Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label cheat sheets. Show all posts
Showing posts with label cheat sheets. Show all posts

Saturday, November 2, 2013

ForSec Linkfest - 2013 DST Fallback Edition

Posted on 1:23 PM by Unknown

FYI…tomorrow morning at 2 AM here in the United States of America it will be time to “fall back” from DST. One more hour of sleep and then it’s weeks of trying to get the body’s timeclock to readjust.

So as you get ready to find all the clocks you need to manually adjust (don’t forget the vehicles!), here is some linkage to distract you from that task. Please note I’ve also sprinkled in some networking items as well to keep you on your toes!

  • Wireshark 1.10.3 and 1.8.11 Released - Wireshark website
  • Wireshark - Official site Download
  • Reviewing Wireshark's Capture Pane (by Tony Fortunato) - LoveMyTool blog
  • Using PowerShell to Automate Tracing - MessageAnalyzer blog
  • Nmap cheat sheet - HelpNet Security blog - From the notice:
    • Counter Hack founder and SANS instructor Ed Skoudis and his team created a helpful cheat sheet for Nmap, which includes notable scripts of the Nmap Scripting Engine, script categories, instructions for scan types, probing options, and more.
  • How A Wireless Issue Looks Like a Wired Issue (by Tony Fortunato) - LoveMyTool blog
  • NAFT: The Movie - Didier Stevens
  • New utility to quickly set the DNS servers of your Internet connection - QuickSetDNS utility from Nir Sofer's workbench.
  • On getting Pineappled at Web Directions South - Troy Hunt’s blog
  • Disassembling the privacy implications of LinkedIn Intro - Troy Hunt’s blog
  • Command-line Forensics of hacked PHP.net - NETRESEC Blog
  • iOS apps can be hijacked to show fraudulent content and intercept data - Ars Technica
  • Your iPhone knows where you’ve been, puts it on a map - Chron.com’s TechBlog
  • What's New in the Prefetch for Windows 8?? - Invoke-IR blog
  • Re-Introducing the Vulnerability Search - Journey Into Incident Response blog
  • Links - Windows Incident Response blog
  • Incident Response Teams are the New (Security) Black - Speaking of Security - The RSA Blog and Podcast
  • Red Alert: 10 Computer Security Blogs You Should Follow Today - MakeUseOf blog
  • New Security Intelligence Report, new data, new perspectives - Microsoft Malware Protection Center blog
  • Meet “badBIOS,” the mysterious Mac and PC malware that jumps airgaps - Ars Technica
  • Hacking a Reporter: Writing Malware For Fun and Profit (Part 1 of 3) - SpiderLabs Anterior
  • Treasure Hunting with FTK, EnCase, and SQLite Databases - Computer & Digital Forensics at Champlain blog
  • Add the CAINE ISO to your E2B drive - RMPrepUSB, Easy2Boot and USB booting

Cheers,

Claus Valca

Read More
Posted in boot-cd's, cheat sheets, forensics, iOS, Link Fest, networking, NFAT, PowerShell, security, utilities | No comments

Sunday, October 20, 2013

Forensic News Flashes - New Projects and learning opportunities galore!

Posted on 9:11 PM by Unknown

It’s late and has been a super-long weekend.

Lavie isn’t too impressed I’m still sitting at my desk working on posts.

In the meantime, I’m commited to getting this last bit of ForSec linkage collected over the past few weeks out the door so you can have fun reviewing it this week.

Those young and crazy pups over at the Computer & Digital Forensics at Champlain program have clearly caught their dean napping. In an interesting series of posts, they attempt to wreak havoc on different hard-drives and then try to put humpty-dumpty back together again.

  • Destructed Data Forensics- Part 3
  • Data Destruction Forensics- Part 2
  • Data Destruction Forensics

MantaRay Forensics - anTech Triage & Analysis System. As far as I can tell, this is the first time I have posted any mention of MantaRay Forensics here at GSD.  Spotted in this C&DF@C post Swimming with MantaRay Forensics

MantaRay was designed to automate processing forensic images, directories and individual files with open source tools. With support for numerous image formats, this tool provides a scalable base to utilize open source and custom exploitation tools. MantaRay was developed by two forensic analysts, Doug Koster and Kevin Murphy.

ForGe Forensic test image generator v1.1 - Git Hub project page. from the Overview description:

ForGe is a tool designed to build computer forensic test images. It was done as a MSc project for the University of Westminster. Its main features include:

  • Web browser user interface
  • Rapid batch image creation (only NTFS supported)
  • Possibility to define a scenario including trivial and hidden items on images
  • Variance between images. For example, if ForGe was told to put 10-20 picture files to a directory /holiday and create 10 images, all these images would have random pictures pulled from repository.
  • Variance in timestamps. Each trivial and hidden file can be timestamped to a specific time. Each scenario is given a time variance parameter in weeks. If this is set to 0, every image receives an identical timeline. If nonzero, a random amount of weeks up to the maximum set is added to each file on each image
  • Can modify timestamps to simulate certain disk actions (move, copy, rename, delete)
  • Implements several data hiding methods: Alternate data streams, extension change, file deletion, concatenation of files and file slack space.
  • New data hiding methods can be easily implemented. Adding a new file system is also documented.

Developer Hannu Visti goes shares a great post over the features and background of this tool over at Forensic Focus. ForGe – Computer Forensic Test Image Generator.  This could be a really fresh and innovative tool to help with both simulating forensic images for training and drill purposes. Very interesting and well worth the time to check out. It’s beyond my skill set to review and comment on but if any of the ForSec pros out there have any thoughts or comments, please feel free to drop them in the comments here for our community education.

Linkz 4 Free Infosec and IT Training - Journey Into Incident Response - Corey Harrell goes above and beyond with an outstanding listing of trainings, exercises, and learning resources that are ForSec focused and absolutely-friggin-free for the taking!  Corey promises to keep the listing updated so bookmark the page and check back often. I’m particularly interested in the CSIRT-like topics and materials listed like those in the ENISA CERT linkage. I’ve downloaded most all of the PDF versions already to review this week as time allows!

Many of these trainings have supplemental videos and VM’s for download too!

Other specific courses from Corey’s post I’m listing below so I can find them quickly…

  • Incident management guide - ENISA CERT
  • Tools - ENISA CERT - OMG what a detailed and categorized listing.
  • Certified Information Systems Security Professional (CISSP)® Common Body of Knowledge (CBK)® Review - via Open Security Training
  • Flow Analysis & Network Hunting - via Open Security Training
  • Introduction to Vulnerability Assessment - via Open Security Training
  • Introduction to Network Forensics - via Open Security Training
  • Offensive, Defensive, and Forensic Techniques for Determining Web User Identity - via Open Security Training
  • Utilizing SysInternals Tools for IT Pros course - Microsoft Virtual Academy - Note I think I have already posted this one earlier!

What 'tier 2' & 'tier 3' tools do you load on your forensic workstation(s)? - ForensicKB blog - Lance Mueller has a great list of Tier 2 and Tier 3 apps he considers. I’m pleased to find more than a few in my toolkit already. Note that not all of the software listed here is necessarily free or open-source. More than a few are commercial applications. That’s not at all a bad thing, but just something to be aware of.

 Windows Incident Response: Shell Item Artifacts, Reloaded - Harlan Carvey undertakes some very methodical validation exercises on Windows shell item artifacts. Definitely worth reading.

Meanwhile, from another ForSec guy who appears to never sleep… Brett Shavers has been in a posing frenzy over at his Windows Forensic Environment blog site.

Best publicly available testing of WinFE I’ve seen to date - Windows Forensic Environment (Note post info is good but link in it has been superseded by one found in post below.

