資訊安全相關內容分享

資安鑑識-Memory Analyzing

主要利用volatility framework 2.6執行 識別system profile python vol.py -f %image\_name% imageinfo pslist pstree cmdscan 延伸閱讀 [轉]藍隊訓練 [轉]病毒分析教學 Malware-Analysis-Training 藍隊營運Blue Team Operations [Part 1]:

藍隊營運Blue Team Operations [Part 2]: How To Investigate Malware Incidents as a SOC Analyst

介紹 Malware incidents are the most common yet most dangerous cyber security incidents in any organization. We shall discuss how a SOC expert will investigate malware incidents in a real-time corporate environment along with a relevant example. Before we discuss malware incidents in detail, first, we will understand what is malware? According to Norton, “Malware is an abbreviated form of “m