
Minoru Kobayashi
@unkn0wnbit
Followers
2K
Following
15K
Media
1K
Statuses
15K
Digital Forensic Investigator (Windows/macOS), Black Hat USA 2018 speaker (https://t.co/t2mgf9OTWr), CISSP, Network Security Engineer
日本 東京
Joined May 2011
Hi #DFIR community,.I'm excited to announce that I have published my new forensic tool for analyzing journal data from #Linux file systems (EXT4 and XFS). 🔗 This tool requires TSK's develop branch to recognize the XFS file system, so you will need to.
github.com
FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), generates timelines, and detects suspicious activities. - mnrkby...
6
66
170
RT @wtsdev: And now, for no reason in particular, how to silently launch an application on macOS:.
gist.github.com
Launch an application silently on macOS. GitHub Gist: instantly share code, notes, and snippets.
0
3
0
RT @wtsdev: Launch constraints are annoying as a security researcher. What if you didn't have to worry about them?.
wts.dev
A security research blog.
0
9
0
RT @Securityinbits: 🔗 Try the tool yourself:. Deobfuscate version:.
github.com
Powershell Linter. Contribute to airbus-cert/minusone development by creating an account on GitHub.
0
6
0
RT @Securityinbits: Ever run into randomly obfuscated PowerShell? 😵💫. I did - thanks to a recent tool (revshell) that generate random vers….
0
60
0
🛠️ FJTA update released (2025-07-29)!. Changes include:.✅ Improved parsing of XFS journal log records .✅ Enhanced handling of directory entries (ext4/XFS).✅ Minor bug fixes. 🔗 #DFIR #Linux.
github.com
FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), generates timelines, and detects suspicious activities. - mnrkby...
0
6
23
RT @HackingLZ: Now that there are tons of these and I can never find them when I need them, thanks @Oddvarmoe for showing me all the LOLS….
lolol.farm
Living Off the Living Off the Lands
0
45
0
RT @MarkBaggett: What do you think of SRUM-DUMP Version 3? Download your free copy here:. Here is a write up on t….
isc.sans.edu
SRUM-DUMP Version 3: Uncovering Malware Activity in Forensics, Author: Mark Baggett
0
7
0
RT @KevinPagano3: #Stark4N6: Introducing DirListHash - A Directory & Hashing Utility #DFIR #Python .
0
6
0
RT @hackingump1: 🚨 RIFT update!.Now supports FLIRT signature generation on Linux 🐧.🔗 #RustLang #MalwareAnalysis #Re….
github.com
Rust Library Recognition Project for Rust Malware by the MSTIC-MIRAGE Team - microsoft/RIFT
0
2
0
RT @hacker_ralf: AdaptixC2 v0.7 is out!. * AxScript scripting support.* Credential Manager added.* BOF support in….
0
114
0
RT @CraigHRowland: Playing with the Medusa stealth rootkit which is LD_PRELOAD style of hiding on Linux. If you think this kind of rootkit….
0
41
0
RT @HexRaysSA: IDA 9.2 (coming soon. ) adds full support for the TriCore TC1.8 architecture, including over 50 new instructions and updat….
0
6
0
「フィッシングメール訓練」は効果があるのか、2万人対象の大規模調査で驚きの結果
xtech.nikkei.com
多くの組織が「フィッシングメール訓練」を実施している。効果はあるのだろうか。それを確かめるべく、米シカゴ大学などの研究者グループはUCSD Healthの職員1万9789人を対象にした調査を実施した。その調査結果はいかに。
0
0
0
Macのメモリ上に一時的な高速仮想ドライブを作成できる「TmpDisk」がAPFSとNoExecオプションをサポートし、CLIツールを追加。
applech2.com
TmpDiskはMacに搭載されているメモリを一時的に揮発性の高速な仮想ドライブへ変換しマウントできるようにしてくれるアプリで、元TwitterのエンジニアのTimothy Marksさん(Imothee LLC.)がオープンソースで開発していますが、このTmpDiskが「TmpDisk v2.2.x」アップデートで、APFSやNoExecオプションなどをサポートしています。
0
0
8
RT @HexRaysSA: 📣 IDA 9.2 Beta is here! This release is packed with UI upgrades, smarter analysis, and expanded architecture support. ➥ Al….
0
36
0
RT @IIJSECT: Technical Analysis of NailaoLocker Ransomware | IIJ Security Diary (in English) @IIJSECT.
sect.iij.ad.jp
This is the English version of the Japanese article "ランサムウェアNailaoLockerの調査". In February 2025, several cybersecurity vendors published a report about a ransomware named NailaoLocker12.Compared to...
0
5
0
RT @__kokumoto: GitHubで公表されている「教育用」の自称デジタルフォレンジックツールOctalyn Forensic Toolkitは実態はモジュール型認証情報窃取マルウェアで。CYFIRMA社報告。C2はTelegram。 .
securityonline.info
Cyfirma uncovers "Octalyn Forensic Toolkit," a GitHub-hosted "educational" tool that's actually a modular credential stealer exfiltrating data via Telegram.
0
20
0