Andrea Fortuna
AboutSearch
Tools
DFIR Toolkit OSINT Toolkit
  • Feb 12, 2018

    Malware hiding and evasion techniques

    Malware authors have always looked for new techniques to stay invisible. … read more »
  • Feb 9, 2018

    USB Devices in Windows Forensic Analysis

    Parsing SetupAPI log for fun and profit! … read more »
  • Feb 7, 2018

    SimpleTwitter: small PHP class for search on Twitter

    Often i publish some small code snippets, usually written during development of large projects. … read more »
  • Feb 5, 2018

    Some thoughts about reverse shells

    During a penetration test, you could lucky enough to find a RCE vulnerability: in this case, the next step should be to obtain an interactive shell. … read more »
  • Feb 2, 2018

    5G Network Slicing and Network Neutrality: my point of view

    Let there be no mistake about this: from a technical point of view, 5G Network Slicing is totally awesome! … read more »
  • Jan 31, 2018

    CVE-2018-0101: Cisco ASA WebVPN is affected by a serious flaw

    Cisco released security updates to address a critical security vulnerability in Cisco ASA software. … read more »
  • Jan 29, 2018

    A Telegram Echo Bot built with a single PHP line

    Some weeks ago i’ve written a brief tutorial focused on building a simple Echo BOT on Telegram using Python. … read more »
  • Jan 26, 2018

    Windows PE run-time encryption with Hyperion

    Hyperion is a crypter for PE files, developed and presented by Christian Amman in 2012. … read more »
  • Jan 24, 2018

    How a malware can be spread through webpages? A simple example made with python

    Recently a colleague asked me an example of how a malware can be spread using simple html pages hosted on a hacked website. … read more »
  • Jan 22, 2018

    Some interesting facts about reverse-engineering of x86 microcode, from a research by Ruhr University Bochum

    Micro­code is an ab­strac­tion layer on top of the phy­si­cal com­po­n­ents of a CPU and is pre­sent in most CPUs. … read more »
  • Jan 19, 2018

    How to create a contextual menu on Windows Explorer for PyInstaller packaging

    Package your python application (for Windows and Linux) with just a right-click! … read more »
  • Jan 17, 2018

    LaZagne, a credentials recovery tool

    LaZagne is a tool developed by Alessandro Zanni useful to retrieve passwords stored on a local computer by most commonly-used software. … read more »
  • Jan 15, 2018

    PE-sieve, a command line tool for investigating inline hooks

    PE-sieve is a small tool for investigating inline hooks and other in-memory code patches, developed by hasherezade. … read more »
  • Jan 12, 2018

    PinMe: tracking a smartphone with localization services turned off

    Arsalan Mosenia, Xiaoliang Dai, Prateek Mittal and Niraj Jha, in paper recently published, describe a new user-location mechanism that exploits non-sensory/sensory data stored on the smartphone to estimate the user’s location when all location services are turned off. … read more »
  • Jan 10, 2018

    Process Doppelgänging: a more stealth alternative of the process hollowing technique?

    Recently at Black Hat Europe conference, Tal Liberman and Eugene Kogan (enSilo lab) presented a a new code injection technique called “Process Doppelgänging”, that works on all Windows versions and seems to be able to bypass most of today’s major… read more »
  • Jan 8, 2018

    <a href="https://www.andreafortuna.org/tag/meltdown/">Meltdown</a>: another PoC in the wild

    Pavel Boldin published a new PoC exploit of Meltdown vulnerability working on Linux, written in C. … read more »
  • Jan 6, 2018

    In-Spectre-Meltdown: a PoC for Meltdown and Spectre vulnerabilities

    In-Spectre-Meltdown is a PoC developed byViral Maniarusing Python and Powershell to check speculative execution side-channel attacks that affect many modern processors and operating systems designs that allows unprivileged processes to steal secrets from privileged processes. … read more »
  • Jan 5, 2018

    Meltdown and Spectre: what we know about the vulnerabilities in CPUs?

    In the last hours, the vulnerabilities of the CPU have had a great prominence even in the non-specialized press. So, I think that would be useful trying to summarize the situation in a simple way. … read more »
  • Jan 3, 2018

    How keyloggers works: a simple example of keyboard hooking using Python

    Keyloggers are often used by malicious softwares to steal sensitive data and login credentials. … read more »
  • Dec 31, 2017

    My Year of Running – 2017

    My running year recap. … read more »
« Previous page Next page »

Andrea Fortuna

  • Andrea Fortuna
  • andrea@andreafortuna.org
  • andreafortuna
  • andreafortunaig
  • andrea-fortuna

Cybersecurity expert, software developer, experienced digital forensic analyst, musician