Updated link on the Mistype project - Windows Forensic Environment

WinFE - direct link to the article mentioned. I agree, it is a truly fascinating read for WinFE aficionados. I’m coming back to read this one carefully this week.

Mini-WinFE - Windows Forensic Environment - This post has tons and tons of screenshots to illustrate the new Mini-WinFE project as well as an introduction that goes over the project features. Very basically, this specific project (1 of 3 promised for alternative WinFE building) allows you to roll your own WinFE boot disk in a “minimal” configuration with FAU utilities, FTK Imager and support for X-Ways Forensics. Total build time is estimated at 10 minutes from start to media in your hand.

Mini-WinFE is out of beta! - Windows Forensic Environment - See you waited too long! The first link was requesting Beta testers. Now it is released!  Direct project link here via Reboot.pro and extensive Mini-WinFE project documentation from Misty is linked here.

Quick video on building a Mini-WinFE - Windows Forensic Environment - a very short (3:33 min) YouTube video is available on this post page for those who want to check out the building process.

Since we are on a WinFE bender, let’s shift gears slightly and use that excuse to post a link on the WinFE’s kissable cousin for sysadmins who aren’t quite as focused on disk read-only preservation, WinPE.

How to Customize Windows PE Boot Images to Use in Configuration Manager - Chris Nackers Blog. Chris links to this Microsoft TechNet resource How to Customize Windows PE Boot Images to Use in Configuration Manager

New website and project roadmap - DEFT Linux - Computer Forensics live CD - The DEFT development team has put some fresh paint on their website as well as outlined where they plan to head in the coming months. Congratulations to DEFTA President Stefano Fratepietro and all the community and project contributors who have worked hard to make DEFT Linux a premiere Forensic live CD resource! From that post..

Here follows the forthcoming milestones concerning the new versions of DEFT 8, Virtual Appliance and User Manual.

  • DEFT Linux 8.1 with relevant news for Mobile Forensics – November 2013
  • DEFT 8 VMware Virtual Appliance – late November 2013
  • Roadmap of projects supported by donations – December 2013
  • DEFT 8 User Manual – February 2014
  • Third Italian National Conference DEFTCON 2014  – Polytechnic of Milano, April 11, 2014

Installing VMware Tools on Kali Linux and Some Debugging Basics - SpiderLabs Anterior - Christophe De La Fuente goes to the mat to show some advanced debugging skills in getting VMware Tools onto Kali Linux. As is pointed out in the comments, there are easier ways to do it, but the experience shared of the road taken makes us all a bit wiser. Which this post then led me to discover and add to my RSS feed pile…

Computer Howto's by Lewis Encarnacion - Lewis’s posts are great. Covering not just Windows 7 topics, but also some of the finer points in using and getting comfortable in Kali Linux.

FAU -version 1.3.0.2464 - Speaking of the Forensic Acquisition Utilities (FAU) it seems a new version came out in August 2013. I don’t think I caught that release. The link has a “what’s new” jump as well as the new binary set download link but for the lazy…from that source:

  • Volume_dump and DD now recognize drives with BusTypeSata as devices supporting the ATA feature set.  ATA specific attributes are reported for these drives.
  • Fixed a problem with the DD --verify option when writing an image to certain to certain drives.  Under certain circumstances the DD --verify option reported a spurious failure even though the reimaging of the target drive succeeded and the cryptographic checksum of the destination drive was in fact identical to the cryptographic checksum source image file or drive.  This problem did not affect the accuracy of the reimaged drive but required that the user to validate the target drive after the imaging process was complete.  Thanks to Suman Beros for reporting this problem.
  • When acquiring a physical drive DD now drops the block size down to the device block size when approaching the putative end of the source drive.  Hard drives often misreport their capacity either by over estimating or under estimating the true size.  The only reliable way to image a hard drive is to attempt to acquire beyond the purported end of the drive and see if valid data is returned.  However, we have encountered a few drives that freeze or hang the imaging process if you attempt to read beyond the end of the drive with a block size that is greater than the device block size.  Needless to say, this can be disconcerting when you have already read 1 TiB of data only to have the whole process hang on the last few sectors.  Dropping down to the device block size when approaching the end of a drive should produce more reliable acquisitions.  A disadvantage is that drive acquisition will be slower at the end of the drive.
  • Examples have been added to the DD help text which show how to acquire a physical drive.

That’s all for tonight!

Cheers my friends.

Claus Valca

Read More
Posted in boot-cd's, cheat sheets, Education, forensics, Learning, Link Fest, Linux, security, software, tutorials, utilities, Win FE, Win PE | No comments

Sunday, July 28, 2013

ForSec “Value Package” Linkfest - No coupons required!

Posted on 5:00 PM by Unknown

One last Linkfest from a now exhausted GSD blogger this weekend.

Cleaning out the “to-be-blogged” hopper is always rewarding, but I tend to get very behind on the weekend chores. My saving grace this weekend has been frequent scattered showers and an equally tired Lavie who hasn’t been interested in going out for shopping, groceries, or dining out. The kitchen has been cleaned. The laundry has been done for the week.

Next stop, a few hours of rest, post-blogging, then a wind-down with Endeavour on PBS Masterpiece.

Too Funny Not To Miss

Bloody galah scammers still not getting the message - Troy Hunt’s blog. Security guru Troy Hunt has had his fair share of “this is (not) Microsoft cold calling you…your PC is infected…let me remote control it” scams and has picked them all apart to the bone.

This time he takes a new angle…in a way that only an Aussie could pull off!  This is a classic! Troy, please offer us some of those sound files or link to where we can get them!  I need to put together a Texan sound-effect package for similar fun with unwanted callers. Brilliant!

Microsoft Security News

Microsoft Releases New Mitigation Guidance for Active Directory - Microsoft Security Blog

Overview of Microsoft`s "Best Practices for Securing Active Directory" - SANS Computer Forensics and Incident Response blog’s Mike Pilkington does a great summary and takeaway of the new AD mitigation guidance.

Security Awareness Training: Your First Line of Defense (Part 4) - WindowSecurity.com’s Deb Shinder discusses evaluating training effectiveness short and long-term.

See also these previous series posts:

  • Security Awareness Training: Your First Line of Defense (Part 1)
  • Security Awareness Training: Your First Line of Defense (Part 2)
  • Security Awareness Training: Your First Line of Defense (Part 3)

Network Security, News and Techniques

Wireshark 1.8.9 and 1.10.1 Security Update - ISC Diary

  • Wireshark 1.10.1 - Release Notes
  • Wireshark 1.8.9 - Release Notes
  • Wireshark - Downloads

Next up are some great and detailed video presentations from Sharkfest 2013

  • Sharkfest 2013 - Wireshark Network Forensics (by Laura Chappell)
  • Sharkfest 2013 - Trace File Sanitization NG (by Jasper Bongertz)
  • Sharkfest 2013 - Attack Trends and Techniques (by Steve Riley)
  • Sharkfest 2013 - Capture Limit of a Laptop, When does it Drop Packets? (by Chris Greer)

Recent Forensically Focused Posts

  • HowTos - Windows Incident Response blog
  • HowTo: Malware Detection, pt I - Windows Incident Response blog
  • HowTo: Data Exfiltration - Windows Incident Response blog
  • HowTo: Add Intelligence to Analysis Processes - Windows Incident Response blog
  • HowTo: Determine/Detect the use of Anti-Forensics Techniques - Windows Incident Response blog
  • HowTo: Investigate an Online Banking Fraud Incident - Windows Incident Response blog
  • Finding an Injected iframe - Journey Into Incident Response blog
  • MS Excel and BIFF Metadata: Last Opened By - Digital Forensics Stream blog

Physical (In)Security?

Duplicate house keys online - Keys Duplicated - This is either freaking amazing or super-scary. I just can’t decide! According to their Security page, precautions are taken.

