RSSAmplifier

Blog

dfir.ch

Recent content on dfir.ch

dfir.chRSS feed ↗72 posts

Latest posts

Field Notes: NSSM - the Non-Sucking Service Manager

Introduction While analyzing Autoruns entries during a Compromise Assessment or an Incident Response case, would you take a second look at the nssm.exe binary running as a service? Hopefully. In a recent case, attackers used nssm.exe to start ngrok as a service to maintain a persistent backdoor. Here is a practical breakdown of how this mechanism works and how you can hunt for it in your…

Fantastic clear-text passwords and where to collect them (Part 2 - Windows)

1. Introduction This post is an expansion of a talk I recently gave about moving beyond standard memory dumping. Pentesters and attackers often rely on dumping the LSASS process to get passwords, but in modern environments, this triggers massive alerts. We are going to explore more sophisticated, alternative methods for attackers to obtain cleartext passwords within a Windows environment. We will…

Fantastic clear-text passwords and where to collect them (Part 1 - Linux)

1. Introduction During Digital Forensics and Incident Response (DFIR) investigations, we frequently observe Threat Actors (TAs) using various methods to harvest clear-text credentials on Linux endpoints. While defense teams focus heavily on Windows credential dumping (like LSASS parsing), Linux infrastructure remains a fertile ground for credential theft. In many discussions with clients and…

Anatomy of a Deno-Based Proxy & RAT

This is a copy of a blog post I wrote for my employee for InfoGuard LABS. Executive Summary In a recent investigation, we encountered malware that combined aggressive social engineering with the unconventional use of Deno, a secure JavaScript and TypeScript runtime built on V8. The attack began with a large-scale email flooding campaign, commonly referred to as mailbombing, designed to overwhelm…

Brucon: Anti-Forensics (and Anti-Anti-Forensics) Techniques

Abstract A full-spectrum dive into anti-forensics across Windows and Linux (with a tad of MacOS, if time permits), centered on real incidents and modern attacker behavior. The course walks through classic log wiping, deeper filesystem tricks, PowerShell, timestomping, sandbox artifacts, memory-only execution, endpoint solution blind spots, and advanced Linux log manipulation. Each technique is…

Botconf: Tomb Raider - In Search of the Lost Signatures

Abstract We explored a decade of open-source offensive tools used in operations worldwide. After analysing hundreds of APT reports and threat-intelligence publications, we compiled a collection of tunnelling tools, reverse shells, loaders, RATs, and living-off-the-land components that threat actors have repeatedly repurposed. This presentation examines if these legacy tools still “work,” how…

FIRST Technical Colloquium Paris: Inside Mythic: Dissecting a Modern Attack Framework

Abstract Your mission if you choose to accept it: take on the role of a detection engineer to dissect the most popular attack framework for attacks against macOS, Mythic. Mythic has various agents that can be easily integrated into the framework. In this talk, we will show common features of the agents, including how C2 communication works, how persistence can be set up, and how additional code…

Dissection of a PHP Backdoor leveraging php-win.exe

Introduction During a recent Incident Response engagement, my colleague Asger Deleuran Strunk identified an unusual Scheduled Task while reviewing AutoRuns data from all servers and workstations across the network. The task, named ClockLauncher, referenced a batch file located at: C:\Windows\Temp\{0b1281f3-c9bc-4b85-ad92-0803ed04208f}\php_2\run-clock.bat Here is the content of the file…

BSides Berlin: Inside Mythic: Dissecting a Modern Attack Framework

Abstract Your mission, if you choose to accept it: take on the role of a detection engineer to dissect the most popular attack framework for attacks against macOS, Mythic. Mythic has various agents that can be easily integrated into the framework. In this talk, we will show common features of the agents, including how C2 communication works, how persistences can be set up, and how additional code…

BSides Chisinau: Congratulations, You're Still Insecure!

Abstract For two decades, the security industry has promised progress: firewalls, antivirus, EDR, XDR, Zero Trust. Budgets have soared, tools have multiplied. And yet attackers still win with the same tricks. Why? Because while we buy shiny solutions, we continue to neglect the basics. This keynote cuts through the illusion of progress and shows why culture and discipline - not the next silver…

Today I learned: binfmt_misc

Introduction binfmt_misc (short for Binary Format Miscellaneous) is a Linux kernel feature that allows the system to recognize and execute files based on custom binary formats. It’s part of the Binary Format (binfmt) subsystem, which determines how the kernel runs an executable file. Normally, Linux only knows how to run native binaries (like ELF files compiled for the system’s CPU architecture,…

Hack.lu: Anti-Forensics - You are doing it wrong

Abstract In this talk, we’ll dissect common anti-forensics strategies—like USN Journal deletion, shellbag clearing, timestamp manipulation, and disabling access time updates—and reveal how they are often executed ineffectively or misunderstood. From registry edits like masking user account activity to configuring Windows EFS, we’ll examine why these techniques often fail against modern…

