Michael Ligh (MHL)

4.3K posts

Michael Ligh (MHL)

Michael Ligh (MHL)

@iMHLv2

CTO @Volexity. Malware Analyst's Cookbook. Art of Memory Forensics. The @Volatility Project. Thoughts are those of my employer, not mine, they made me say it.

Katılım Mart 2011
1.4K Takip Edilen9.7K Takipçiler
Michael Ligh (MHL) retweetledi
Kostas
Kostas@Kostastsale·
@iMHLv2 @ConnectWise ConnectWise is whistling past the graveyard for years now...
GIF
English
0
1
2
440
Michael Ligh (MHL)
Compromised systems will look like this when the attacker is actively controlling it
Michael Ligh (MHL) tweet media
English
0
0
1
293
Michael Ligh (MHL)
Sounds different. This was phish email -> klish [.] top/ab/ -> k126.screenconnect [.] com -> modified msi -> relay/connect back to instance-z9sodv-relay.screenconnect [.] com. Telegram via JS gives attacker heads up
English
0
0
3
268
Michael Ligh (MHL) retweetledi
Anthony Peyton
Anthony Peyton@arpeyton·
@iMHLv2 @ConnectWise Had a weird event at a client today. EDR hit on ScreenConnect (valid tool from another MSP) but the user and MSP both confirmed they weren’t in a session. Next hit was SC launching PowerShell and running .ps1 files in windows\systemtemp\screenconnect Related? DM me?
English
0
1
2
395
Michael Ligh (MHL) retweetledi
Volexity
Volexity@Volexity·
The latest @DarknetDiaries (Ep. 174: Pacific Rim) offers a look at state-sponsored groups targeting perimeter infrastructure & edge devices. Thanks @JackRhysider for mentioning our work! @Volexity’s detection and response efforts combined network visibility, host-based analysis, #threatintelligence & #memoryforensics, enabling us to discover these complex #0days being exploited in the wild. Read our blog post for the original research mentioned: volexity.com/blog/2022/06/1…
Jack Rhysider 🏴‍☠️@JackRhysider

Ep 174 "Pacific Rim" is now live! 🔊 Sophos got attacked by a nation state actor. How they handled it is controversial. Curious what you would have done. darknetdiaries.com/episode/174/

English
0
8
14
2.1K
Michael Ligh (MHL) retweetledi
Andrew Case
Andrew Case@attrc·
I am excited to announce that I will be speaking at @bsidesnash on May 15th. Be sure to attend to see all the latest @volatility 3 plugins against the most sophisticated and devastating malware from the wild!
English
1
8
17
2.6K
Michael Ligh (MHL) retweetledi
Andrew Case
Andrew Case@attrc·
Memory-only malware leaves no trace on the file system & is commonly used by threat actors ranging from criminal organizations to ransomware operators to APTs. In our @volatility 3 training, students gain deep hands on experience analyzing such threats: memoryanalysis.net/courses-malwar…
Andrew Case tweet media
English
0
35
142
10.9K
Michael Ligh (MHL) retweetledi
volatility
volatility@volatility·
We have announced the winners of the 2025 @volatility #PluginContest! And the First Place is: Daniel Baier for XFRM Inspector Read the full Contest Results in our blog post: volatilityfoundation.org/the-2025-volat… Congrats to all winners & thank you to all participants! #DFIR #memoryforensics
volatility tweet media
volatility@volatility

The 2025 @volatility #PluginContest review is complete! We received 8 submissions from 7 different countries that included 20 plugins! We will be highlighting each #Contender & the winners will be announced on Friday! #DFIR #memoryforensics

English
0
6
11
3.5K
Michael Ligh (MHL) retweetledi
Volexity
Volexity@Volexity·
.@Volexity recently released GoResolver v1.4, bringing significant updates to our #opensource tool for recovering symbol data from obfuscated Go binaries. This release is available on GitHub: github.com/volexity/GoRes… [1/8]
English
2
15
32
2.7K
Michael Ligh (MHL) retweetledi
volatility
volatility@volatility·
.@volatility #PluginContest #Contender Devarjya Purkayastha: PEScan provides an alternative method for analyzing PE files in a memory sample, assigning a threat score to each memory region that contains a PE file & summarizing high/critical regions. #DFIR #memoryforensics
English
0
2
3
543
Michael Ligh (MHL) retweetledi
volatility
volatility@volatility·
.@volatility #PluginContest #Contender Thomas Clark: The EA App Artifacts, MetaHorizonWorlds & SteamArtifacts plugins help investigators with incidents involving popular gaming platforms by scanning memory for relevant processes and artifacts. #DFIR #memoryforensics
English
0
2
3
556
Michael Ligh (MHL) retweetledi
volatility
volatility@volatility·
.@volatility #PluginContest #Contender Kartik Iyer: APCWatch & MalAPC together provide the capability to identify & analyze APC injection attacks in Windows memory forensics, one of the most sophisticated code injection techniques employed by modern malware #DFIR #memoryforensics
English
0
3
2
488
Michael Ligh (MHL) retweetledi
volatility
volatility@volatility·
.@volatility #PluginContest #Contender Diyar Saadi Ali: This submission includes a suite of detection plugins & tools to identify suspicious processes + artifacts within the memory sample of a suspected system using a variety of heuristics & indicators. #DFIR #memoryforensics
English
0
2
2
452
Michael Ligh (MHL) retweetledi
volatility
volatility@volatility·
.@volatility #PluginContest #Contender Théo Letailleur: Journald Extractor automates extraction of Linux journal files cached in memory, along with analysis via the open-source go-journalctl tool to obtain parsed versions of these files from memory. #DFIR #memoryforensics
English
0
2
2
605