The Keys Duplicated Blog - A couple really cool and technical posts on the behind the scenes things that make their keys pretty good.

…as spotted on Lifehacker’s post: Shloosl Copies Your House Keys Using a Smartphone Photograph

When 'Smart Homes' Get Hacked: I Haunted A Complete Stranger's House Via The Internet - Forbes

ForSec LiveCD Distro News

  • More on WinFE and Autopsy - Windows Forensic Environment blog
  • DEFT Linux 8 stable with DART 2 is out! - DEFT Linux - Computer Forensics live cd
  • Kali Linux Summer Update Release 1.0.4 - Kali Linux
  • Pass the Hash toolkit, Winexe - Kali Linux
  • Downloads - Kali Linux

AV/AM Bits

Microsoft Security Essentials quietly released version 4.3.216.0 engine update for their free antivirus scanning program. If you use MSSE, you should get it via the automatic updates…if you have them turned on…you do have them turned on right?

Download Microsoft Security Essentials - Microsoft Download Center - Like most things MSSE, trying to figure out just what got updated is next to impossible so let’s just say for now that this one must be better than the previous version and move on.

I’m still using MSSE around the Valca home on all our home systems. I also continue to recommend it to friends and family (generally everyone non-work-related) who I provide friendly IT support to. I find it is pretty non-threatening to the non-technical users I know and though it loves to alert on many of my security programs (potentially unwanted programs) since they can also be used for 3vil, it seems to do a more than adequate job security the systems.

For my Windows 8 systems, I’m instead relying on Bitdefender Antivirus Free. In some ways it’s a bit different model in that you need to sign up with an email address to set up your account. Then you can download the client to the system. What is nice is that if you manage multiple systems in your home, you can log into your account at their site and then get a console feedback on the status of those systems. That’s something that I do at work with another vendor’s enterprise AV client health/status management console. That’s super cool for a free product. I’m seriously leaning to expanding it’s coverage to my main Windows 7 laptop at home. Performance has been outstanding on my Windows 8 systems.

Kaspersky tops real world protection test - BetaNews - this post does point out that Bitdefender tied Kaspersky with a 99.9 % protection level in AV-Comparatives Independent Tests of Anti-Virus Software for July 2013. While Microsoft Security Essentials rated a 92.5 % protection level. There are some additional disclaimers so read the short BetaNews article carefully. Then head over to AV-Comparatives to dig deeper and see the full findings.

  • AV-Comparatives Real-World Protection Test March-June 2013 - AV-Comparatives
  • AV-Comparatives Real-World Protection Tests - AV-Comparatives

Finally, we wrap up this segment with this interesting discussion:

The evolution of Ronvix: Private TCP/IP stacks - Microsoft Malware Protection Center

It’s a bootkit infection that has its own private TCP/IP stack. By doing so it can be extra stealthy and bypass personal firewall hooks and can lurk unseen in standard tools and utilities (such as nbtstat). Doing so, depending on packet/network monitor off the infected machine may be ineffective. However, it still must talk ON the network, so an independent network monitoring and forensics analysis approach using a network monitoring appliance or span port capture may detect the traffic. This may be why comparing outside network traffic captures from a system on the network to network traffic captured on the system may be a useful exercise for incident response and monitoring purposes.

Legally Focused

I’ve been reading a wider range of subjects, and a small part of those touch on our legal system. Mainly they apply to digital law and crime but some are more general. I’m just tossing them out there for the interested or curious. Generally they tend to analysis of current events or provide a more detailed lawyer’s review than the talking/shouting legal heads we encounter on mass-media “news-like” entertainment outlets these days.

  • CYB3RCRIM3 - Susan Brenner’s blog on cybercrime and cyberconflicts in technology and law.
  • Popehat - group blog with a mostly legal focus (though topics can range far afield!)
  • Le·gal In·sur·rec·tion - group blog with mostly legal and law-in-today’s-culture focus. Pretty vibrant opinions. Alignments may vary.
  • Lowering the Bar - Sometimes lighthearted (though always serious at the core) look at some of the nonsense the legal system contains, or foists on others from time to time. Great site.
  • Massad Ayoob - legal, cultural, and educational postings primarily dealing with legal private firearm ownership issues. Also analysis of public media trends and news stories.

Have a great week!

--Claus Valca

Read More
Posted in Active Directory, anti-virus software, boot-cd's, cheat sheets, firewalls, forensics, humor, Link Fest, malware tools, Microsoft, networking, NFAT, security, troubleshooting, tutorials, utilities, video, viruses, Win FE | No comments

PowerShell Reference Post: The Train Cometh Near…

Posted on 9:30 AM by Unknown

Ever have that experience when you wake up and realize that event, or project, or whatever that you have been working hard at avoiding or denying is “Upon You”?

Very, very soon down in the coal mine, the opportunity to have Windows PowerShell natively installed on all our Windows desktop system will be realized.

I’ve been doing some old-school “BAT” files and even some very light VBS scripts for a while now to help automate some IT sysadmin functions from the CLI to avoid use of EXE based third-party tools and utilities where possible. Sometimes this has proved wildly successful. Other-times, not so much.

What I probably need to do is hunker down and pound my head into the desk and keyboard and learnz me some Ruby or Perl or Python.

However, for whatever reason, those still seem super-overwhelming to try to figure out how to tackle.

Instead (for now), what I think I really need to do is take the big-boy step of getting some basic familiarity and comfort with PowerShell usage under my belt.

Since the base PowerShell should be on all our deploying Windows 7 systems (and upgradable to what, PS 4.0 now?) that would present a great opportunity to extend system and network administration tasks and increase efficiency.  And since I’m fairly comfortable with the Windows BAT file writing/debugging process, this jump may be a bit easier to make.

So anyway, this is just a list of initial PowerShell references I’m dumping so that I can start my learning process.

If my dear readers have any additional recommendations -- books, URL’s, on-line videos, blogs, etc. -- for helping someone get up to speed with learning PowerShell and its support for system and network administration tasks, please drop your tips into the comment jar.

Windows PowerShell - TechNet Script Center Introduction - Windows PowerShell 2.0, Windows PowerShell 3.0, Windows PowerShell 4.0

Getting Started with PowerShell 3.0 | Channel 9 - A nine-part Microsoft video series - “This Jump Start is designed to teach the busy IT Professionals about this powerful management tool. Learn how PowerShell works and how to make PowerShell work for you from the experts Jeffrey Snover, the inventor of PowerShell, together with Jason Helmick, Senior Technologist at Concentrated Technology. IT Professionals, Admins, and Help Desk persons learn how to improve your management capabilities, automate redundant tasks and manage your environment in scale.”

Advanced Tools and Scripting with PowerShell 3.0 - Windows Virtualization Team Blog - Coming August 1st - Free Microsoft Virtual Academy online presentation training event -- “Find out how to turn your real time management and automation scripts into useful reusable tools and cmdlets. You’ll learn the best patterns and practices for building and maintaining tools and you’ll pick up some special tips and tricks along the way.” I expect it will also be up on Channel 9 a week or so later.

PowerShell Script to Manage Java Browser Plug-In and Java Security Level - SANS Windows Security Blog

Download Windows PowerShell Quick Reference - Microsoft Download Center - “Quick-reference guide to commonly-used Windows PowerShell commands.”

Download Windows PowerShell 3.0 Step By Step Guide - Microsoft Download Center - “Microsoft by default has decided to display Windows PowerShell in the Windows 8.1 WinX Power Menu, although you can change it back to Command Prompt, if you wish. But for those of you who’d like to try you hand at learning Windows PowerShell 3.0, you can download these step by step guides released by Microsoft.”

