Category Archives: Forensics

Anti-Forensics: Leveraging OS and File System Artifacts

Hola, I know it seems that the zone has been abandoned for a year, and that is why I didn’t want the year to end without posting anything. Anyway, this presentation has been covered in Feb-2016, and thought why not … Continue reading

Posted in DFIR, Forensics | Comments Off on Anti-Forensics: Leveraging OS and File System Artifacts

Digital Forensic Challenge #4

The Case: A company’s web server has been breached through their website. Our team arrived just in time to take a forensic image of the running system and its memory for further analysis. The files can be found below: 1- … Continue reading

Posted in Academia, Challenges, Forensics, z0ne | Tagged , , , | 2 Comments

Forensic Analysis: Creating User GUI vs CLI

Hello, This is my first forensic analysis post in English; as I’m sure you noticed by now that all of it is in Arabic; so excuse me for my bad English :) The whole idea came out when @azeemnow asked … Continue reading

Posted in Forensics, Windows | Tagged , , , , , | Comments Off on Forensic Analysis: Creating User GUI vs CLI

Network Forensics Challenge 1

كالعادة، الغياب عن هذا المكان أصبح شيء روتيني :) على كل حال … قمنا بوضع تحدي على موقع مجتمع الحماية العربي يمكنكم الوصول له من هنا … الى هذه اللحظة لم يقم بحل التحدي سوى شخصين، أحداهم هي طالبتي والثاني … Continue reading

Posted in Academia, Forensics, Networks | Tagged , , , | Comments Off on Network Forensics Challenge 1

Disable Automount for SIFT

مشكلة بسيطة في إستعمال SANS Investigation Forensic Toolkit أو ما يسمى SIFT تكمن في عمل ربط mount للأجهزة الخارجية مثل USB بشكل تلقائي وهذا أمر سيء في مجال الـ Digital Forensics ولهذا لحل هذه المشكلة، كل ما عليك فعله هو: … Continue reading

Posted in Forensics, GNU/Linux | Tagged , , , , , , , , , , , | Comments Off on Disable Automount for SIFT