• My Weekly Roundup #161

    Cybersecurity Samsung Has Been Hacked: What Data Has Been Stolen? On September 2, Samsung published a security advisory confirming it had been hacked. The breach would appear to have been of Samsung systems in the U.S. and took place in… read more »
  • Search tools for forensic investigation

    During a forensic investigation, a big part of all tasks are composed by searches on files. Below is a brief list of the tools I usually use for this type of activity.. awk An extremely useful tool, especially for parsing… read more »
  • Windows 10 administrator password recovery

    Time ago I have had to perform memory capture on a Windows 10 system that was infected with malware but whose administrator password had been lost. “Fortunately,”, the malware had gained a fair amount of persistence and was able to… read more »
  • My Weekly Roundup #160

    Cybersecurity A new botnet Orchard Generates DGA Domains with Bitcoin Transaction Information DGA is one of the classic techniques for botnets to hide their C2s, attacker only needs to selectively register a very small number of C2 domains, while for… read more »
  • My Weekly Roundup #159

    Cybersecurity Microsoft ties novel ‘Raspberry Robin’ malware to Evil Corp cybercrime syndicate Microsoft’s security team published evidence this week tying the Raspberry Robin malware to Russian cybercrime syndicate Evil Corp. New Qualys Research Report: Evolution of Quasar RAT The Qualys… read more »
  • My Weekly Roundup #158

    Cybersecurity Reverse Image Search Guide #osint The tool I recommend you start your search with is Yandex Images. Not only does it search very well for similar images, but it also recognizes the text on them and identifies the location… read more »
  • My Weekly Roundup #157

    A selection of interesting news published during this week on news.andreafortuna.org. Cybersecurity Above the Fold and in Your Inbox: Tracing State-Aligned Activity Targeting Journalists, Media Key Takeaways Those involved in media make for appealing targets given the unique access, information,… read more »
  • My Weekly Roundup #156

    Cybersecurity Killnet: Russian DDoS Group Claims Attack on US Congress Website On July 8, the Russian hacktivist DDoS group “Killnet” claimed responsibility for an attack on the website of US Congress. A Library of Congress spokesperson told CyberScoop that the… read more »