The Windows PowerShell Toolbox - TechNet Script Center - Loads of links and references for using Windows PowerShell

Scripting with Windows PowerShell - TechNet Script Center - Webcast series links and references, scripts, download sources and usage guides.

Discover the Easy Way to Begin Learning Windows PowerShell - Hey, Scripting Guy! Blog

Windows PowerShell Team Blog

Download Windows Management Framework 3.0 - Microsoft Download Center - Contains Windows PowerShell 3.0 among other bits.

Download Windows Management Framework 4.0 Preview - Microsoft Download Center - Not yet ready for production release, this contains the bits for the next generation of Windows PowerShell.  Consider carefully before deployment as some big system incompatibilities haven’t yet been resolved.

Windows PowerShell 4.0 Preview - Rick Barber's Blog. From Rick’s brief summary post…

“You should note that the supported operating systems do not include Windows 8 or anything earlier than Windows 7 SP1.  Sources tell me that PowerShell 4.0 will be included with Windows 8.1 when it is released as well as Windows Server 2012 R2.

“Pay close attention to the link above as the Management Framework 4.0 Preview is not compatible with some Microsoft Server applications including all versions of Exchange server, SharePoint server, and other applications.  You really shouldn’t be installing a preview in a production environment, anyway, but rather using it locally on your workstation or laptop for testing and familiarization.“

PowerGUI.org - Free Windows Powershell Community. When we did a big rollover from Novell to Active Directory, the AD pros who were brought in had PowerGUI prominently displayed on their secondary monitor as they powered through the transitional operations.

PowerShell Pro! - website with tons of on-line tutorials for Windows PowerShell. It doesn’t look like it has been updated for a number of years, but if you are just getting started from the ground up, most of the material here should still be valuable, especially considering the rich illustrations and screen captures that accompany the primary guide texts.

PowerShell Analyzer - (now free) GUI tool to manage PowerShell scripting. Old TechNet Mag review here: Toolbox: New Products for IT Pros

PowerShell.com – PowerShell Scripts, Tips, Forums, and Resources. Community website.

learn windows powershell - YouTube search results on the terms

learn windows powershell - DuckDuckGo search results on the terms.

Cheers!

Claus Valca

Read More
Posted in cheat sheets, Learning, Microsoft, PowerShell, Scripting, software, tutorials, video, Windows 7, Windows 8 | No comments

Thursday, November 22, 2012

Windows 8 Linkage: Call me maybe?

Posted on 2:30 PM by Unknown

So Windows 8 has been out for a short while now.

Some folks are buying it and upgrading. Others are buying new hardware and getting it along for the ride. Others (like me) are still on the fence. Windows 8 is having one of the most successful OS launches yet, or not. Things remain murky all the way ‘round.

Meanwhile Win8 just wants to be everyone’s new friend.

I’m just getting burned out on the same Win8 commercials everywhere I turn the channel.

Below please find collected for my future reference the latest round of Windows 8 information and tippage that I am storing away Spring when I will likely upgrade to Windows 8. Or not.

Win8 - Start Here - Get It

  • Windows 8 upgrade will not create an ISO - Borns IT & Windows Blog

Win8 - Related Betas

  • NEWS: Office Home & Student 2013 RT Preview updated to Release - Kurt Shintaku's Blog

Win8 - Install It

  • Windows 8 Pro Upgrade: Black Screen Troubleshooter - Borns IT & Windows Blog
  • Windows 8 Upgrade-Failure troubleshooting and analysis - Borns IT & Windows Blog
  • No support? No problem! Installing Windows 8 on a Mac with Boot Camp - Ars Technica
  • Windows 8 upgrade: "We are just a few things before" - Borns IT & Windows Blog
  • Windows 8 Upgrade: Step-by-Step - Part 1 - Borns IT & Windows Blog
  • Windows 8 Upgrade: Step-by-Step - Part 2 - Borns IT & Windows Blog
  • Windows 8 Upgrade: Step-by-Step - Part 3 - Borns IT & Windows Blog
  • Windows 8 Upgrade Troubleshooting FAQ - Part 1 - Borns IT & Windows Blog
  • Windows 8 Upgrade Troubleshooting FAQ - Part 2 - Borns IT & Windows Blog
  • Windows 8 Upgrade Troubleshooting FAQ - Part 3 - Borns IT & Windows Blog
  • Windows 8-trap: ESD DVD not EFI bootable - Borns IT & Windows Blog
  • How to create a bootable Windows 8 installation DVD using the ESD folder - Page Start (Note: link recommended by my brother who had a pile of hurt trying to get his systems upgraded from Win 7 to Win 8 last weekend.)

Win8 - Under the Hood

  • Better on the inside: under the hood of Windows 8 - Ars Technica
  • Review: Windows 8 core apps OK for tablets, disappointing on desktops - Ars Technica
  • Surface disk space: a bit better, and a bit worse, than Microsoft says - Ars Technica

Win8 - To Go

  • Windows To Go Startup Options - Anything about IT
  • How To Create A Portable Windows 8 Enterprise To Go Workspace - Addictive Tips
  • Windows To Go workspace bug solved - - Borns IT & Windows Blog

Win8 - Tweaks

  • How To Tweak The Visual Effects In Windows 8 - MakeUseOf Blog
  • Get Your Google Back On Windows 8 With A New Dedicated Website [Updates] - MakeUseOf Blog
  • How To Use Windows 8 Themes in Windows 7 - Windows7hacker
  • How to Fix Windows 8’s Biggest Annoyances (and Make It More Like Windows 7) - Lifehacker
  • How To Allow Multiple Concurrent Users Log In Windows 8 through Remote Desktop - Windows7hacker
  • HOWTO: Extend internal Surface RT storage to the microSD card - Kurt Shintaku's Blog
  • Win8 BTD: [B]oot [T]o [D]esktop - Caschy’s Blog
  • Change Windows 8 Boot Menu To Standard Windows 7 Bootloader - Addictive Tips
  • Windows 8 – Script to automatically show the desktop - Anything about IT
  • Windows 8: boot into the desktop - Caschy’s Blog
  • Here Are Two Useful Registry Hacks To Make Windows 8 Faster - Addictive Tips
  • How To Bring Back Aero Effects In Windows 8 - Addictive Tips
  • Windows 8 Start Screen Personalization With Decor8 - Addictive Tips
  • Windows 8 Start Screen Customizer review - BetaNews
  • Windows 8 Start Screen Customizer v1.3 beta - by ~vhanla on deviantART
  • Windows 8, Step 0 - Turn on continuous backups via File History - Scott Hanselman’s ComputerZen
  • Windows 8: Enable Flash On Any Website In Internet Explorer 10 - Addictive Tips
  • Make A Fancy Tile on Windows 8 Start Screen - Windows7hacker
  • Silence Windows 8 notifications temporarily - Ed Bott
  • How To Add 'All Apps' Shortcut To Windows 8 Desktop & Taskbar - Addictive Tips
  • Customize Windows 8 Start Screen - Caschy’s Blog
  • Give Your Windows 8 Desktop A Makeover With Rainmeter & RocketDock - Addictive Tips
  • How To Disable "Drag To Close" For Modern Apps In Windows 8 - Addictive Tips
  • The Always Updated Windows 8 Tweaking Tool List - Windows7hacker

Win8 - Deeper Insights

  • Windows 8 provides 0x8024001E error - Borns IT & Windows Blog
  • Windows 8: Store will not work - Borns IT & Windows Blog
  • Windows 8: App Update Error 0x80073cf0 - Borns IT & Windows Blog
  • Windows 8 Freezes when WeTab and other computers - Borns IT & Windows Blog
  • Windows 8 Freeze the WeTab analysis Part 2 - Borns IT & Windows Blog
  • Where is the Startup Folder in Windows 8 and How To Easily Access to it? - Windows7hacker
  • INFO: “I have an Windows 8/RT app that just disappears/crashes & drops me into the desktop or a blue background. Dude, WTF?” - Kurt Shintaku's Blog
  • Windows 8: Force boot menu at startup settings BCD Injection - Borns IT & Windows Blog
  • INFO: Windows 8 Modern apps failing to “start up”? One possible solution: Your Graphics Driver - Kurt Shintaku's Blog

