New release of minusone (v0.4.0) with a lot of new deobfuscation pattern : github.com/airbus-cert/...
🚨Online version : minusone.skyblue.team 🚨
#powershell #deobfuscation
Kerberos plugin for @volatilityfoundation.org allows you to list and extract tickets from memory dump. Another way to track user activity by checking services tickets !
github.com/airbus-cert/...
github.com
Volatility plugin to deal with windows kerberos security provider, list, carve and dump Tickets - airbus-cert/volatility-kerberos