Troopers: Anti-Forensics - You are doing it wrong

Abstract In this talk, we’ll dissect common anti-forensics strategies—like USN Journal deletion, shellbag clearing, timestamp manipulation, and disabling access time updates—and reveal how they are often executed ineffectively or misunderstood. From registry edits like masking user account activity to configuring Windows EFS, we’ll examine why these techniques often fail against modern…

FIRST Conference: Anti-Forensics - You are doing it wrong

Abstract In this talk, we’ll dissect common anti-forensics strategies—like USN Journal deletion, shellbag clearing, timestamp manipulation, and disabling access time updates—and reveal how they are often executed ineffectively or misunderstood. From registry edits like masking user account activity to configuring Windows EFS, we’ll examine why these techniques often fail against modern…

Euskalhack: In-Depth Study Of Linux Rootkits

Abstract This talk, “In-Depth Study of Linux Rootkits,” will provide a comprehensive examination of the evolution of Linux rootkits, from their inception to the sophisticated variants seen today. Participants will gain insights into advanced rootkit techniques, effective detection strategies, and the future landscape for defenders. By exploring the historical context, current…

x33fcon: From Zero to a Moderately Skilled MacOS Forensic Analyst

Abstract Learn the essentials of macOS forensic analysis, from foundational concepts to advanced techniques, in this comprehensive journey into the world of macOS security. Figure 1: From Zero to a Moderately Skilled MacOS Forensic Analyst Youtube Video

SecurityFest: Anti-Forensics - You are doing it wrong

Abstract In this talk, we’ll dissect common anti-forensics strategies—like USN Journal deletion, shellbag clearing, timestamp manipulation, and disabling access time updates—and reveal how they are often executed ineffectively or misunderstood. From registry edits like masking user account activity to configuring Windows EFS, we’ll examine why these techniques often fail against modern…

Linux Capabilities Revisited

Introduction Notes to kernel developers: The goal of capabilities is divide the power of superuser into pieces, such that if a program that has one or more capabilities is compromised, its power to do damage to the system would be less than the same program running with root privilege. Capabilities(7) — Linux manual page Capabilities are a fine-grained access control mechanism in Linux, allowing…

BSides Transylvania: From Zero to a Moderately Skilled MacOS Forensic Analyst

Abstract Learn the essentials of macOS forensic analysis, from foundational concepts to advanced techniques, in this comprehensive journey into the world of macOS security. Figure 1: BSides Transylvania: From Zero to a Moderately Skilled MacOS Forensic Analyst Youtube Video Not recorded.

FIRST Technical Colloquium Amsterdam: In-Depth Study of Linux Rootkits

Abstract This talk, “In-Depth Study of Linux Rootkits,” will provide a comprehensive examination of the evolution of Linux rootkits, from their inception to the sophisticated variants seen today. Participants will gain insights into advanced rootkit techniques, effective detection strategies, and the future landscape for defenders. By exploring the historical context, current…

BSides Kent: The Gist of Hundreds of Incident Response Cases

Abstract How to become an Incident Response Rockstar? After conducting hundreds of Incident Response cases, more data is not always better. Focusing on the most relevant forensic data can speed up the investigation process rapidly. In this talk, we will discuss the importance of various event logs to track down lateral movement paths from the attackers, how to find planted (and seemingly…

Today I Learned - Protected Symlinks

Introduction A long-standing class of security issues is the symlink-based time-of-check-time-of-use race, most commonly seen in world-writable directories like /tmp. The common method of exploitation of this flaw is to cross privilege boundaries when following a given symlink (i.e. a root process follows a symlink belonging to another user). For a likely incomplete list of hundreds of examples…

macOS Extended Attributes: Case Study

Introduction Extended attributes (EAs) are a powerful and sometimes overlooked feature of macOS’s file system, storing additional metadata about files beyond what standard attributes like file name, size, and permissions allow. While these attributes are invisible in typical file interactions, they play a critical role in various macOS features and workflows. Inspecting Extended Attributes…

Tear Down The Castle - Part 2

This is the second part of a two-part series about Active Directory security. Read the first part here. To gain insight into common issues and patterns of misconfiguration, we analyzed 250 PingCastle reports collected from Incident Response cases and Compromise Assessments. We indicate how many of the 250 domains checked were affected by the finding (Affected Domains: N/250). PingCastle is a…

Oh my .. ! - Suspicious network traffic detected including Ransomware

Introduction A customer contacted us due to a high-severity ransomware alert in Windows Defender for Endpoint (Figure 1). Figure 1: Suspicious network traffic detected including Ransomware Clicking on one of the alerts does not reveal additional details besides the IP address (Figure 2). Figure 2: Process Tree After further clicks, we end up at the explanation in Figure 3, which doesn’t inspire…

