PowerShell Function Basics and Recursion
## Defining a Function ```powershell function Get-Factorial { param([int]$n) if ($n -le 1) { return 1 } return $n * (Get-Factorial -n ($n - 1)) } Get-Factorial -n 5 …
74 results for “u”
## Defining a Function ```powershell function Get-Factorial { param([int]$n) if ($n -le 1) { return 1 } return $n * (Get-Factorial -n ($n - 1)) } Get-Factorial -n 5 …
# Writing Python Functions and Recursion Basics ## Defining a simple function A function packages reusable logic under a name. You define it with `def`, give it parameters, and …
# WinDbg Patching Arguments at Runtime When a function is about to receive a bad argument (e.g. `NULL` filename passed to `__loaddll`), you can fix the pointer value on [[Stack F…
Active recall is a learning technique that involves actively testing yourself on material rather than passively re-reading. It is closely related to [[Spaced Repetition]] and [[Le…
Spaced repetition is a learning technique where you review information at strategically increasing intervals over time. Instead of cramming, you revisit material just as you're ab…
# Evidence Acquisition Fundamentals Acquisition is the bridge between the *existence* of a digital trace and its *usability* as evidence. It is where the philosophical principles…
This is a test note for debugging wikilink functionality. It contains a link to [[Test Node Beta]]. Created for bug-fixing purposes.
This is a second test note for debugging wikilink functionality. It contains a link back to [[Test Node Alpha]]. Created for bug-fixing purposes.
# Regex Fundamentals A foundational reference for regex syntax, with emphasis on practical application in digital forensics, log analysis, and tooling like [[Burp Suite]]. ## 1.…
# PowerShell as an Acquisition Engine PowerShell is described in Hosmer's book as a powerful **acquisition engine** for digital investigations. Its role is to gather raw informat…
PowerShell is typically preinstalled on modern Windows desktop and server platforms. If it is not present, you can download and install it by searching for **Windows Management Fr…
The opening of *Practical Malware Analysis* presents a cautionary incident-response scenario: a network is breached, antivirus identifies the malware as **TROJ.snapAK**, the respo…
# Malware Analysis **Malware analysis** is the process of dissecting malicious software to understand how it works, how to identify it, and how to defeat or eliminate it. It is a…
The forensic analyst occupies a uniquely privileged position: they have the technical access to discover, preserve, and interpret evidence, but they also have the ability to manip…
In network forensics, the **footprint** is the impact an investigator leaves on the systems under examination. Every interaction with a live system modifies it in some way—just as…
**Direct evidence** is testimony from a **direct witness** who personally observed the act or event in question. It is based on firsthand human perception rather than inference fr…
**Hearsay** is an out-of-court statement offered to prove the truth of the matter asserted. Under the **U.S. Federal Rules of Evidence (FRE)**, hearsay is generally **not admissib…
**Business records** are documents or data that an enterprise routinely generates and retains as part of its normal operations, and that are considered accurate enough to guide ma…
**Network-based digital evidence** is digital evidence produced as a result of **communications over a network**. It is a subset of **[[Digital Evidence]]**, but it is distinguish…
**Real evidence** is a physical, tangible object that played a relevant role in the event being investigated. It is the kind of evidence a jury can see and touch, such as the murd…
Network-based evidence is a subset of [[Digital Evidence]] that comes with its own set of practical and legal headaches. Section [[1.4 Challenges Relating to Network Evidence]] gr…
A **live breach** is an active, ongoing security incident in which an attacker is currently connected to or operating inside a network while the investigative response is underway…
**Encapsulation** and **demultiplexing** are the two complementary processes that move data through the layers of the **[[OSI Model]]**. ### Encapsulation (sender side) When data…
The **TCP three-way handshake** is the process used by the **Transmission Control Protocol (TCP)** to establish a reliable, bidirectional connection between two hosts. It is a fou…