Metro Apps That Caught My Eye

  • BoxCryptor App released for Windows 8 - Caschy’s Blog
  • Toolbox For Windows 8: Use Multiple Tools At Once In Adjustable Grids - Addictive Tips
  • 8 Zip is A File Compressing Tool for Windows 8 and RT - Windows7hacker
  • Watch High Definition Videos On Windows 8 With The Official Vimeo App - Addictive Tips
  • Browse The deviantART Gallery In Windows 8 With PicTRO - Addictive Tips
  • Best Windows 8 apps this week - BetaNews
  • Run Modern UI Apps Within Windows 8 Desktop With RetroUI Pro - Addictive Tips

Win8 - Usage Tips

  • Little Details: Windows 8 passwords - Next at Microsoft - TechNet Blog
  • Desktop on Windows RT makes sense - BetaNews
  • Music and Video in Windows 8: a work in progress - Ars Technica
  • DOWNLOAD: Windows 8 keyboard shortcut Quick Reference sheet - Kurt Shintaku's Blog
  • DOWNLOAD: Windows 8 Quick Reference Card - Kurt Shintaku's Blog
  • RELEASE: Windows Phone app for Windows 8/RT - Kurt Shintaku's Blog
  • Windows 8 primer: how to navigate Microsoft's new operating system - The Verge
  • Download Windows 8 For Dummies - Free eBook from Dell
  • Going to work with Windows 8 Enterprise - Ars Technica
  • Windows 8 Modern User Interface tips - 4sysops
  • Windows 8 basics: Tips, tricks, and cures - Ars Technica
  • How To Directly Search Settings and Files from Windows 8 Start Menu - Windows7hacker
  • Move Mouse Cursor Past Windows 8 Hot Corners In Multiple Monitor Setup - Addictive Tips
  • How To Configure And Use Multiple Monitors In Windows 8 - Addictive Tips
  • How to Use Windows 8's New File History Backup (aka Time Machine for Windows) - Lifehacker

Win8 - Miscellanea & Rumors

  • Windows 8 — Disappointing Usability for Both Novice & Power Users - Jakob Nielsen's Alertbox
  • Jumping Blind Into My “Windows RT” Surface - Bits from Bill
  • Microsoft's Big Hidden Windows 8 Feature: Built-In Advertising - HotHardware
  • Windows 8, the post-PC world, and Linux: Microsoft will prevail - Ars Technica
  • ReadWrite – Why Windows 8 PCs Look So Darn Different - ReadWrite
  • Windows 8: Does not so great ... - Borns IT & Windows Blog
  • Microsoft Surface Review: The Best… Something - ReadWrite

Windows 8 - GSD Previously Posted

  • Windows 8 Linkage: “Majestic Metro” version
  • Windows 8 Linkage: “Passage Public Metro” version
  • Windows 8 Linkage: “Metro Santiago” edition
  • Windows 8 Linkage: “Metro at Nightfall” edition
  • Windows 8 Linkage: Product Name “Something or Another”
  • Windows 8 Linkage: In Which a Name is Chosen
  • Windows 8 Linkage: A Bit Behind the Ball
  • Windows 8 - “It’s here” edition

Cheers

--Claus V.

Read More
Posted in Active Directory, cheat sheets, Internet Explorer, Link Fest, Microsoft, troubleshooting, utilities, Windows 8 | No comments

Friday, October 19, 2012

Pile ‘o Linkage

Posted on 1:53 PM by Unknown

Chain links _ Flickr - Photo Sharing!_2012-08-25_17-32-04CC attribution: "Chain links" by HowardLake on flickr.

Time to unload them…

Forensics

  • Windows 8 Forensics - A First Look - YouTube video from ForensicFocus presented by Josh Brunty. appx 40 min.
  • Digital Forensics Stream: VSC Toolset - GUI tool for executing batch files against a volume shadow copy. More details on the latest version in this VSC Toolset Update: File Recovery blog post.
  • Windows Incident Response: Forensic Scanner - Windows Incident Response blog - Harlan has recently released a super assessment tool to get a fast big-picture view report of a system being examined. It is very simple to use and provides great data for figuring out if there are any important indicators to spend more time in a closer examination of the system. Download available at forensicscanner - ASI Forensic Scanner via Google Project Hosting
  • Network Artifacts found in the Registry - Windows Incident Response blog - This is a RegRipper focused post but the previously mentioned Forensic Scanner also provides some network information; the WiFi info is quite useful on laptops to see where they have been traveling and connecting to.
  • From Malware Analysis to Portable Clam AV - Journey Into Incident Response - Corey Harrell has a fun post read on identifying a malware binary and then creating a custom AV signature in ClamAV.
  • New Archive of RegRipper Plugins - RegRipper has a new collection of current/updated plugins available if you haven’t snagged them recently.
  • Live forensics: prefetch and powershell - 8 bits blog - using PowerShell in incident response.
  • CAINE Live CD - computer forensics digital forensics - Release version 3.0 “QUASAR” is out with some updates and application additions.

Adobe Reader XI (11)

  • Announcing Adobe Reader XI - New version of Adobe Reader is out…just when you were probably getting your apps finally coded to interact with Adobe X (10).
  • Adobe Reader XI Deployment - Stealthpuppy’s Aaron Parker has some excellent as always tips on deploying it; including some customizations.
  • How to configure Group Policy for Adobe Reader XI - Group Policy Central - Not to be outdone by Aaron, Alan Burchill also has some tips for using it with GP.

Network Bits

  • Meet the successor to Microsoft Network Monitor! - MessageAnalyzer - TechNet Blogs. The successor to Microsoft’s NetMon packet trace tool is out in beta. I believe it is only supported on Win7/8. I’ve played with it a bit and NetMon users should quickly feed comfortable in it, although the GUI is significantly different in many ways. Testing captures on a Win8 RC virtual machine have gone pretty well. I’ve had a few crashes so more work does need to be done before final release in mid-2013. Definitely worth checking out though not likely to replace Wireshark or your other favorite network packet capture tools quite yet.
  • New Release: Cisco Discovery for Windows v1.3 -What the.....? blog. - I’ve posted before of various ways you can trace down what switch port is connected to, all usually multi-stepped. If you have a Cisco based switched network, this new-to-me tool in a single executable might save a whole lot of frustration if kept handy on a USB stick.  Run it, pick your interface, get your CDP data…switch/port will be magically revealed. Sweet! Get the WinCDP tool here.
  • WinsockServicesView - NirSoft - is a New utility to view, disable, and enable the installed Winsock service providers. Nir does it again with a super easy-to-use and helpful tool to catalog Winsock service providers on a system.
  • Install NetworkMiner with apt-get - NETRESEC Blog. Yeah. It’s now that easy. Not like before in a previous GSD post: Network Miner Updating on Ubuntu 12.04
  • Wireshark Tutorial Series. Tips and tricks used by insiders and veterans - Sniff free or die blog details a new Hands on with Wireshark YouTube video (11 min) by RiverbedTechnology that covers some basic usage tips.

