• How to read Windows Hibernation file (hiberfil.sys) to extract forensic data?

    The hibernation file (hiberfil.sys) is the file used by default by Microsoft Windows to save the machine's state as part of the hibernation process. The operating system also keeps an open file handle to this file, so no user, including… read more »
  • My Weekly RoundUp #92

    The news I read last week didn't really impress me. Just something about Microsoft and OpenSource and, of course, Game Of Thrones! Privacy Security lapse exposed a Chinese smart city surveillance system: thousands of facial recognition scans were matched against… read more »
  • The history of the world according to cats

    Okay, it's Friday. Today we're talking about a light and funny topic: yes, we talk about cats! The domestication of the modern house cat can be traced back to at the Neolithic era. Neolithic farmers stored grain in large pits… read more »
  • iptables: a simple cheatsheet

    Whether you’re a novice user or a system administrator, iptables is a mandatory knowledge! iptables is the userspace command line program used to configure the Linux 2.4.x and later packet filtering ruleset.When a connection tries to establish itself on your… read more »
  • My Weekly RoundUp #91

    Strange weekend for Firefox users... Technology Firefox Addons Being Disabled Due to an Expired Certificate Mozilla Firefox users are discovering that all of their addons were suddenly disabled. It turns out that this is being caused by an expired intermediary… read more »
  • Matteo Carcassi, "Andantino in C": a simple Ukulele arrangement

    Matteo Carcassi was a famous Italian guitarist and composer.Born in Florence, Carcassi also studied the piano, but learned guitar when still a child: he quickly gained a reputation as a virtuoso concert guitarist. This simple study is taken from the… read more »
  • RaiPlayDL: a python script to automatically download and merge RaiPlay Radio Podcasts

    RaiPlay is the online platform of italian national broadcast company RAI: on this platform a big amount of interesting contents are freely available. A special section is dedicated to radio channels, with a lot of good (italian) audio tracks: documentary,… read more »
  • My Weekly RoundUp #90

    DockerHUB had some trouble… Privacy Alexa, stop being creepy! Our letter to Jeff Bezos Dear Mr. Bezos, We are writing to call for your urgent action regarding last week’s report[1] in Bloomberg, which revealed that Amazon has been employing thousands… read more »
  • Glenn Greenwald: Why privacy matters

    This TED Talk by Glenn Greenwald is really inspiring. Glenn Greenwald was one of the first reporters to see the Edward Snowden files, with their revelations about the United States' extensive surveillance of private citizens. In May 2013, Glenn Greenwald… read more »
  • How to mount a Azure's VHD disk image on Linux

    I just recently to perform a forensic analysis on a compromised Microsoft Azure VM, and I'd like to share a couple of useful tips. The first step is the download of disk image of the VM.Pretty simple: Azure dashboard allows… read more »
  • My Weekly RoundUp #89

    Bendgate 2.0, Sea Turtle Hijacking and some problems for 'Wannacry Hero' Privacy The mystery of the Amazon Echo data With over 6.3 million Amazon Echo devices worldwide, there is a good chance these constantly active devices will record criminal behavior.Bloomberg, who recently… read more »
  • "New Britain" (Amazing Grace): a fingerstyle ukulele rendition

    "New Britain" was originally a pentatonic folk tune, with melodic figures that outline triads: probably it was sung slowly with grace notes and melodic embellishments. In 1835 William Walker assigned to this song the words of the hymn "Amazing Grace"… read more »
  • How to extract forensic artifacts from pagefile.sys?

    Microsoft Windows uses a paging file, called pagefile.sys, to store page-size blocks of memory that do not current fit into physical memory. This file, stored in %SystemDrive%\pagefile.sys is a hidden system file and it can never be read or accessed… read more »
  • My Weekly RoundUp #88 - Dragonblood, M87 Black Hole, SpaceX and Game of Thrones' Season 8

    No, nothing about Julian Assange's arrest: i've already published a long post last friday. Cybersecurity Serious flaws leave WPA3 vulnerable to hacks that steal Wi-Fi passwords The next-generation Wi-Fi Protected Access protocol released 15 months ago was once hailed by… read more »
  • Julian Assange’s arrest: some hightlights

    A famous activist, appreciated award-winning journalist author of great journalistic scoops, was dragged out of an embassy and arrested.No, it didn't happen in a dictatorial state, it happen in London. An interesting point, IMHO, is that the Julian Assange’s charges… read more »
  • Permanently delete files in Windows using built-in utilities

    A good wiping tool is available in all Windows systems since Windows 2000 Cipher.exe is a command line tool was originally released with Windows 2000 with the release of NTFS V5.0 and the ability to use the Encrypting File System,… read more »
  • My Weekly RoundUp #87

    Can Tesla's AI beat the Kobayashi Maru Test? Technology AT&T Archives: The UNIX Operating System https://www.youtube.com/watch?v=tc4ROCJYbm0 In the late 1960s, Bell Laboratories computer scientists Dennis Ritchie and Ken Thompson started work on a project that was inspired by an operating… read more »
  • Must-Know Ukulele pieces: Gavotte 1 & 2 from J.S. Bach Cello suite No.6 BWV 1012

    The six Cello Suites (BWV 1007-1012), are suites for unaccompanied cello by Johann Sebastian Bach. They are some of the most frequently performed and recognizable solo compositions ever written for cello. Bach most likely composed them during the period 1717–23,… read more »
  • How to analyze a VMware memory image with Volatility

    A very brief post, just a reminder about a very useful volatility feature. The process on a VMware machine is more simple than VirtualBox, just 4 simple steps: Suspend the virtual machine Navigate to the virtual machine's directory and identify… read more »
  • My Weekly RoundUp #86 - What happened in the Article 13's Week?

    Last week the European Union’s Copyright Directive was approved by the European Parliament in Strasbourg.Here some interesting articles about this significant topic, but also more light news. Technology What is Article 13? The EU's copyright directive explained Article 13 is… read more »