Workshop: An Introduction to macOS Forensics with Open Source Software
Common Information
Type | Value |
---|---|
UUID | 057e0fa9-5c7c-495e-a0b0-75b6965a9586 |
Fingerprint | 59d5d3af75cb12bc7823347a6dabd84349ab0f49c65d4b76a3652e667d08d893 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Jan. 31, 2022, 12:20 p.m. |
Added to db | March 12, 2024, 7:58 p.m. |
Last updated | Aug. 31, 2024, 4:55 a.m. |
Headline | Workshop: An Introduction to macOS Forensics with Open Source Software |
Title | Workshop: An Introduction to macOS Forensics with Open Source Software |
Detected Hints/Tags/Attributes | 83/2/203 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 14 | cve-2021-30657 |
|
Details | Domain | 4127 | github.com |
|
Details | Domain | 36 | www.volexity.com |
|
Details | Domain | 3 | desktop.app |
|
Details | Domain | 5 | helper.app |
|
Details | Domain | 5 | firefox.app |
|
Details | Domain | 1 | plugin-container.app |
|
Details | Domain | 2 | themittenmac.com |
|
Details | Domain | 8 | chrome.app |
|
Details | Domain | 359 | com.apple |
|
Details | Domain | 2 | com.apple.xpc.launchd.oneshot.0x10000004.google |
|
Details | Domain | 30 | objective-see.com |
|
Details | Domain | 2 | netiquette.app |
|
Details | Domain | 2 | 239.237.117.34.bc.googleusercontent.com |
|
Details | Domain | 172 | www.crowdstrike.com |
|
Details | Domain | 46 | jsac.jpcert.or.jp |
|
Details | Domain | 281 | docs.microsoft.com |
|
Details | Domain | 3 | knockknock.app |
|
Details | Domain | 4 | lulu.app |
|
Details | Domain | 1 | com.objective-see.lulu.app |
|
Details | Domain | 6 | com.apple.developer.team |
|
Details | Domain | 1 | vbg97ub4ta.com.objective-see.lulu.app |
|
Details | Domain | 33 | com.apple.security |
|
Details | Domain | 2 | vbg97ub4ta.com |
|
Details | Domain | 1373 | twitter.com |
|
Details | Domain | 2 | aff4containers.cc |
|
Details | Domain | 8 | autogen.sh |
|
Details | Domain | 2 | 6hopperscript.tt |
|
Details | Domain | 2 | script.tt |
|
Details | Domain | 4 | siri.app |
|
Details | Domain | 4 | sqlitebrowser.org |
|
Details | Domain | 7 | stedolan.github.io |
|
Details | Domain | 16 | process.pid |
|
Details | Domain | 27 | com.microsoft |
|
Details | Domain | 3 | autoupdate.app |
|
Details | Domain | 7 | assistant.app |
|
Details | Domain | 2 | kkfilter.sh |
|
Details | Domain | 3 | padawan-4n6.hatenablog.com |
|
Details | Domain | 16 | installer.app |
|
Details | Domain | 5 | tinkaotp.app |
|
Details | Domain | 20 | processmonitor.app |
|
Details | Domain | 21 | filemonitor.app |
|
Details | Domain | 55 | process.name |
|
Details | Domain | 2 | file.process.name |
|
Details | Domain | 3 | assets.car |
|
Details | Domain | 4 | cedowens.medium.com |
|
Details | Domain | 14 | installer.sh |
|
Details | Domain | 2 | z4so.py |
|
Details | Domain | 604 | www.trendmicro.com |
|
Details | Domain | 81 | blog.malwarebytes.com |
|
Details | Domain | 4 | www.mac4n6.com |
|
Details | Domain | 3 | blockblock.app |
|
Details | Domain | 26 | posts.specterops.io |
|
Details | Domain | 2 | rmdir.sh |
|
Details | Domain | 1 | sdl-monitor.zip |
|
Details | Domain | 77 | amazonaws.com |
|
Details | Domain | 5 | eclecticlight.co |
|
Details | File | 2 | netiquette.html |
|
Details | File | 2 | jsac2020_7_kobayashi_jp.pdf |
|
Details | File | 5 | knockknock.html |
|
Details | File | 2 | kkresults_sample.txt |
|
Details | File | 5 | com.obj |
|