For the SysAdmins

  • How to find latest Microsoft Knowledge Base articles for Windows 8 and Server 2012 - Anything about IT
  • FREE: Group Policy Search – Find Group Policy settings - 4sysops - Via this MSDN site: Group Policy Search
  • DOWNLOAD: Group Policy Settings Reference for Windows (8) and Windows Server (2012) - Kurt Shintaku's Blog - See also: Group Policy Settings Reference Spreadsheet - Group Policy Team Blog
  • Crash Course in Active Directory Organizational Unit Design - Windows Networking site.
  • Case of the Domain Join Failure followed by Case of the Domain Join Failure II–Object Already Exists - chentiangemalc
  • Enterprise Wireless Security – An overview - 4sysops
  • Get Files Out of a Running Virtual Machine - Ben Armstrong Virtual PC Guy Blog
  • How to diagnose Windows sleep problems - Tenniswood Blog
  • 7 Cool Useful Command Prompt Tips You May Not Know - Windows7hacker
  • Beyond good ol’ Run key, Part 2 - Hexacorn blog
  • Windows PowerShell 3.0 download - Bink.nu summary of the new features in PS 3.0
  • Download: WMF 3.0 - Microsoft Download Center
  • PowerShell 3.0 - 4sysops - Krishna Kumar offers a overview of some of those newest features.
  • PowerShell 3.0 overview – Part 2 - 4sysops - the review continues….

Utilities

  • Updates: Autoruns v11.34, ProcDump v5.0, Sigcheck v1.8, VMMap v3.11 - Sysinternals Site blog
  • Process Explorer v15.23 - Sysinternals
  • PsPing - Sysinternals new CLI tool to measure network performance including bandwidth available between systems. Also can generate histograms of results.
  • Rapid Environment Editor - Most folks won’t have any need to ever edit their Windows environment variables. But if you are a tweaker or geek or sysadmin, you might need to. This looks to be the tool for you! in addition it provides Error checking to highlight any problems with the entries. I had two “abandoned” items in my system I cleaned up with it. Really a nice portable tool to keep handy.
  • MetroTextual 1.1 - SingularLabs - Minor update to a Win8’ish style notepad tool. I posted quite a bit about it earlier MetroTextual - Spirit of the notepad known as Bend...  This new version has some fixes and feature enhancements. However I noticed on my Win7 x64 system that while v1.0 seemed OK, version 1.1 garbles selected text. I like the newest feature adds but it remains a work in progress…which raises the same question Scott Hanselman of ComputerZen pondered: A Bug Report is a Gift.  What is the best way to report it to the developers…from within the app?

    before text selection…
    z2q0i14a.klx

    after text selection…
    ajp20ovk.jktCurious…
  • HexDive 0.5 – Adding a bit of a context… & HexDive 0.6 – new strings and more -Context… - Hexacorn continues to make great leaps of improvement in the free and super-useful HexDive tool to look for interesting string patterns in files. Check it out!
  • PeStudio 4.10 - Winitor - Speaking of binary analysis, PeStudio is a new-to-me tool to aid in application binary analysis. Cool!

New “Defrag” Tools Videos (and others also)

Microsoft/Sysinternals and their Channel9 team have really scored a home-run with their “Defrag Tools” video series. Each week (or sooner) a new quality video comes out..with clear file download links/formats…that reviews or expands an in-depth review of Sysinternals tools and usage.  I’ve already posted links for Episodes 1-6 and now we have 7-12 out.  I download these at home and tuck them away for replay on rainy days or presidential debates. Even when I consider myself very comfortable using a particular Sysinternals utility, walkthroughs such as these always leave me with a new tip/trick/configuration tweak that I didn’t have before.

  • Defrag Tools: #7 - VMMap
  • Defrag Tools: #8 - Mark Russinovich
  • Defrag Tools: #9 - ProcDump
  • Defrag Tools: #10 - ProcDump - Triggers
  • Defrag Tools: #11 - ProcDump - Windows 8 & Process Monitor
  • Defrag Tools: #12 - TaskMgr and ResMon

A great supplemental Channel 9 is The Defrag Show

See also this WEBCAST: Maximizing Windows 7 Performance: Troubleshooting Tips (1hr 1min) as found by Kurt Shintaku and add it to your video bag as well.

Google Fonts

Font geek? Me too!

I frequently hit the following sites looking for new and impactful free-use fonts for maximum impact on presentations and documents where having just the right font can add a punch of enhancement.

  • 1001 Free Fonts
  • Font Squirrel
  • dafont.com
  • Font Freak

So I got really excited when I found that Google has a web font collection (500+) under the Open Font License.

  • Google Web Fonts - Google
  • Google Fonts directory - Google
  • Download and Install Google Fonts on your Computer - Digital Inspiration
  • Download Reference Posters for Google Web Fonts- Digital Inspiration

Now this is really cool!.

Cheers!

--Claus V.

Read More
Posted in Active Directory, boot-cd's, cheat sheets, forensics, Google, graphics, Link Fest, malware tools, Microsoft, networking, NFAT, utilities, video, Windows 7, Windows 8 | No comments

Sunday, July 1, 2012

Material Roundup: Linkfest

Posted on 6:00 PM by Unknown

Been a semi-relaxing weekend.

Read with interest this TaoSecurity blog post Bejtlich's Thoughts on "Why Our Best Officers Are Leaving" as well as this one Whither United States Air Force Academy? both by Richard Bejtlich. I also noted that the USAFA was evacuated this week as cadets were heading in due to the area fires. These things still catch my attention as I had started the process to become a USAFA candidate my senior year of high-school before removing myself from the process for family reasons (my choice…no excuses). Still, I will always wonder about the path not taken.

Also, while IANAL, I was left scratching my head and heartbroken just a bit by the recent SCOTUS decision. The USNI blog had a post that resonated with my own feelings: The U.S. Supreme Court just diminished the significances of Military Valor [opinion].

Little bro was in town so he brought some pizza’s over, I grabbed some super-good local micro-brewed root beers and we had a party catching up, comparing life notes, and watching Act of Valor on this pre-July 4th weekend.

I wrapped things up yesterday with a viewing of Cave of Forgotten Dreams (Wikipedia) which covers the Chauvet Cave (Wikipedia). Very interesting and well filmed documentary. The cave-art is really fascinating…I just wish we could have learned more about the people behind it.

I guess if there was a theme it was reflecting on the importance of what remains of us, of our efforts, of the world around us.

Back to the shallows…

Sometimes I feel a bit guilty just dumping a super-post like this that is heavy-laden with linkage.

Some weeks are busier than others, however, and while I have more than a few posts still pending in the hopper that are deeper collections of “how-to”, personal reviews, or troubleshooting sessions, I hope that some find value in these “linkfests”.  Primarily they serve to help me quickly search and find material, tools, and techniques that I believe will either be useful, or are useful, when I am away from my desk and my USB dongle is at home rather than in hand. It’s challenging finding that right software or tip and maybe something here will be useful to others or pique their interest and send them in the right direction.

