74 results for “u”

PowerShell Function Basics and Recursion

## Defining a Function ```powershell function Get-Factorial { param([int]$n) if ($n -le 1) { return 1 } return $n * (Get-Factorial -n ($n - 1)) } Get-Factorial -n 5 …

Writing Python Functions and Recursion Basics

# Writing Python Functions and Recursion Basics ## Defining a simple function A function packages reusable logic under a name. You define it with `def`, give it parameters, and …

WinDbg Patching Arguments at Runtime

# WinDbg Patching Arguments at Runtime When a function is about to receive a bad argument (e.g. `NULL` filename passed to `__loaddll`), you can fix the pointer value on [[Stack F…

Active Recall

Active recall is a learning technique that involves actively testing yourself on material rather than passively re-reading. It is closely related to [[Spaced Repetition]] and [[Le…

Spaced Repetition

Spaced repetition is a learning technique where you review information at strategically increasing intervals over time. Instead of cramming, you revisit material just as you're ab…

Evidence Acquisition Fundamentals

# Evidence Acquisition Fundamentals Acquisition is the bridge between the *existence* of a digital trace and its *usability* as evidence. It is where the philosophical principles…

Test Node Alpha

This is a test note for debugging wikilink functionality. It contains a link to [[Test Node Beta]]. Created for bug-fixing purposes.

Test Node Beta

This is a second test note for debugging wikilink functionality. It contains a link back to [[Test Node Alpha]]. Created for bug-fixing purposes.

Regex Fundamentals

# Regex Fundamentals A foundational reference for regex syntax, with emphasis on practical application in digital forensics, log analysis, and tooling like [[Burp Suite]]. ## 1.…

PowerShell as an Acquisition Engine

# PowerShell as an Acquisition Engine PowerShell is described in Hosmer's book as a powerful **acquisition engine** for digital investigations. Its role is to gather raw informat…

Experimenting with PowerShell

PowerShell is typically preinstalled on modern Windows desktop and server platforms. If it is not present, you can download and install it by searching for **Windows Management Fr…

Why Malware Names Are Not Enough

The opening of *Practical Malware Analysis* presents a cautionary incident-response scenario: a network is breached, antivirus identifies the malware as **TROJ.snapAK**, the respo…

Malware Analysis: Role and Value of the Analyst

# Malware Analysis **Malware analysis** is the process of dissecting malicious software to understand how it works, how to identify it, and how to defeat or eliminate it. It is a…

Forensic Analyst as Insider Threat

The forensic analyst occupies a uniquely privileged position: they have the technical access to discover, preserve, and interpret evidence, but they also have the ability to manip…

Footprint (Forensic)

In network forensics, the **footprint** is the impact an investigator leaves on the systems under examination. Every interaction with a live system modifies it in some way—just as…

Direct Evidence

**Direct evidence** is testimony from a **direct witness** who personally observed the act or event in question. It is based on firsthand human perception rather than inference fr…

Hearsay

**Hearsay** is an out-of-court statement offered to prove the truth of the matter asserted. Under the **U.S. Federal Rules of Evidence (FRE)**, hearsay is generally **not admissib…

Business Records

**Business records** are documents or data that an enterprise routinely generates and retains as part of its normal operations, and that are considered accurate enough to guide ma…

Digital Evidence

**Network-based digital evidence** is digital evidence produced as a result of **communications over a network**. It is a subset of **[[Digital Evidence]]**, but it is distinguish…

Real Evidence

**Real evidence** is a physical, tangible object that played a relevant role in the event being investigated. It is the kind of evidence a jury can see and touch, such as the murd…

Network Evidence Challenges

Network-based evidence is a subset of [[Digital Evidence]] that comes with its own set of practical and legal headaches. Section [[1.4 Challenges Relating to Network Evidence]] gr…

Live Breach

A **live breach** is an active, ongoing security incident in which an attacker is currently connected to or operating inside a network while the investigative response is underway…

Encapsulation and Demultiplexing

**Encapsulation** and **demultiplexing** are the two complementary processes that move data through the layers of the **[[OSI Model]]**. ### Encapsulation (sender side) When data…

TCP Three-Way Handshake

The **TCP three-way handshake** is the process used by the **Transmission Control Protocol (TCP)** to establish a reliable, bidirectional connection between two hosts. It is a fou…

