# forensic

Published articles for forensic.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How to find hidden processes and ports on Linux/Unix/Windows

DevFeed: [How to find hidden processes and ports on Linux/Unix/Windows](<https://devfeed.tech/articles/how-to-find-hidden-processes-and-ports-on-linux-unix-windows-41966.md>)

Original publisher: [Read original article](<https://www.cyberciti.biz/tips/linux-unix-windows-find-hidden-processes-tcp-udp-ports.html>)

Author: Vivek Gite

Published: 2024-05-07T05:05:51Z

Content type: tutorial

Language: en

Sources: [nixCraft: Linux Tips, Hacks, Tutorials, And Ideas In Blog Format (RSS/FEED)](<https://devfeed.tech/sources/nixcraft-linux-tips-hacks-tutorials-and-ideas-in-blog-format-rss-feed.md>)

Topics: [Processes](<https://devfeed.tech/topics/processes.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>)

Tags: [forensic](<https://devfeed.tech/tags/forensic.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [operating-systems](<https://devfeed.tech/tags/operating-systems.md>), [tcp](<https://devfeed.tech/tags/tcp.md>), [udp](<https://devfeed.tech/tags/udp.md>), [unix](<https://devfeed.tech/tags/unix.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

A tutorial on using the Unhide and unhide-tcp forensic tools to detect hidden processes and listening TCP/UDP ports on Linux, Unix-like systems, and Windows. It covers installation across several distributions and operating systems, available detection techniques, and basic usage.

### Source excerpt

Unhide is a little handy forensic tool to find hidden processes and TCP/UDP ports by rootkits / LKMs or by another hidden technique. This tool works under Linux, Unix-like system, and MS-Windows operating systems. Love this? sudo share_on: Twitter - Facebook - LinkedIn - Whatsapp - Reddit The post How to find hidden processes and ports on Linux/Unix/Windows appeared first on nixCraft.

## Comparing Retrospectives

DevFeed: [Comparing Retrospectives](<https://devfeed.tech/articles/comparing-retrospectives-36733.md>)

Original publisher: [Read original article](<https://shostack.org/blog/comparing-retrospectives/>)

Author: Adam

Published: 2023-09-19T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [retrospectives](<https://devfeed.tech/topics/retrospectives.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [design](<https://devfeed.tech/tags/design.md>), [forensic](<https://devfeed.tech/tags/forensic.md>), [investigations](<https://devfeed.tech/tags/investigations.md>), [logs](<https://devfeed.tech/tags/logs.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [report](<https://devfeed.tech/tags/report.md>), [retention](<https://devfeed.tech/tags/retention.md>), [retrospectives](<https://devfeed.tech/tags/retrospectives.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article compares Microsoft's retrospective on the Storm-0558 key acquisition with Thornton Tomasetti's forensic investigation of the Arecibo Telescope collapse. It argues that retrospectives preserve authoritative accounts, support organizational learning, and reassure stakeholders, while contrasting the reports' length, authorship, and treatment of evidence. It also examines log retention as a security design choice.

### Source excerpt

We can learn a lot from comparing retrospectives

## Scanning your iPhone for Pegasus, NSO Group's malware

DevFeed: [Scanning your iPhone for Pegasus, NSO Group's malware](<https://devfeed.tech/articles/scanning-your-iphone-for-pegasus-nso-group-s-malware-41998.md>)

Original publisher: [Read original article](<https://arkadiyt.com/2021/07/25/scanning-your-iphone-for-nso-group-pegasus-malware/>)

Published: 2021-07-25T07:00:00Z

Content type: tutorial

Language: en

Sources: [Arkadiy Tetelman](<https://devfeed.tech/sources/arkadiy-tetelman.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>), [Android](<https://devfeed.tech/topics/android.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [Jailbreak](<https://devfeed.tech/topics/jailbreak.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [backup](<https://devfeed.tech/tags/backup.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [filesystem](<https://devfeed.tech/tags/filesystem.md>), [forensic](<https://devfeed.tech/tags/forensic.md>), [infection](<https://devfeed.tech/tags/infection.md>), [ios](<https://devfeed.tech/tags/ios.md>), [iphone](<https://devfeed.tech/tags/iphone.md>), [jailbreak](<https://devfeed.tech/tags/jailbreak.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [safari](<https://devfeed.tech/tags/safari.md>), [scanner](<https://devfeed.tech/tags/scanner.md>)

### AI overview

A practical guide to scanning an iPhone for indicators of Pegasus, NSO Group's mobile malware, using Amnesty International's open-source Mobile Verification Toolkit. It explains the trade-offs between scanning a device backup and a filesystem dump from a jailbroken device.