The **OSI model** (Open Systems Interconnection) is a seven-layer framework developed by ISO for designing and understanding network communications. Each layer solves a discrete …
Two instructions look similar in disassembly but do opposite things with memory. | Instruction | What it does | C analogy | |-------------|--------------|-----------| | `mov ecx,…
A **protocol** is a set of formal rules describing how to transmit data, especially across a network. Protocols are: - Rules for successful communication between different system…
[[Circumstantial Evidence]] is evidence that does **not directly prove a conclusion**, but can be linked with other evidence to **deduce** what happened. It requires inference and…
**[[Best Evidence]]** is the **best available evidence that can be produced in court** to prove the content of a writing, recording, or photograph. Under the **U.S. Federal Rules …
A classic example of recursion is the factorial [[Function Calls and Returns in Detail|function]]: `n! = n * (n-1)!` If `n` is 1, the function returns 1 ([[Reading Conditional Bra…
Docker containers isolate applications by packaging code and dependencies together. They share the host OS kernel but run in separate namespaces, a form of isolation relevant to […
**Reproducibility** is the principle that a forensic process or finding must be capable of being repeated by an independent party, using the same procedures, and yielding the same…
**Progressive change** is the principle that digital evidence is not static: systems, files, and data continually change through normal use, automated processes, and the passage o…
Objectivity is the discipline of forming conclusions from the evidence rather than selecting evidence to fit a conclusion. ## Explanation In forensic work, ego is the enemy. The…
**Lawfulness** is the principle that every forensic action — from evidence collection through analysis to presentation — must be carried out under proper legal authority and withi…
**Integrity** is the assurance that digital evidence remains complete, accurate, and unaltered from the moment of acquisition through analysis, storage, and presentation in court.…
**Evidence Preservation** is the set of practices used to maintain the original state, integrity, and availability of digital evidence from the moment of collection through its pr…
**Defensibility** is the quality of a forensic process or finding such that it can withstand scrutiny from opposing counsel, technical experts, and the court, because every step t…
**Chain of custody** is the documented, unbroken record of who collected, handled, transferred, and stored a piece of evidence from the moment of acquisition until it is presented…
Getting code to run is only half of an assignment. The other half is proving that the code satisfies every requirement in the specification. Missing requirements like "write outpu…
# Installing and Troubleshooting pip and uv Most [[Python Essentials for Security Scripting|Python]] installations ship with `pip`, but it can be missing, outdated, or not on you…
PowerShell is built around **objects** rather than plain text. CmdLets like `Get-Process` return objects with **properties** (data) and **methods** (actions). Objects make it easy…
`Select-Object` is a PowerShell CmdLet that selects or shapes the properties of objects coming through the pipeline. It is commonly used to limit output, pick specific properties,…
`ForEach-Object` is a PowerShell CmdLet that processes each object coming through the pipeline one at a time. It is the standard way to run a script block against every item in a …
PowerShell provides built-in **EventLog cmdlets** for collecting and inspecting Windows event logs. The most commonly used cmdlet is **Get-EventLog**, which retrieves events from …
In a [[Debugger attach and ASLR rebasing pitfalls|debugger]], **suspend** means pausing the target process, not killing it. The OS scheduler simply stops giving the process CPU ti…
In 32-bit x86 code compiled with a stack-based calling convention [[x86 Calling Conventions: cdecl vs stdcall]] (`cdecl` or `stdcall`), arguments are accessed as positive offsets …
# Function Prologue Decomposition Methodology When you open an x86 function, do not read line-by-line. Read the **prologue as one block** and answer these five questions before a…
This section introduces three PowerShell CmdLets used to examine network settings on a Windows system. Unlike the legacy Windows Command Line, PowerShell exposes network configura…