Tear Down The Castle - Part 1

Introduction In the realm of IT infrastructure, Active Directory (AD) serves as a crucial backbone, enabling organizations to manage users, devices, and resources efficiently. However, given its central role, it also presents a significant security target, and maintaining its integrity is paramount. Misconfigurations and overlooked security gaps in AD can expose an organization to critical…

Analysis of Python's .pth files as a persistence mechanism

Introduction The purpose of the update.py script is to deploy a backdoor to the following path: /usr/lib/python3.6/site-packages/system.pth. The backdoor, written in Python, starts by an import and its main content is stored as a base64 encoded blob. The .pth extension is used to append additional paths to a Python module. Starting with the release of Python 3.5, lines in .pth files beginning with…

Today I Learned - setfacl

Introduction setfacl is a command-line utility in Linux/Unix systems used to set Access Control Lists (ACLs) on files and directories. ACLs provide a more flexible permission mechanism than the traditional owner-group-other model. They allow for the assignment of specific permissions to individual users or groups beyond what the basic file system permissions support. setfacl [options]…

Shell Script Compiler (shc)

Introduction After installing the payload, the shell script inst.sh runs a backdoor binary that matches the target device’s architecture. The backdoor is a shell script compiled using an open-source project called Shell Script Compiler (shc), and enables the threat actors to perform subsequent malicious activities and deploy additional tools on affected systems." Source: IoT devices and…

DeepSec: RAT Builders - How to catch them all

Abstract Cybercriminals now have unprecedented ease in creating their own remote access trojans (RATs), thanks to a plethora of open-source or leaked builders. One can generate a new binary with just a click of a button. We meticulously examine different builders, such as AgentTesla, DCRat, Nanocore, and others, to extract Indicators of Compromise. These indicators serve as valuable instruments…

BSides Munich: /proc for Security Analysts

Abstract In the intricate landscape of cybersecurity, the ability to uncover hidden threats and analyze system behaviors is paramount.T The /proc filesystem, a critical component of Unix-like operating systems, serves as a treasure trove of real-time data and system information. In this talk, “/proc for Security Analysts,” will delve into the forensic value of /proc, demonstrating how it can be…

Reptile's Custom Kernel-Module Launcher

Introduction “In REPTILE version 2.0, the original developer of REPTILE altered how the Kernel-level component is loaded, switching from using insmod to a custom launcher. The launcher Mandiant observed UNC3886 use throughout their operations, based on the custom launcher, was updated with a new function to daemonize a process.” — Mandiant, Cloaked and Covert: Uncovering UNC3886 Espionage…

Hack.lu: The Gist of Hundreds of Incident Response Cases

Abstract How to become an Incident Response Rockstar? After conducting hundreds of Incident Response cases, more data is not always better. Focusing on the most relevant forensic data can speed up the investigation process rapidly. In this talk, we will discuss the importance of various event logs to track down lateral movement paths from the attackers, how to find planted (and seemingly…

Hack.lu: In-Depth Study of Linux Rootkits: Evolution, Detection, and Defense

Abstract This talk, “In-Depth Study of Linux Rootkits,” will provide a comprehensive examination of the evolution of Linux rootkits, from their inception to the sophisticated variants seen today. Participants will gain insights into advanced rootkit techniques, effective detection strategies, and the future landscape for defenders. By exploring the historical context, current…

bedevil: Dynamic Linker Patching

Introduction bedevil (bdvl), according to the GitHub page, is an LD_PRELOAD rootkit. Therefore, this rootkit runs in userland. The group Muddled Libra used bedevil to target VMware vCenter servers, according to Palo Alto’s Unit42 Blog, 2024. The rootkit comes with a nifty feature called Dynamic Linker Patching: Upon installation, the rootkit will patch the dynamic linker libraries. Before…

Microsoft Defender XDR's Deception Technology

Introduction This week wasn’t the first time we’ve investigated a case where a customer reported suspicious accounts that couldn’t be linked to any employees. In this case, two domain admin users were found on the affected network, but neither is employed by the company. Both accounts had logged into nearly every device within the organization, which understandably caused concern…

tmate - Instant Terminal Sharing (or How To Backdoor a Linux Server)

Introduction Over the last three years, various cyber security companies wrote about TeamTNT TTPs, notably about the use of tmate as their tool of choice for backdooring Linux servers after a compromise: TeamTNT: Cryptomining Explosion (Intezer, 2021) Attackers Abusing Various Remote Control Tools (ASEC, 2022) TeamTNT Reemerged with New Aggressive Cloud Campaign (Aqua, 2023) In this short blog…

