Andrea Fortuna
AboutSearch
Tools
DFIR Toolkit OSINT Toolkit
  • Jun 27, 2018

    Pay attention to unknown USB sticks!

    Some days ago, with a colleague, i’ve talked about the real usefulness of USB hardware locks on critical clients/servers. … read more »
  • Jun 25, 2018

    Google App Engine and Python: a correct way to store configuration variables

    When you develop an application, often you could need to store some configurations. This data can contain a lot of sensitive informations, and this is a critical point if your sourcecode is hosted on a GitHub repository. … read more »
  • Jun 22, 2018

    Andrés Segovia’s daily practice routine

    It’s not a mistery: a musician needs to spend time with the instrument. … read more »
  • Jun 20, 2018

    Malware analysis: Gargoyle, a memory scanning evasion technique

    Gargoyle is a memory analysis evasion technique that uses return-oriented programming (RoP) for hiding all of a program’s executable code in non-executable memory when it is inactive, and temporarily mark it executable to do some work at a pre-defined interval… read more »
  • Jun 18, 2018

    Fun with network protocols, using Python and Impacket

    Impacket is a collection of Python classes, developed by Core Security, for working with network protocols, which provides a low-level programmatic access to the packets and, for some protocols such us SMB1-3 and MSRPC, the protocol implementation itself. … read more »
  • Jun 15, 2018

    Stock-market fraud, steganography and cyberattacks...in 1834! The fascinating tale of Blanc brothers

    When the first hacking of a telecommunication system occurred? … read more »
  • Jun 13, 2018

    Analysing Active Directory event logs to identify compromised accounts

    During investigation in a security incident, event log analysis is a key element. … read more »
  • Jun 11, 2018

    Powercat: a porting of Netcat written in Powershell

    With some useful enhanced features! … read more »
  • Jun 8, 2018

    How to check your website for GDPR compliance, from command line!

    On 25th May 2018, the GDPR (General Data Protection Regulation) enacted by the EU has come into effect. … read more »
  • Jun 6, 2018

    Dumpzilla: a forensic tool to extract information from browsers based on Firefox

    Dumpzilla is a Python 3 script developed to extract artifacts from Firefox, Iceweasel and Seamonkey browsers, useful durgin a forensic analysis. … read more »
  • Jun 4, 2018

    Using MFT anomalies to spot suspicious files in forensic analysis

    A typical NTFS filesystem contains hundreds of thousands of files. … read more »
  • Jun 1, 2018

    "Ludovico Technique", a simple guitar study for beginners

    A very basic fingerstyle piece composed for my guitar students: a little study inspired by a melody by Ludovico Einaudi. … read more »
  • May 30, 2018

    How to check Cloudflare cache status programmatically

    Just imagine: your small web app, that allows user to download medium-large ZIP files, due a lucky reddit post, suddenly start to receive huge amount of traffic, and specifically a lot of downloads. … read more »
  • May 28, 2018

    How to install (and run) tcpdump on Android devices

    When performing the analysis of a malicious Android program directly on the device, often can be required to dump some network traffic. … read more »
  • May 25, 2018

    Happy Towel (and GDPR) Day!

    Every year, on May 25, i write a small post celebrating the Towel Day, but this time there is also a further event! … read more »
  • May 23, 2018

    Forensic Artifacts: evidences of program execution on Windows systems

    During a forensic analysis of a Windows system, it is often critical to understand when and how a particular process has been started. … read more »
  • May 21, 2018

    Malware VM detection techniques evolving: an analysis of GravityRAT

    The malware detects virtualized environments by taking infected machines’ CPU temperature. … read more »
  • May 18, 2018

    Alexandr Misko at TEDxMannheim

    Alexandr Misko, 20 years old, a great percussive-fingerstyle technique and a successful career as a musician. … read more »
  • May 16, 2018

    Exploiting SUDO for Linux privilege escalation

    Abusing SUDO for fun and profit! … read more »
  • May 14, 2018

    Some thoughts about RDP protocol, from the point of view of cybersecurity

    Microsoft Terminal Services Remote Desktop Protocol (RDP) is a great feature that allows the interactive use or administration of a remote Windows system. … read more »
« Previous page Next page »

Andrea Fortuna

  • Andrea Fortuna
  • andrea@andreafortuna.org
  • andreafortuna
  • andreafortunaig
  • andrea-fortuna

Cybersecurity expert, software developer, experienced digital forensic analyst, musician