### Source excerpt

In collaboration with more than a dozen other news organizations The Guardian recently published an exposé about Pegasus, a toolkit for infecting mobile phones that is sold to governments around the world by NSO Group. It's used to target political leaders and their families, human rights activists, political dissidents, journalists, and so on, and surreptitiously download their messages/photos/location data, record their microphone, and otherwise spy on them. As part of the investigation, Amnesty International wrote a blog post with their forensic analysis of several compromised phones, as well as an open source tool, Mobile Verification Toolkit, for scanning your mobile device for these indicators. MVT supports both iOS and Android, and in this blog post we'll install and run the scanner against my iOS device. Choosing your options For iPhones, MVT can either run against a device backup or a full file system dump (which is only available from jailbroken devices). The device backup method has access to less forensic data than the filesystem dump but has the benefit that you don't need to jailbreak your device. MVT conveniently documents which forensic artifacts are available to which method - the following artifacts are not available when using the backup method: cache_files.json net_usage.json safari_favicon.json version_history.json webkit_indexeddb.json webkit_local_storage.json webkit_safari_view_service.json The same documentation link also explains what data each file contains and where it's sourced from, and Amnesty's blog post describes in more detail how each data type is relevant for detecting Pegasus. For instance for the Safari favicon data (safari_favicon.json) they write: Although Safari history records are typically short lived and are lost after a few months (as well as potentially intentionally purged by malware), we have been able to nevertheless find NSO Group's infection domains in other databases of Omar Radi's phone that did not appear in Safa

## Pair Locking your iPhone with Configurator 2

DevFeed: [Pair Locking your iPhone with Configurator 2](<https://devfeed.tech/articles/pair-locking-your-iphone-with-configurator-2-41994.md>)

Original publisher: [Read original article](<https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-with-configurator-2/>)

Published: 2019-10-07T07:00:00Z

Content type: tutorial

Language: en

Sources: [Arkadiy Tetelman](<https://devfeed.tech/sources/arkadiy-tetelman.md>)

Topics: [iphone](<https://devfeed.tech/topics/iphone.md>), [Security](<https://devfeed.tech/topics/security.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [bootrom](<https://devfeed.tech/topics/bootrom.md>), [locking](<https://devfeed.tech/topics/locking.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [bootrom](<https://devfeed.tech/tags/bootrom.md>), [forensic](<https://devfeed.tech/tags/forensic.md>), [ios](<https://devfeed.tech/tags/ios.md>), [iphone](<https://devfeed.tech/tags/iphone.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A tutorial on pair-locking an iPhone with Configurator 2 to prevent forensic tools from pairing with the device, imaging it, scanning its contents, or extracting app authentication tokens. It explains the privacy rationale and how pairing works.

### Source excerpt

In response to the recent iphone bootrom bug (and also because I was already in the market for a new phone), I recently purchased a new iPhone XR. This gave me a chance to re-run the steps required to pair lock the device, a process which prevents law enforcement from using forensics tools against your phone, and the result of which is this blog post. It covers: Why pair lock your device? How does it work? Supervising and pair locking your device Why pair lock your device? It's an unfortunate state of affairs but people's digital privacy is increasingly under attack by law enforcement agencies, especially at protests, airports, and border crossings. Articles like the following have become all too common: A US-born NASA scientist was detained at the border until he unlocked his phone Man sues feds after being detained for refusing to unlock his phone at airport Phone and laptop searches at US border 'quadruple' US deports foreign student 'over friends' social media posts' Are Police Searching Inauguration Protesters' Phones? and closer to my home in San Francisco we see tweets like this one: By pair locking your device you will prevent iPhone forensics tools from being able to connect to your device, image it, scan through your messages and camera roll, read your contacts and call history, etc - even if you've been compelled by law enforcement to unlock your device! They can still manually look through your unlocked phone contents, but they can't image the device for offline analysis, they can't run automated content scanners, and they no longer get access to your various app authentication tokens. I originally learned about this feature / unintended side effect from Jonathan Zdziarski's excellent blog post about it. Jonathan was a well-known iOS security researcher who now works on Apple's security team. Unfortunately since joining Apple he stopped blogging about iOS security (and deleted his twitter), and the instructions in his original 2014 blog are now slightly

