Shafik Punja Profile
Shafik Punja

@qubytelogic

Followers
932
Following
2K
Media
23
Statuses
2K

DFIR worker bee/research monkey. Views are my own.🐧 And do not necessarily represent strategies, views or opinions of any employers: past, present or future.

Joined June 2011
Don't wanna be here? Send us removal request.
@qubytelogic
Shafik Punja
5 years
Arsenal Image Mounter (by @ArsenalRecon ) functionality walk through:
0
2
4
@chessMan786
Mohit Mishra
10 months
Computer Architecture From Scratch Very good series of videos on computer architecture with great visualization
6
173
2K
@mjolnir_intern
intern
11 months
the forensic guy just said, “Oh… that’s not good.” i don’t know what he saw, but is it too late to consider a career in accounting... 🫠
0
1
1
@mjolnir_intern
intern
11 months
we’re extracting VMs from the server. people are typing aggressively. someone just whispered “this is fine” while sweating.
0
1
1
@vxunderground
vx-underground
1 year
One thing noobie scoobies don't seem to understand is that malware is literally just software. Understandably, that seems kind of obvious, it's in the name — 'malicious software'. But it seems less obvious to some that, in order to write malware, you apply the exact same
40
159
1K
@4enzikat0r
Kathryn Hedley
1 year
🚨 #DFIR Tool update 🚨 I’ve updated parseUSBs (again!): - Now supports mounted #KAPE images - Improved deduplication of events within secs of each other - Added extraction of partition style (MBR/GPT) & FS - Parses alternate S/Ns - Parses WPDBUSENUM key https://t.co/MOBVqRdRva
Tweet card summary image
github.com
Parses USB connection artifacts from offline Registry hives - khyrenz/parseusbs
0
8
46
@naehrdine
Jiska
1 year
Apple indeed added a feature called "inactivity reboot" in iOS 18.1. This is implemented in keybagd and the AppleSEPKeyStore kernel extension. It seems to have nothing to do with phone/wireless network state. Keystore is used when unlocking the device. https://t.co/ONZuU9zVt2
@josephfcox
Joseph Cox
1 year
New from 404 Media: police freaking out at iPhones stored for forensic examination mysteriously rebooting themselves. This makes brute forcing much harder. Cops hypothesize Apple pushed an update that tells nearby iPhones to reboot if not on phone network
18
444
3K
@sansforensics
SANS DFIR
1 year
🔎 Can you trust your #forensic tools? Discover how to validate them at Community Learning Day at #DFIRCON with @4enzikat0r's. This hands-on tutorial will provide you the skills to ensure your #DigitalForensic tools are dependable. 👉 Learn more: https://t.co/3LLPYZWgXp
0
8
23
@MrEerie
derek eiri 👻
1 year
I wrote a blog post exploring @DasZamomin 's project, UFADE. Exploring UFADE to Extract Data From iOS Devices – mr. eerie ( https://t.co/rvsGgQTjHF)
mreerie.com
"It looks like we've got ourselves a digital forensic mystery!"
1
4
10
@qubytelogic
Shafik Punja
1 year
The Eyes Lie - Written
0
0
2
@thatstraw
TRÄW🤟
1 year
How ARP works.
3
228
1K
@joshlemon
Josh Lemon
1 year
If you're interested in getting into #Linux #logging and evidence collection, this is an excellent write-up from @Kostastsale that compares #EVTX logs on Windows with #Auditd, #SysMon for Linux, and native Linux logging. #DFIR #LinuxForensics #SIEM #CSIRT https://t.co/uukC9K0Ct2
0
113
276
@cyb_detective
Cyber Detective💙💛
1 year
Open Directory Search Tool A simple online tool that generates queries to Google to search for audio, video, ebooks and archives in open directories on different servers. https://t.co/MF2LvAmavO Tip by @DarkWebInformer Similar tool https://t.co/XI5kRH2y7n
2
46
158
@MrEerie
derek eiri 👻
1 year
Took a short FOR518 study break to: 1) Recover from a catastrophic OS drive failure (min. data loss, yay.) 2) Explore Christian Peter's UFADE for Windows https://t.co/kv4MyJYG31 Here, I'm combining iMazing to pair a supervised iOS device to a Windows mach. to take screenshots.
4
2
9
@Therapyquotes_
Therapy Quotes
1 year
Marriage advice from 1886
77
10K
52K
@BushidoToken
Will
1 year
Oh, so you track ransomware tools? OK, name every one. Me:
9
135
708
@cyb_detective
Cyber Detective💙💛
1 year
If you need to process PDF documents (crop, merge, split, convert, read metadata, etc) but don't want to upload them to third-party online services, you can: 1. Use command line tools (see comments). 2. Use self-hosted PDF services such as Stirling PDF. https://t.co/D7u9JjbZSF
5
57
179
@cyb_detective
Cyber Detective💙💛
1 year
A list of more than 15 reverse image search tools can be found in the Linkedin group of my old mates - OSINT Experts & Resources, by UserSearch
@cyb_detective
Cyber Detective💙💛
1 year
https://t.co/f6PBoTZ25J Reserve images/face images search tool. Search duplicates and similar images. Filter results by domains and keywords. Tip by @HolismVision #osint #socmint
5
50
158
@4enzikat0r
Kathryn Hedley
1 year
In case you missed my big news in today’s workshop… I will be re-running Ranges events for ALL of my previous @sansforensics #GettingStartedinDFIR #DFIR workshops, so all 6 workshops will be live from 13:00 EDT on Aug 13th to midnight on Aug 21st in the run up to the #DFIRSummit
1
13
25
@cyb_detective
Cyber Detective💙💛
1 year
10 Free OSINT tools for Beginners and Pros by @wondersmith_rae An overview of 10 widely known and very useful tools that everyone involved in OSINT should know about (but I'm sure you already know at least 7-8 of them). https://t.co/4U2398ge1q
1
35
119