binary of Volatility 3 version 2.7.0. To compile it yourself, you can run the vol3-compile.bat present in the same repo. Find it here - github.com/stuxnet999/vol… #DFIR #memoryforensics


Abhiram Kumar รีโพสต์แล้ว

There are certain books whose knowledge can't be assimilated with a single reading. Maybe reading 10 times won't do it. Such books are precious because you evolve each time you read them. I have found two such books - Karma Yoga and Jnana Yoga.


Loading...

Something went wrong.


Something went wrong.