PowerShell Network Configuration CmdLets
This section introduces three PowerShell CmdLets used to examine network settings on a Windows system. Unlike the legacy Windows Command Line, PowerShell exposes network configura…
All notes
100 notesThis section introduces three PowerShell CmdLets used to examine network settings on a Windows system. Unlike the legacy Windows Command Line, PowerShell exposes network configura…
# Baseline in Digital Forensics A **baseline** is a captured snapshot of a system's normal state under known-good conditions. It records what processes, services, network connect…
In forensic and analytical work, thinking is not enough. You must build a **testable chain** between your ideas and the evidence. ## The core loop 1. **Observe** — Notice someth…
# Address Types in Reverse Engineering When analyzing a binary you will see several different address spaces. The same byte can be described by each of them depending on which to…
x86 and x86-64 use **little-endian** [[Endianness in x86/x86_64 Memory]]: the least-significant byte of a multi-byte value is stored at the lowest memory address. ## Reading a va…
# Endianness in x86/x86_64 Memory **[[Endianness and Memory Layout|Endianness]]** describes the order in which the bytes of a multi-byte value are stored in memory. ## Little-en…
# Endianness and Memory Layout When a CPU stores a multi-byte integer in memory, it must choose which byte goes at the lowest address. That choice is called **endianness**. ## K…
# x86 `rand()` Calling Convention and Return Value In x86 assembly, the C standard library function `rand()` is called like any other function: ```asm call _rand ``` ## Signatu…
# WinDbg Stack Inspection Commands Use these commands to inspect values that have been pushed onto the stack, especially right before a function call. ## Core command ```windbg…
# Function Thunks and Stubs A **thunk** (also called a *stub* or *trampoline*) is a tiny function whose only purpose is to forward execution to another function. It does little o…
# WinDbg Hardware Breakpoints (`ba`) `ba` sets a **hardware breakpoint** that triggers on **memory access** rather than execution. ## `ba` vs `bp` | Command | Type | Fires when…
# Winsock fd_set Structure (0x104 Signature) On 32-bit Windows, the `fd_set` structure from Winsock (`winsock2.h`) is exactly 260 bytes, or `0x104`. That makes `0x104` a useful s…
# WinDbg Commands for Live Binary Analysis Essential commands used to inspect buffers, catch encryption, and trace function behavior in WinDbg during disassembly/reverse engineer…
# x86 Calling Conventions: cdecl vs stdcall A **calling convention** is the contract between a caller and a callee that answers two questions: 1. How are arguments passed? 2. Wh…
# Debugger attach and ASLR rebasing pitfalls When attaching a debugger to a live Windows process, the static disassembly addresses shown in tools like [[Binary Ninja]] are usuall…
# Adversarial deception and data poisoning as active defense Instead of only detecting or blocking AI-driven attacks, defenders can actively mislead attacker tooling by feeding i…
# Convergent vs Divergent Thinking in DFIR These two thinking modes are the mental engine behind every good investigation. ## Divergent thinking Cast a wide net. You do not know…
# Extreme Privacy, 4th Edition: Book Structure **Extreme Privacy: What It Takes to Disappear, 4th Edition** (2022) by Michael Bazzell is a practical, end-to-end guide to removing…
# C2 Server vs Persisted Shell A **C2 (command-and-control) server** and a **persisted shell** are related but distinct concepts in offensive security. ## C2 Server A C2 server…
# Haidt's Six Moral Foundations Jonathan Haidt's **Moral Foundations Theory** proposes that the human mind is equipped with six innate "moral taste receptors"—psychological syste…