Forensic Blogs

An aggregator for digital forensics blogs

May 14, 2022 by Didier Stevens

Update: oledump.py Version 0.0.67

This new version of oledump.py brings support for user defined properties and an update to plugin plugin_msg_summary.py

Office documents with VSTO applications have user defined properties. These properties can be extracted with my plugin plugin_medata.py, but not with the current version of olefile.
However, the development version of olefile can be used to extract these properties. This new version of oledump checks if the olefile module has a function to extract user defined properties (get_userdefined_properties), and if it does, it calls it when analyzing metadata:

Figure: oledump option -M with olefile supporting get_userdefined_properties Figure: plugin_metadata

I added URL extracting to my plugin plugin_msg_summary, a plugin to summarize the content of an .msg file (Outlook email).

oledump_V0_0_67b.zip (http)
MD5: D6D1748A98AEA3D922D99415E908C609
SHA256: 092A2EA0FBB67357FC5E4D7B8E266B52EA242C147609FD025616754EAA2532E1

Read the original at: Didier StevensFiled Under: Digital Forensics Tagged With: My Software, Update

May 12, 2022 by Didier Stevens

Update: zipdump.py Version 0.0.22

This is just a bugfix version.

zipdump_v0_0_22.zip (http)
MD5: 68F9F3809E4E1F9ADE4A4C3835CDF475
SHA256: 92ED372579001C826D5AF31615B8334CC798FF2DA4AF8B7C46267BF7D995C757

Read the original at: Didier StevensFiled Under: Digital Forensics Tagged With: My Software, Update

May 8, 2022 by Didier Stevens

Update: cs-parse-traffic.py Version 0.0.5

In this update for cs-parse-traffic.py, my tool to decrypt & parse Cobalt Strike traffic, I added some error handling.

cs-parse-traffic_V0_0_5.zip (http)
MD5: CFF6D97E816B23065F051D91B0F101A6
SHA256: 69763EB4D3A163824B417A0E23131B318F5E97198F255ECE449A65D4360C6302

Read the original at: Didier StevensFiled Under: Digital Forensics Tagged With: My Software, Update

  • « Previous Page
  • 1
  • 2
  • 3
  • 4
  • 5
  • …
  • 146
  • Next Page »

About

This site aggregates posts from various digital forensics blogs. Feel free to take a look around, and make sure to visit the original sites.

  • Contact
  • Aggregated Sites

Suggest a Site

Know of a site we should add? Enter it below

Sending

Jump to Category

All content is copyright the respective author(s)