Details | File | 2 | developer.sys |
|
Details | File | 1 | s%20forensics-mus2020.pdf |
|
Details | File | 2 | revisiond.pl |
|
Details | File | 2 | evidence.dmg |
|
Details | File | 2 | mac_apt.py |
|
Details | File | 2 | data.dmg |
|
Details | File | 10 | apple.doc |
|
Details | File | 2 | k.pl |
|
Details | File | 7 | cache.db |
|
Details | File | 4 | mac_apt.db |
|
Details | File | 4 | unifiedlogs.db |
|
Details | File | 2 | fakeapp.dmg |
|
Details | File | 2 | procmon_simple.json |
|
Details | File | 17 | agent.pl |
|
Details | File | 24 | apple.log |
|
Details | File | 6 | initems.pl |
|
Details | File | 5 | store.db |
|
Details | File | 4 | apfs_volumes_xxxx.db |
|
Details | File | 2 | kkresults.txt |
|
Details | File | 1 | sqliteでmac_apt.db |
|
Details | File | 2 | nsec_conv.py |
|
Details | File | 36 | datetime.dat |
|
Details | File | 3 | recentitems.pl |
|
Details | File | 2 | globalpreferences.pl |
|
Details | File | 6 | finder.pl |
|
Details | File | 2 | spotlight.pl |
|
Details | File | 2 | installhistory.pl |
|
Details | File | 3 | system_logs.log |
|
Details | File | 1 | safariを使ってinstaller.dmg |
|
Details | File | 6 | installer.dmg |
|
Details | File | 6 | tinkaotp.dmg |
|
Details | File | 2 | tinkaopt.dmg |
|
Details | File | 2 | mina_procmon.json |
|
Details | File | 2 | mina_filemon.json |
|
Details | File | 3 | appstore.db |
|
Details | File | 52 | hash.txt |
|
Details | File | 130 | info.pl |
|
Details | File | 2 | tinkaotp_procmon.json |
|
Details | File | 2 | tinkaotp_filemon.json |
|
Details | File | 1 | appはinstaller.dmg |
|
Details | File | 2 | tinkaotp.png |
|
Details | File | 11 | history.db |
|
Details | File | 7 | downloads.pl |
|
Details | File | 5 | lastsession.pl |
|
Details | File | 2 | safaritabs.db |
|
Details | File | 6 | bookmarks.pl |
|
Details | File | 4 | extensions.pl |
|
Details | File | 3 | safari.pl |
|
Details | File | 3 | blog_0x64.html |
|
Details | File | 2 | z4so.py |
|
Details | File | 1 | platform-attack-capability.html |
|
Details | File | 1 | 0-demo.dmg |
|
Details | File | 1 | -demo.dmg |
|
Details | File | 1 | _amavisd.pl |
|
Details | File | 1 | _devicemgr.pl |
|
Details | File | 1 | _krb_krbtgt.pl |
|
Details | File | 1 | _scsd.pl |
|
Details | File | 1 | _analyticsd.pl |
|
Details | File | 1 | _diskimagesiod.pl |
|
Details | File | 2 | macforensics.pl |
|
Details | File | 10 | inwindow.pl |
|
Details | File | 2 | accounts.pl |
|
Details | File | 1 | tsx.sql |
|
Details | File | 2 | accountsx.sql |
|
Details | File | 2 | accounts4.sql |
|
Details | File | 24 | tcc.db |
|
Details | File | 2 | blockblock.pl |
|
Details | File | 2 | atrun.pl |
|
Details | File | 28 | apple.sys |
|
Details | File | 9 | system.key |
|
Details | File | 1 | systemkeyファイルにはsystem.key |
|
Details | File | 13 | login.key |
|
Details | File | 4 | netusage.sql |
|
Details | File | 5 | knowledgec.db |
|
Details | File | 4 | currentpowerlog.pls |
|
Details | File | 2 | dd_xxxxxxxx.pl |
|
Details | File | 2 | qsql.gz |
|
Details | File | 1 | 0-8a32.dmg |
|
Details | File | 28 | 0.tar |
|
Details | File | 1 | sdl-monitor.zip |
|
Details | File | 1 | idapython-book.pdf |
|
Details | File | 2 | 12.dmg |
|
Details | File | 1 | 0_macos_x86-64_langpack_ja.dmg |
|
Details | File | 1 | mt-fuji-477832_1920.jpg |
|
Details | File | 1 | 12-7a112.dmg |
|
Details | File | 2 | 43_v2.zip |
|
Details | File | 2 | 4_build_18e226.dmg |
|