Security Bits

  • Adobe updates Flash Player 11.3 to fix Firefox crashing problem - The H Security - Adobe issued a new Flash (non-IE only) version 11.3.300.262 to address some issues in Firefox 13. Get your update.
  • Analysis of drive-by attack sample set  - ISC Diary - I always value posts like these that teach and show how “drive-by” vectors work. I’ve cleaned more than a few systems that fell victim to a drive-by because Java/Flash/OS/etc. wasn’t correctly patched.
  • Firefox thumbnails could expose private data; fix 'coming soon' - ZDNet. I hadn’t thought of it as an issue since I am use to Chrome doing the same thing, but the thumbnails are larger in Firefox and I could make out some detail to the webmail pages I saw as compared to how they render in Chrome.
  • Stop Firefox 13 Speed Dial Thumbnails From Showing Secure Content - AddictiveTips
  • How to turn off Firefox’s New Tab Page Completely - ghacks.net blog.
  • Our password hashing has no clothes - Troy Hunt’s Blog - Troy lays out an excellent (developer level) case for the new challenges of password hashing and salting. This was excellent reading and I really took a lot out of it in terms of password security in general.
  • John the Ripper password cracker - speaking of which Jon the Ripper “jumbo” edition just got released at version 1.7.9-jumbo-6 for Unit. WIndows binaries seem to be at 1.7.9-jumbo-5. Announcement here.
  • oxid.it - Cain & Abel - seems worth mentioning…
  • Free Computer Security - Personal Software Inspector (PSI) - Secunia. New Version 3.0 released with even more awesomeness!
  • Third edition of vulnerability spotter Secunia PSI - The H Security. More breakdowns.
  • Secunia PSI 3.0 released - HelpNet Security - more details here regarding this release version.
  • Free Online Computer Scan - Online Software Inspector (OSI) - Secunia. If the “installed” client isn’t your thing, the on-line scan is still super awesome and helpful.
  • Qualys BrowserCheck - Related - don’t browse the web in your browser without checking it for patch and plugin update availability!
  • Detect & Remove Fake Antivirus Scams From Your Windows PC - AddictiveTips post for a new MicroTrend tool to help with fake-av infection removal. See below.
  • Removing Fake Antivirus (FakeAV) - TrendMicro. Comes in both CLI and GUI downloads.
  • Remove 50 Known Fake Antivirus Software From Windows - AddictiveTips related post on another fake-av removal tool
  • Remove Fake Antivirus 1.86 - download tool as offered by free of virus & comptuer tips blog.
  • Security Center reports Virus Protection is On - ever handy tip from TinyApps blog.

For Sec News

  • Registry Decoder 1.3 released! - Digital Forensics Solutions. Bug fixes and some new plugins.
  • More good stuff - RegRipper - new plugins from Elizabeth Schweinsberg coming soon.
  • SANS Digital Forensics and Incident Response Poster Released - Handy! SANS
  • Training, and Learning - Windows Incident Response blog
  • When was a file accessed? - Windows Incident Response blog (How many times does this question get asked?)
  • Investigator's Tool-kit: Timeline - ISC Diary. Quite detailed overview and issues post
  • Win7 HomeGroup Reg Particulars - Forensic Artifacts
  • WinFE “Lite” - Windows Forensic Environment
  • Build questions -Windows Forensic Environment
  • HexDive 0.2 - Hexacorn Blog

Network Resources

  • Wireshark 1.8.0 can capture from multiple interfaces at once - The H Security
  • Wireshark · Wireshark 1.8.0 Release Notes - new Wireshark release in the waters…if you didn’t figure it out.
  • Wireshark · Download links
  • SoftPerfect Network Scanner - freeware - release 5.4.4 now out. Changelog Comes in both x32 and x64 flavors. My favorite stand-alone IP scanner (out of more than many I carry).
  • Chatter on the Wire: OS Fingerprinting - Satori was recently updated and now supports many more network fingerprints.
  • http://kitty.9bis.com - Never heard of KiTTY before but it is a fork of .62 PuTTY telnet client with some extra features.
  • New: KiTTY Portable 0.62.1.2 (telnet and SSH with added features) Released - PortableApps.com has a portable version.
  • PuTTY: a free telnet/ssh client - For the purists.
  • Announcing TightVNC Version 2.5.2 -TightVNC - New version just released. Love this app.
  • TightVNC: VNC-Compatible Free Remote Control / Remote Desktop Software - Download TightVNC here.
  • Announcing TightVNC Java Viewer - Yeah, the Java version rocks the beans as well. Super easy to use, compatible with standard VNC, TightVNC, UltraVNC, x11vnc, Apple Remote Desktop in Mac OS X, Xen/HVM, VMWare, Qemu etc. The link/page says 2.1 but there is a download link present for TightVNC Java Viewer version 2.5.2 so be sure you grab the latest version!

Tools and Utilities of Note

  • Updates: Autoruns v11.32, Process Explorer v15.21, Process Monitor v3.02 - Sysinternals. Stop, Drop, and Download now; the holy trinity of software tools just got updated again!
  • Monitor Any Folder Or Disk Drive For Changes In Real-Time, Even Across Networks - AddictiveTips blog post review of new NirSoft tool.
  • FolderChangesView - Monitor folder/drive changes - NirSoft
  • ExtremeCopy: Probably The Fastest File/Folder Move & Copy Utility - AddictiveTips blog review.
  • ExtremeCopy - Easersoft. I’m a dedicated TeraCopy fan but this one sounds intriguing. Will need to put it through the paces soon.
  • Remove Items from the Windows Explorer and IE Context Menus - CyberNet News.
  • MenuMaid - SD Software - software utility link
  • 4 Better Windows Console Tools Alternatives to Windows Built In Command Prompt -Windows7hacker - Kent has a really nice roundup. While the good-ole cmd.exe will do the job, I must say these “replacements” are quite nice. I’ve used “Console2” quite a bit and like the tab format and transparency/font/color tweaking options. PowerCMD surprised me with its feature set and I really can see myself using it more regularly. Check out the others as well.
  • GetFoldersize - Michael Thummerer Software Design - Super nice freeware tool to locate and understand just what is taking up space on your hard-drive. Was recently updated to version 2.5.10. I really like this tool.
  • SizeOnDisk Folder Size - new to me freeware tool found on CodePlex.  Another nice tool to find file/folder size hogs.
  • Folder Size - another freeware file/folder size tool.
  • SpaceSniffer - Uderzo Software - freeware tool that is amazingly fast and amazingly fun to use. While the previously mentioned tools excel at a tabular report, this one provides a super easy visual layout presentation of your space usage. You can drill down very easily. It gives you a easy-to-grasp picture on what is using up your hard-drive space..
  • SequoiaView - I keep this one around just because it is so beautiful. It does a great job even though it hasn’t been updated in quite a long time. It may have been one of the first to present space on disk usage in a “squarified” treemap format.
  • FolderSize - tiny little app (174 kb) from developer Jan Horn that is standalone and gives you a basic what-you-need-to-know report on drive/folder space usage.
  • DirectorySlicer - With giant (and cheap) USB sticks and network connections aplenty, splitting files and folders to specific sizes is become a rarified task. That said this CodePlex project is worth snagging in that it splits files of a folder into partitions of a specified size. So that super-folder you are trying to burn to CD doesn’t fit? Directory Slicer takes the work out of guessing by allowing you to set the size (or use a preset) then it divvies it up accordingly! Clever.
  • Unlock & Delete Empty Folders via Wildcard-Based Rules - AddictiveTips post review of…
  • Empty Folder Cleaner - 4dots Software
  • Reminded me of a previously GSD mentioned Empty Folder Nuker by Simon Wai.


For the Admins: Mostly from Microsoft

  • Rights Protected Folder Explorer 1.0 - Bink.nu blog. “Rights Protected Folder Explorer is a Windows based application that allows you to work with Rights Protected Folders. A Rights Protected Folder is similar to a file folder in that it contains files and folders. However, a Rights Protected Folder controls access to the files that it contains, no matter where the Rights Protected Folder is located.” Also Download Rights Protected Folder Explorer from Microsoft info from TheWindowsClub blog. Get it here Download: RPF Explorer - Microsoft Download Center(Download Details).
  • The Group Policy Setting “Verbose vs normal status messages” has a new name in Windows 8 - Anything about IT  blog
  • Comprehensive Linux course - TinyApps bloggist shares an amazing resource find for us Linux wannabe-better’s offered by Paul Cobbaut. Although it is claims to be Linux basics, it covers a wide range of topics and material.  This is a great find! Check back to the site often as the material is getting frequent updates.
  • Microsoft Outlook Configuration Analyzer Tool 2.0 - Bink.nu blog - “The Outlook Configuration Analyzer Tool 2.0 provides a detailed report of your current Outlook profile and mailbox. This report includes many parameters about your profile, and it highlights any known problems that are found in your profile or mailbox. For any problems that are listed in the report, you are provided a link to a Microsoft Knowledge Base (KB) article that describes a possible fix for the problem.” Go get the Download OCAT_Setup.zip over at the Microsoft Download Center’s Download Details page
  • FREE: Service Credential Manager – Search Windows services - 4sysops post on a new tool Service Credential Manager to help check all scheduled services and tasks based on a specific user account across your domain. Nice! In free/$ flavors.
  • FREE: ADREPLSTATUS – Active Directory Replication Status Tool - 4sysops blog post on a new Microsoft tool with a snazzy GUI to check for AD replication issues. Has export ability for reporting. Download: ADREPLSTATUS at the Microsoft Download Center (Download Details).

