https://www.reddit.com/r/Nexus6P/comments/3vtpb5/how_to_flash_update_images_without_wiping_data/?depth=2

 

How to flash update images without wiping data

Posted in r/Nexus6P by u/inate71 • 152 points and 137 comments

www.reddit.com

https://www.sans.org/reading-room/whitepapers/detection/paper/34232

 

SANS Institute: Reading Room - Intrusion Detection

Intrusion Detection Featuring 195 Papers as of March 26, 2019 Event Monitoring and Incident Response by Ryan Boyle - May 15, 2013  System security policies can still have security holes after implementation and may even introduce unintended consequences. V

www.sans.org

https://www.sans.org/reading-room/whitepapers/incident/paper/37920

 

SANS Institute: Reading Room - Incident Handling

Incident Handling Featuring 148 Papers as of April 2, 2019 A Practical Example of Incident Response to a Network Based Attack STI Graduate Student Research by Gordon Fraser - August 16, 2017  A commonly accepted Incident Response (IR) process includes six

www.sans.org

https://www.first.org/resources/papers/conference2008/chuvakin-anton-slides.pdf

불러오는 중입니다...

 

https://www.unb.ca/cic/datasets/index.html

 

Datasets | Research | Canadian Institute for Cybersecurity | UNB

 

www.unb.ca

 

상황을 가정하자면, 

로컬컴퓨터에 Dropbox가 설치되어 있고 synced 파일들의 백업도 발견되었다. Credential 만 가지고 dropbox를 access할 수 있으니 어느 계정과 동기화되었었는지가 중요하다. 케이스의 핵심도 어느 credential이 사용되었는지를 찾는 것이다. 설정에서 Account link도 지워지고 없는 상태이다.


DROPBOX DBX DECRYPTION




https://www.13cubed.com/downloads/rdp_flowchart.pdf


어느 evtx에서 어느 타입을 볼지는 링크로 들어가서 볼 것


EventID 1149

EventID 4624

EventID 21

EventID 22

+ Recent posts