OSI Model

The **OSI model** (Open Systems Interconnection) is a seven-layer framework developed by ISO for designing and understanding network communications. Each layer solves a discrete …

lea vs mov [mem] in x86 Assembly

Two instructions look similar in disassembly but do opposite things with memory. | Instruction | What it does | C analogy | |-------------|--------------|-----------| | `mov ecx,…

Protocol (Networking)

A **protocol** is a set of formal rules describing how to transmit data, especially across a network. Protocols are: - Rules for successful communication between different system…

Circumstantial Evidence

[[Circumstantial Evidence]] is evidence that does **not directly prove a conclusion**, but can be linked with other evidence to **deduce** what happened. It requires inference and…

Best Evidence

**[[Best Evidence]]** is the **best available evidence that can be produced in court** to prove the content of a writing, recording, or photograph. Under the **U.S. Federal Rules …

Recursion

A classic example of recursion is the factorial [[Function Calls and Returns in Detail|function]]: `n! = n * (n-1)!` If `n` is 1, the function returns 1 ([[Reading Conditional Bra…

Docker Containers

Docker containers isolate applications by packaging code and dependencies together. They share the host OS kernel but run in separate namespaces, a form of isolation relevant to […

Reproducibility

**Reproducibility** is the principle that a forensic process or finding must be capable of being repeated by an independent party, using the same procedures, and yielding the same…

Progressive Change

**Progressive change** is the principle that digital evidence is not static: systems, files, and data continually change through normal use, automated processes, and the passage o…

Objectivity

Objectivity is the discipline of forming conclusions from the evidence rather than selecting evidence to fit a conclusion. ## Explanation In forensic work, ego is the enemy. The…

Lawfulness

**Lawfulness** is the principle that every forensic action — from evidence collection through analysis to presentation — must be carried out under proper legal authority and withi…

Integrity

**Integrity** is the assurance that digital evidence remains complete, accurate, and unaltered from the moment of acquisition through analysis, storage, and presentation in court.…

Evidence Preservation

**Evidence Preservation** is the set of practices used to maintain the original state, integrity, and availability of digital evidence from the moment of collection through its pr…

Defensibility

**Defensibility** is the quality of a forensic process or finding such that it can withstand scrutiny from opposing counsel, technical experts, and the court, because every step t…

Chain Of Custody

**Chain of custody** is the documented, unbroken record of who collected, handled, transferred, and stored a piece of evidence from the moment of acquisition until it is presented…

Installing and Troubleshooting pip and uv

# Installing and Troubleshooting pip and uv Most [[Python Essentials for Security Scripting|Python]] installations ship with `pip`, but it can be missing, outdated, or not on you…

PowerShell Custom Objects

PowerShell is built around **objects** rather than plain text. CmdLets like `Get-Process` return objects with **properties** (data) and **methods** (actions). Objects make it easy…

Select-Object

`Select-Object` is a PowerShell CmdLet that selects or shapes the properties of objects coming through the pipeline. It is commonly used to limit output, pick specific properties,…

PowerShell ForEach-Object CmdLet

`ForEach-Object` is a PowerShell CmdLet that processes each object coming through the pipeline one at a time. It is the standard way to run a script block against every item in a …

PowerShell EventLog CmdLets

PowerShell provides built-in **EventLog cmdlets** for collecting and inspecting Windows event logs. The most commonly used cmdlet is **Get-EventLog**, which retrieves events from …

Debugger Suspend Does Not Kill the Process

In a [[Debugger attach and ASLR rebasing pitfalls|debugger]], **suspend** means pausing the target process, not killing it. The OS scheduler simply stops giving the process CPU ti…

Decoding IDA-Style Argument Offsets

In 32-bit x86 code compiled with a stack-based calling convention [[x86 Calling Conventions: cdecl vs stdcall]] (`cdecl` or `stdcall`), arguments are accessed as positive offsets …

Function Prologue Decomposition Methodology

# Function Prologue Decomposition Methodology When you open an x86 function, do not read line-by-line. Read the **prologue as one block** and answer these five questions before a…

PowerShell Network Configuration CmdLets

This section introduces three PowerShell CmdLets used to examine network settings on a Windows system. Unlike the legacy Windows Command Line, PowerShell exposes network configura…