Details | File | 1 | 0_macos_x86-64.dmg |
|
Details | File | 1 | sentinal-one-mac-os-.pdf |
|
Details | File | 1 | architecture-1869398_1920.jpg |
|
Details | Github username | 9 | velocidex |
|
Details | Github username | 5 | mnrkbys |
|
Details | Github username | 2 | sleuthkit |
|
Details | Github username | 2 | aff4 |
|
Details | Github username | 6 | ydkhatri |
|
Details | Github username | 5 | crowdstrike |
|
Details | Github username | 3 | mac4n6 |
|
Details | Github username | 4 | n0fate |
|
Details | md5 | 2 | E140C97A5D60B342D466BBE813971A06 |
|
Details | md5 | 2 | F05437D510287448325BAC98A1378DE1 |
|
Details | sha1 | 2 | 8d489231a242131974a307abd5188a3614d265a7 |
|
Details | sha1 | 3 | fa3deb60b8a2eaa29a7dccf14bee6adae81f442f |
|
Details | IPv4 | 2 | 239.237.117.34 |
|
Details | IPv4 | 4 | 192.168.11.2 |
|
Details | IPv4 | 3 | 34.117.237.239 |
|
Details | IPv4 | 2 | 0.0.29.3 |
|
Details | Url | 2 | https://github.com/velocidex/c-aff4/releases/tag/1.0.rc2 |
|
Details | Url | 2 | https://github.com/velocidex/c-aff4/releases/tag/3.2 |
|
Details | Url | 2 | https://www.volexity.com/products-overview/surge |
|
Details | Url | 2 | https://themittenmac.com/the-truetree-concept |
|
Details | Url | 2 | https://objective-see.com/products/netiquette.html |
|
Details | Url | 1 | https://www.crowdstrike.com/blog/how-to-leverage- |
|
Details | Url | 3 | https://github.com/mnrkbys/macosac |
|
Details | Url | 2 | https://jsac.jpcert.or.jp/archive/2020/pdf/jsac2020_7_kobayashi_jp.pdf |
|
Details | Url | 5 | https://objective-see.com/products/knockknock.html |
|
Details | Url | 2 | https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns |
|
Details | Url | 2 | https://twitter.com/unkn0wnbit/status/1254971428606107648 |
|
Details | Url | 2 | https://github.com/sleuthkit/sleuthkit/pull/1272 |
|
Details | Url | 2 | https://github.com/aff4/pyaff4 |
|
Details | Url | 2 | https://github.com/aff4/aff4-cpp-lite |
|
Details | Url | 1 | https://github.com/aff4/aff4-cpp-lite.git |
|
Details | Url | 1 | https://github.com/ydkhatri/presentations/blob/master/maco |
|
Details | Url | 1 | https://github.com/ydkhatri/macos_fe/tree/master |
|
Details | Url | 6 | https://github.com/ydkhatri/mac_apt |
|
Details | Url | 4 | https://github.com/crowdstrike/automactc |
|
Details | Url | 2 | https://github.com/mac4n6/apollo |
|
Details | Url | 2 | https://github.com/mnrkbys/dsstoreparser/tree/fix_bug_non-ascii |
|
Details | Url | 4 | https://github.com/n0fate/chainbreaker |
|
Details | Url | 1 | https://malware.example/download/fakeapp.dmg |
|
Details | Url | 3 | https://sqlitebrowser.org |
|
Details | Url | 6 | https://stedolan.github.io/jq |
|
Details | Url | 2 | https://padawan-4n6.hatenablog.com/entry/2020/03/15/052607 |
|
Details | Url | 2 | http://www.2fa.test/download/installer.dmg |
|
Details | Url | 1 | http://www.2fa.test/download/tinkaotp.dmg |
|
Details | Url | 1 | https://cedowens.medium.com/macos-gatekeeper- |
|
Details | Url | 3 | https://objective-see.com/blog/blog_0x64.html |
|
Details | Url | 1 | https://www.trendmicro.com/en_us/research/20/e/new- |
|
Details | Url | 6 | https://blog.malwarebytes.com/threat- |
|
Details | Url | 1 | https://www.mac4n6.com/blog/2020/6/1/analysis-of-apple- |
|
Details | Url | 2 | https://posts.specterops.io/are-you-docking-kidding-me-9aa79c24bdc1 |
|
Details | Url | 2 | https://eclecticlight.co/lockrattler-systhist |