Cheers and happy pre-July 4th State-side well wishes to all.

Claus V.

Read More
Posted in Active Directory, anti-virus software, boot-cd's, cheat sheets, command-line interface, forensics, Link Fest, Linux, malware tools, Microsoft, networking, NFAT, security, utilities, viruses, Win FE | No comments

Saturday, March 10, 2012

Incident Response Toolsets and Checklists

Posted on 11:56 AM by Unknown

A few months ago I was reading this Digital Forensics Case Leads: ReFS, Ex01, and DFIROnline post and came across the following bit under the Tools section:

Michael Ahrendt recently released an interesting looking "Automated Triage Utility," written in the AutoIT scripting language. It is a GUI-driven data collection utility designed for live system response. In this regard, it reminds me a lot of Monty McDougal's Windows Forensic Toolchest. They differ in UI and programming language, but aim at the same objective.

I hopped over to take a look at Michael’s Automated Triage Utility and it is pretty cool. You do have some "light” building work to do to seed the structure Michael provides with some extra applications but in total it provides a responder a great set of information logs and evidence collection.

While one-click incident assessments are no substitute to a detailed and focused analysis and pick-apart, these toolsets and first-responses may be of significant benefit getting some assessment data to determine scope of impact and breadth incident. With the core data collected an analyst or response team can then plan out additional responses.

Of course, use of these tools on a live system may have an impact of their own on that system. If possible it might be best to first try to capture both system and memory images if possible to preserve volatile system state information. That said, if the threat is significant enough and risk of critical data loss high, then it might be wise to isolate the system from the network immediately if your response protocol allows. Detailed documentation of response actions and tools run will also help in the post-mortem.

Here are some other related tools and resources that came to my mind after looking at the Automated Triage Utility Toolset.

RegRipper - Harlan Carvey’s Perl-based toolset for picking apart critical registry locations and data for a forensic response. Addition of additional community-based scripts extends the features wonderfully.

RegExtract - Mark Woan’s own take of RegRipper that uses a Windows binary with other 70 plugins to assess system information.

BinPack -Godai Group - a portable application storehouse with over 100 security tools for security assessment and pen-testing.

MIR-ROR - CodePlex project from Russ McRee and Troy Larson. MIR-ROR = Motile Incident Response - Responde Objectively, Remediate. Customized CLI script that uses Windows Sysinternals tools and others to do live-system captures. More info here at HolisticInfoSec’s Toolsmith: (PDF) June 2009 - MIR-ROR: Motile Incident Response - Respond Objectively, Remediate.

Confessor - CodePlex project built from the concepts of MIR-ROR. This allows remote intel gathering on a host of systems in an AD environment. Pretty cool stuff. More info here at HolisticInfoSec’s Toolsmith: (PDF) November 2010- Confessor & MOLE

Registry Decoder Digital Forensics Software - registrydecoder & regdecoderlive - Automated, live acquisition of registry files - via Google Project Hosting. Some of the previous tools listed work on Windows Registry hives that have already been collected. This one is a bit different in that it can be used against live registry files as well as historical ones. More info here at HolisticInfoSec’s Toolsmith: (PDF) December 2011 - Registry Decoder

MANDIANT: Intelligent Information Security has an outstanding collection of free software for incident response and malware analysis. In particular, their Redline utility does some super-awesome host triaging work. See also: IOC Finder

Security Database IT Watching - Evidence Collector - Not supported from some time, but still a very clever and useful “command and control center” tool that leverages other applications in collecting information from systems being assessed.

OSForensics - PassMark Software’s tool can be used to build a portable version to do extensive system information and analysis.

ESET Sysinspector - Neat tool to collect details on a running system, then perform heuristic analysis for risk level labeling of captured components. Makes it easy to begin a top-down assessment of a system.

Nigilant32 - Agile Risk Management LLC. Tiny tool to create a report snapshot of critical live-system processes, services, accounts, tasks, ports, and so on, as well as file-system review tool and active memory imaging support.

rapier - First Responders Info Gathering Tool - Google Project Hosting - RAPIER stands for Rapid Assessment & Potential Incident Examination Report tool. It doesn’t appear to be active since early 2008 but there may be some good material left in this tool. Check the “Downloads” page for some additional PDF and presentation material regarding the toolset. Based on the Intel (R) RPIER project. Added to post list 04-21-12

Response Checklists

Of course, just because you got some tools in your box doesn’t mean that you should just run rough-shod onto a system that is the target of some evilness. Hopefully you and/or your organization has a well-documented incident response framework already in place to guide and shape your response activities in a meaningful and effective way.

Here is a collection of some good ones you may want to consider.

Information and Security Cheat Sheet and Checklist References - Lenny Zeltser. Serious collection of cheat sheets and checklists for IT security response pros. Look carefully at the bottom of the page as Lenny offers some additional cheat sheets form others as well.

KnowYourEnemy.eu - Checklists galore!

Incident Response Checklist (PDF) - via Digi4nsic.com

Procedure for Windows Incident Response (PDF) - via Digi4nsic.com

Request for Forensic Examination (PDF) - via Digi4nsic.com

Computer Security Incident Handling Guide (PDF) - NIST

An Incident Handling Process for Small and Medium Businesses - SANS Institute. Page 39 in particular has a good “Checklist for incident response capability”

Malware Detection Checklist - GoogleDocs - Instrument developed by Harlan Carvey and posted in this DFIROnline: Detecting Malware in an Acquired Image in Windows Incident Response blog post.

His work was expanded a bit in these posts:

  • Linkz 4 Exploits to Malware - Journey Into Incident Response
  • Malware Detection Checklist - Sketchymoose’s blog

Cheat Sheets - Packet Life - For the network incident response crew.

More resources:

Simple Malware Research Tools - ISC Diary. Some fresh tools from the SANS gang.

Can we believe our eyes? Another story - Microsoft Malware Protection Center

Malware Analysis Blog - Great new blog (to me) covering malware review and study.

PXE Boot Server in a Malware Lab - Malware Analysis Blog

Using Free Windows XP Mode as a VMWare Virtual Machine - Lenny Zeltser on Information Security blog

US-CERT: United States Computer Emergency Readiness Team - 2011 GFIRST 2011 Conference papers and materials. So much goodness!

  • Infected! Using the Oregon SIRT Malware Toolkit to Safely Determine Source, Vector, and Duration of a Malware Infection (PDF) - John Ritchie, Senior Security Analyst, State of Oregon Enterprise, Security Office
  • Cyber Incident Management: A Process-Driven Approach with an Integrated, Train-in-Place, Cyber Drill and Exercise Capability (PDF) - Christopher Fogle, Partner, Delta Risk LLC & Brian Zaas, Director, Enterprise Solutions, Avineon, Inc.
  • Sniper Forensics: One Shot, One Kill (PDF) - Christopher E. Pogue, Senior Security Analyst, Trustwave

Cheers!

--Claus V.

Read More
Posted in cheat sheets, forensics, Link Fest, malware tools, security, utilities | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile