Kerberos plugin for @volatilityfoundation.org allows you to list and extract tickets from memory dump. Another way to track user activity by checking services tickets !
github.com/airbus-cert/...
We just released an $I30 INDX carver written in Rust! 🦀 🚀
github.com/airbus-cert/...
🐝 New blog post at skyblue.team/posts/unsafe...
At Airbus CERT, we worked on the sudo CVE-2025-32463 to create detection and hunting rules.
Based on the underlying vulnerability, we developed an eBPF based tool to monitor unsafe chroot behavior regarding NSS reloading.
github.com/airbus-cert/...
Bye Omnivore 😭
blog.omnivore.app/p/details-on...
Volatility plugin to deal with windows kerberos security provider, list, carve and dump Tickets - airbus-cert/volatility-kerberos