Hypothesis-Driven Analytical Investigation

In forensic and analytical work, thinking is not enough. You must build a **testable chain** between your ideas and the evidence. ## The core loop 1. **Observe** — Notice someth…

Big-endian vs little-endian byte order

x86 and x86-64 use **little-endian** [[Endianness in x86/x86_64 Memory]]: the least-significant byte of a multi-byte value is stored at the lowest memory address. ## Reading a va…

Endianness and Memory Layout

# Endianness and Memory Layout When a CPU stores a multi-byte integer in memory, it must choose which byte goes at the lowest address. That choice is called **endianness**. ## K…

x86 rand() Calling Convention and Return Value

# x86 `rand()` Calling Convention and Return Value In x86 assembly, the C standard library function `rand()` is called like any other function: ```asm call _rand ``` ## Signatu…

Function Thunks and Stubs

# Function Thunks and Stubs A **thunk** (also called a *stub* or *trampoline*) is a tiny function whose only purpose is to forward execution to another function. It does little o…

Winsock fd_set Structure 0x104 Signature

# Winsock fd_set Structure (0x104 Signature) On 32-bit Windows, the `fd_set` structure from Winsock (`winsock2.h`) is exactly 260 bytes, or `0x104`. That makes `0x104` a useful s…

Debugger attach and ASLR rebasing pitfalls

# Debugger attach and ASLR rebasing pitfalls When attaching a debugger to a live Windows process, the static disassembly addresses shown in tools like [[Binary Ninja]] are usuall…

Extreme Privacy 4th Edition Book Structure

# Extreme Privacy, 4th Edition: Book Structure **Extreme Privacy: What It Takes to Disappear, 4th Edition** (2022) by Michael Bazzell is a practical, end-to-end guide to removing…

Haidt's Six Moral Foundations

# Haidt's Six Moral Foundations Jonathan Haidt's **Moral Foundations Theory** proposes that the human mind is equipped with six innate "moral taste receptors"—psychological syste…

JavaScript fetch with Credentials

Using `fetch` with Credentials in JavaScript When you call an API from JavaScript, the browser's `fetch` API does **not** automatically send cookies or HTTP authentication header…

WebSocket Protocol Security

# WebSocket Protocol Security WebSockets are a **full-duplex, persistent communication channel** built on top of TCP, initiated through an HTTP-compatible upgrade handshake. Once…

Firewall Service Filter

A **Service Filter** in Windows Firewall with Advanced Security is a rule property that limits a firewall rule to traffic associated with a specific Windows service. Instead of ap…

Parsing Binary Formats with Construct

# Parsing Binary Formats with Construct `construct` is a Python library that lets you describe binary file layouts as data structures instead of writing manual `struct.unpack` ca…

How Displays Produce Images

# How Displays Produce Images A display creates the illusion of a continuous image by lighting up a grid of tiny picture elements called **pixels**. Even though a screen looks li…

Defensive Input Handling for Security Scripts

# Defensive Input Handling for Security Scripts Security scripts often process data that comes from untrusted or messy sources: scan output, logs, network traffic, user uploads, …

Counter in Python

# Counter in Python `Counter` is a specialized dictionary class from the `collections` module in Python's standard library. It is designed for **counting hashable objects**. ## …

Python Essentials for Security Scripting

# Python Essentials for Security Scripting A review of core Python syntax, data structures, and file I/O with an emphasis on writing clean, maintainable security scripts for pent…

Maximum Transmission Unit (MTU)

# Maximum Transmission Unit (MTU) The **Maximum Transmission Unit (MTU)** is the largest size (in bytes) of a single protocol data unit that can be transmitted over a network lin…

PowerShell + Python Acquisition Pipeline

# PowerShell + Python Acquisition Pipeline A practical exercise pattern from the book's philosophy: use **PowerShell** for acquiring raw data from Windows systems and **Python** …

PowerShell Replace String in File

PowerShell provides several ways to replace strings inside files using the standard **verb-noun** [[CmdLet]] pairs `Get-Content` and `Set-Content`, plus the `-replace` operator. …

Internet Protocol Suite

# Internet Protocol Suite The **Internet Protocol Suite**, also known as the **TCP/IP protocol suite**, is the collection of protocols used to implement networking functions on t…