NotSteph retweetledi
NotSteph
814 posts

NotSteph
@notstephtweets
Math nerd turned digital forensics nerd. Most proud of my cat mom abilities. Opinions my own.
Katılım Nisan 2012
271 Takip Edilen234 Takipçiler

Mushy now supports LevelDBs, check out the update via @BlakDouble #DFIR doubleblak.com/app.php?id=Mus…
English

Hard to explain the joy I experienced finding out about @hexordia's new weekly CTF! Let's goooo hexordia.com/spring2024-wee…
English
NotSteph retweetledi

You can write and test YARA rules directly in CyberChef
#recipe=YARA_Rules('rule%20beepboop%20%7B%5Cnstrings:%5Cn$mz%20%3D%20%22mz%22%20nocase%5Cn$s1%20%3D%20%22beep%22%5Cn$s2%20%3D%20%22boop%22%20%5Cncondition:%5Cnfilesize%20%3C%201000%5Cnand%20$mz%20at%200%20%5Cnand%20all%20of%20them%5Cn%7D',false,false,false,true,true,true)&input=bXogdGVzdCBtYXRlcmlhbCAKdGhhdCB5b3UgYXJlIHNjYW5uaW5nCnNvbWV0aGluZyBzb21ldGhpbmcgCmJlZXAgYm9vcCBjb21wdXRlcg" target="_blank" rel="nofollow noopener">gchq.github.io/CyberChef/#rec…
#100daysofYARA

English

@KevinPagano3 @UlfFrisk I’ve used vmss2core to combine the vmem and vmss in the past but can’t find those notes atm. Is this at all helpful in this case: angry-bender.github.io/blog/vmware_sn…
English

Anyone know how to convert .vmem to .raw? Trying to get it to work with MemProcFS @UlfFrisk
English
NotSteph retweetledi
NotSteph retweetledi
NotSteph retweetledi
NotSteph retweetledi

Packing stickers and buttons and other random things for #DFIRSummit, if anyone wants some come find me 😊

English

NotSteph retweetledi
NotSteph retweetledi
NotSteph retweetledi
