EDR: The Great Escape - RomHack Training Review

This course aims to provide a comprehensive understanding of the architecture of modern EDRs and their underlying Antivirus (AV) systems. It delves deeply into the complexity of modern EDRs, their structure, including the components responsible for real-time monitoring, data collection, and threat analysis. [..] 50% of the course will be dedicated to hands-on labs showing how to translate the…

Today I Learned - NSG Flow Log

Introduction Azure flow logs are a feature in Azure that allows you to capture and analyze network traffic to and from virtual network interfaces (NICs) in Azure. Specifically, flow logs provide granular data about IP traffic flowing through a Network Security Group (NSG). Azure automatically creates a network security group (NSG) when you create a virtual machine: $vmname-nsg. This data includes…

ScriptBlock Smuggling

Introduction PowerShell’s Script Block Logging is a security feature that records and logs the contents of all scripts and commands executed within PowerShell. This includes both legitimate administrative scripts and potentially malicious commands. When enabled, Script Block Logging generates detailed logs stored in the Windows Event Log under Microsoft-Windows-PowerShell/Operational. I have…

Botnet Fenix

Introduction To improve my rusty reverse-engineering skills, I’m going to analyze various malware samples that have come up in our incident response cases in loose succession. The first sample belongs to the Fenix botnet (sample here). In this post, we analyze a sophisticated malware infection chain that begins with a user downloading a ZIP file from a Dropbox link and culminates in the…

Today I Learned - WebDAV Cache

Introduction User @karol_paciorek recently tweeted about an open directory containing malware, depicted in Figure 1. You can find the original post here: Figure 1: opendir: 216.9.224[.]58:5555 Along with the MS_calendar.lnk file mentioned in the tweet from @karol_paciorek, there are additional files publicly available on that server: LNK Analysis We will examine the LNK file schedule.lnk (MD5:…

Abusing the “search-ms” URI protocol handler

Introduction Last month, I stumbled upon a blog post from Trustwave titled Search & Spoof: Abuse of Windows Search to Redirect to Malware. Figure 1: Search & Spoof: Abuse of Windows Search to Redirect to Malware (Source: Trustwave) Trustwave SpiderLabs has detected a sophisticated malware campaign that leverages the Windows search functionality embedded in HTML code to deploy malware. We found the…

Tainted Kernels

Introduction A tainted kernel in Linux refers to a kernel that has been marked with one or more flags indicating that it is in a state that might affect its stability or functionality. Detecting tainted kernel module loads is crucial for ensuring system security and integrity, as malicious or unauthorized modules can compromise the kernel and lead to system vulnerabilities or unauthorized access.…

Today I Learned - kernel.modules_disabled

Introduction The kernel.modules_disabled parameter is a security feature in the Linux kernel that prevents the loading and unloading of kernel modules. This setting is particularly useful for hardening a system against certain types of attacks, such as attempts to load malicious kernel modules (think rootkits) or manipulate the system at a low level. Mandiant recently published a blog post where…

Systemd Path Activation - Poor Man's File Integrity

This blog post outlines a method for monitoring changes to files and directories in Linux using path units. Administrators and defenders can be notified of modifications by creating a new path unit, which watches for changes to files and directories and links it to a service unit that executes a script when changes are detected. This setup might be particularly useful for detecting unauthorized…

From Dangerous PHP Functions to Webshell Hunting

This blog post discusses how to enhance PHP security using the disable_functions directive, which prevents specific PHP functions from being executed. We further explore webshell detection techniques, highlighting the challenges of identifying webshells using Yara rules, proposing alternatives like manual analysis, frequency analysis of web server logs, and utilizing tools like Velociraptor and…

FIRST Conference: (Advanced) Purple Teaming - BlueTeam Edition

Abstract How do the bad guys can breach our defenses so fast? In this training, we will touch on different advanced topics that will give you a better understanding of how attacks are carried out and how we can protect ourselves better against them. Windows Credentials: The various forms of credentials and how they are used during authentication. We will learn how attackers can steal these…

Today I Learned - Instrument ClamAV to extract AutoIT scripts

Introduction A customer contacted us because they intend to use SimpleLAPS-GUI in their company. However, multiple AV vendors flag the precompiled binary (SimpleLapsGui.exe) as malicious (see here). According to the FAQ on the GitHub repository from SimpleLAPS-GUI: Does the exe version contains viruses? It is reported on “virustotal.com”. No it doesn’t. This happens because of…

SecurityFest: The Gist of Hundreds of Incident Response cases

Abstract How to become an Incident Response Rockstar? After conducting hundreds of Incident Response cases, more data is not always better. Focusing on the most relevant forensic data can speed up the investigation process rapidly. In this talk, we will discuss the importance of various event logs to track down lateral movement paths from the attackers, how to find planted (and seemingly…