## Zen and the Art of Craft CMS Log File Reading

DevFeed: [Zen and the Art of Craft CMS Log File Reading](<https://devfeed.tech/articles/zen-and-the-art-of-craft-cms-log-file-reading-31323.md>)

Original publisher: [Read original article](<https://nystudio107.com/blog/zen-and-the-art-of-craft-cms-log-file-reading>)

Author: andrew@nystudio107.com (Andrew Welch)

Published: 2019-07-22T05:00:00Z

Content type: tutorial

Language: en

Sources: [nystudio107 | Articles on modern web development.](<https://devfeed.tech/sources/nystudio107-articles-on-modern-web-development.md>)

Topics: [Logging](<https://devfeed.tech/topics/logging.md>), [debugging](<https://devfeed.tech/topics/debugging.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [black](<https://devfeed.tech/tags/black.md>), [cli](<https://devfeed.tech/tags/cli.md>), [contain](<https://devfeed.tech/tags/contain.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [diagnose](<https://devfeed.tech/tags/diagnose.md>), [file](<https://devfeed.tech/tags/file.md>), [files](<https://devfeed.tech/tags/files.md>), [forensic](<https://devfeed.tech/tags/forensic.md>), [information](<https://devfeed.tech/tags/information.md>), [insights](<https://devfeed.tech/tags/insights.md>), [learn](<https://devfeed.tech/tags/learn.md>), [let-s](<https://devfeed.tech/tags/let-s.md>), [like](<https://devfeed.tech/tags/like.md>), [logging](<https://devfeed.tech/tags/logging.md>), [php](<https://devfeed.tech/tags/php.md>), [precious](<https://devfeed.tech/tags/precious.md>), [problems](<https://devfeed.tech/tags/problems.md>), [reading](<https://devfeed.tech/tags/reading.md>), [recording](<https://devfeed.tech/tags/recording.md>)

### AI overview

A tutorial on reading Craft CMS log files to diagnose problems, including how Craft separates web, 404, console, queue, and PHP error logs in the storage/logs/ directory. It also discusses using the Debug Toolbar to search, sort, and filter logs during local debugging.

### Source excerpt

Like a black box recording, log files contain precious forensic information for when you have to diagnose problems. Let's learn the art of reading them

## NTFS Write Support GSoC - Week 3

DevFeed: [NTFS Write Support GSoC - Week 3](<https://devfeed.tech/articles/ntfs-write-support-gsoc-week-3-32969.md>)

Original publisher: [Read original article](<https://reactos.org/blogs/ntfs-write-support-gsoc-week-3/>)

Published: 2016-06-13T00:00:00Z

Content type: article

Language: en

Sources: [Front Page on ReactOS Website](<https://devfeed.tech/sources/front-page-on-reactos-website.md>)

Topics: [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [Data structures](<https://devfeed.tech/topics/data-structures.md>), [integrity](<https://devfeed.tech/topics/integrity.md>), [Code](<https://devfeed.tech/topics/code.md>), [file](<https://devfeed.tech/topics/file.md>)

Tags: [code](<https://devfeed.tech/tags/code.md>), [data-structures](<https://devfeed.tech/tags/data-structures.md>), [file](<https://devfeed.tech/tags/file.md>), [files](<https://devfeed.tech/tags/files.md>), [forensic](<https://devfeed.tech/tags/forensic.md>), [free](<https://devfeed.tech/tags/free.md>), [gsoc](<https://devfeed.tech/tags/gsoc.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [learning](<https://devfeed.tech/tags/learning.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [os](<https://devfeed.tech/tags/os.md>), [react](<https://devfeed.tech/tags/react.md>), [reactos](<https://devfeed.tech/tags/reactos.md>), [win32](<https://devfeed.tech/tags/win32.md>), [winapi](<https://devfeed.tech/tags/winapi.md>)

### AI overview

A GSoC Week 3 progress report on implementing NTFS write support. The author describes studying NTFS, building a standalone file-listing app, and updating data structures needed to extend non-resident files, including file records and fixup arrays.

### Source excerpt

Learning About NTFS I spent most of the week studying NTFS in-depth, and really learning about some of the things I glossed over before. This is something I had to do make meaningful progress with increasing file sizes. This involved (re-re-re-)reading the three relevant chapters in File System Forensic Analysis. Also, in order to retain and really understand the information, I've started making a standalone app that lists files on an NTFS partition.