eBPF rootkits & forensics: from blinding telemetry to memory detection
How an eBPF rootkit bypasses kernel lockdown to blind Linux telemetry, and a memory detection method with Volatility 3 linking processes, maps and eBPF programs.
How an eBPF rootkit bypasses kernel lockdown to blind Linux telemetry, and a memory detection method with Volatility 3 linking processes, maps and eBPF programs.
Why modelling security data as graphs improves DFIR and threat hunting, with examples based on Zeek, Neo4j, BloodHound and JACG.
How to scale forensic investigations with Dissect, Logstash and ELK to extract, centralise and search artefacts across multiple machines.
DFIR analysis of an Active Directory PCAP with Zeek to reconstruct initial access, SMB/RDP lateral movement and DPAPI-related activity.
Introduction to network DFIR on an Active Directory PCAP with Zeek and JupyterLab to prepare the investigation, inspect logs and build first pivots.
Walkthrough of an RPC backdoor in a Microsoft environment, covering DCE/RPC internals, malicious interface implementation and network/host detection.
Step-by-step guide to building an Active Directory lab with Ludus on Proxmox, including templates, VLAN networking and a Kali VM.
Introduction to NobisD, a technical blog about cybersecurity, labs, Active Directory, DFIR and practical learning.