In forensic and analytical work, thinking is not enough. You must build a **testable chain** between your ideas and the evidence. ## The core loop 1. **Observe** — Notice someth…
x86 and x86-64 use **little-endian** [[Endianness in x86/x86_64 Memory]]: the least-significant byte of a multi-byte value is stored at the lowest memory address. ## Reading a va…
# Endianness and Memory Layout When a CPU stores a multi-byte integer in memory, it must choose which byte goes at the lowest address. That choice is called **endianness**. ## K…
# x86 `rand()` Calling Convention and Return Value In x86 assembly, the C standard library function `rand()` is called like any other function: ```asm call _rand ``` ## Signatu…
# Function Thunks and Stubs A **thunk** (also called a *stub* or *trampoline*) is a tiny function whose only purpose is to forward execution to another function. It does little o…
# Winsock fd_set Structure (0x104 Signature) On 32-bit Windows, the `fd_set` structure from Winsock (`winsock2.h`) is exactly 260 bytes, or `0x104`. That makes `0x104` a useful s…
# Debugger attach and ASLR rebasing pitfalls When attaching a debugger to a live Windows process, the static disassembly addresses shown in tools like [[Binary Ninja]] are usuall…
# Extreme Privacy, 4th Edition: Book Structure **Extreme Privacy: What It Takes to Disappear, 4th Edition** (2022) by Michael Bazzell is a practical, end-to-end guide to removing…
# Haidt's Six Moral Foundations Jonathan Haidt's **Moral Foundations Theory** proposes that the human mind is equipped with six innate "moral taste receptors"—psychological syste…
Using `fetch` with Credentials in JavaScript When you call an API from JavaScript, the browser's `fetch` API does **not** automatically send cookies or HTTP authentication header…
# WebSocket Protocol Security WebSockets are a **full-duplex, persistent communication channel** built on top of TCP, initiated through an HTTP-compatible upgrade handshake. Once…
A **Service Filter** in Windows Firewall with Advanced Security is a rule property that limits a firewall rule to traffic associated with a specific Windows service. Instead of ap…
# Parsing Binary Formats with Construct `construct` is a Python library that lets you describe binary file layouts as data structures instead of writing manual `struct.unpack` ca…
# Normalization vs Canonicalization in Pentest Input Handling In security tooling, you often compare inputs against a signature database. The attacker controls the input, and you…
# Single Responsibility Principle in Security Scripts The **Single Responsibility Principle** (SRP) says a function or module should have one reason to change — it should do one …
# How Displays Produce Images A display creates the illusion of a continuous image by lighting up a grid of tiny picture elements called **pixels**. Even though a screen looks li…
# Defensive Input Handling for Security Scripts Security scripts often process data that comes from untrusted or messy sources: scan output, logs, network traffic, user uploads, …
# Counter in Python `Counter` is a specialized dictionary class from the `collections` module in Python's standard library. It is designed for **counting hashable objects**. ## …
# Designing Python Scripts for Automation and Pipelines A script is rarely the final destination. In pentest, forensics, and reverse engineering work, Python tools usually feed o…
# Python Syntax Recall and Fluency for Security Work Many learners struggle with Python syntax not because they are "bad at memorizing," but because they are trying to memorize *…
# Python Essentials for Security Scripting A review of core Python syntax, data structures, and file I/O with an emphasis on writing clean, maintainable security scripts for pent…
# Maximum Transmission Unit (MTU) The **Maximum Transmission Unit (MTU)** is the largest size (in bytes) of a single protocol data unit that can be transmitted over a network lin…
# PowerShell + Python Acquisition Pipeline A practical exercise pattern from the book's philosophy: use **PowerShell** for acquiring raw data from Windows systems and **Python** …
PowerShell provides several ways to replace strings inside files using the standard **verb-noun** [[CmdLet]] pairs `Get-Content` and `Set-Content`, plus the `-replace` operator. …
# Internet Protocol Suite The **Internet Protocol Suite**, also known as the **TCP/IP protocol suite**, is the collection of protocols used to implement networking functions on t…