Showing posts with label Learning. Show all posts
Showing posts with label Learning. Show all posts

Monday, May 30, 2016

TRAINING: Windows Security & Forensics

“New” Microsoft Virtual Academy training course spotted.

Topics:

  1. Windows Security and Forensics
    Take a look at the current state of the security landscape, Windows Security, and what "computer forensics" are.
  2. Windows Memory Attacks and Forensics
    Learn how and why hackers attack a system’s memory, and see how Memory Forensics can help address the problem.
  3. Windows Authentication Attacks and Forensics
    See demonstrations of how attackers use credential dependencies to gain elevated access to systems and to perform lateral movement. Plus, learn how to detect and prevent many of these attacks.
  4. Windows Forensics
    Explore Digital Forensics, and find out what to do as a first responder to preserve evidence for legal actions.
  5. Network Forensics
    Explore network forensics, along with case studies, best practices, and online analysis techniques.
  6. Malware Incident Response
    Learn about malware incident response, including identifying, locating, and removing malware.
  7. Windows 10 Forensics
    Take a look at Windows 10 forensics, and hear about new security features and innovations that can help forensic experts with their work.

Learn the following through this course:

  • Examine how and why hackers attack a system’s memory.
  • Identify how attackers use credential dependencies to gain elevated access.
  • Review what to do as a first responder to an attack; learn to preserve evidence for legal actions.
  • Explore network forensics.
  • Learn about innovations of Windows 10 that can help forensic experts do their jobs.
  • Learn the basics of computer forensics.
  • See how to respond to malware incidents.

This won’t instantly make you a professional forensicator it looks to give sysadmins a well-rounded introduction into key topic and foundational approaches when deciding where to begin – if there isn’t already a formal support structure in your organization for these items.

Claus Valca

Saturday, November 28, 2015

Microsoft Training Courses: Networks, AD, & Security

I found these the other day while working on a project at work.

Networking

Networking Fundamentals - Microsoft Virtual Academy

Want to learn network security fundamentals? In this MVA course, discover the building blocks of modern network design and function and prepare for Exam 98-366: Networking Fundamentals, part of an MTA certification. Our online network security training course is free of charge and led by an expert who can help you build your skills and career.

Take this networking fundamentals training, and find out how to put the many pieces together to build a functional and secure network.

Understanding Local Area Networking
In this module you’ll learn about basic concepts and Local Area Networking.

Defining Networks with the OSI Model
This module describes the OSI model and how its layers determine how network traffic is moved and consumed.

Understanding Wired and Wireless Networks
This module covers the basics of wired and wireless media, protocols, standards, and concepts.

Understanding Internet Protocol
In this module you’ll learn about Internet Protocol (IP) and how it makes the internet and modern networks function.

Implementing TCP/IP in the Command Line
This module describes the tools used to manage and troubleshoot networks.

Working with Networking Services
This module describes the services that can be provided and that are required for a network to function.

Understanding Wide Area Networks
In this module you’ll learn about connecting your local area network to other local area networks over large geographic areas and across multiple types of boundaries.

Defining Network Infrastructure and Network Security
This module show you how to appropriately use the tools described in earlier modules to build a functional, secure network.

Recommended Resources and Next Steps for Networking Fundamentals
The information in this module provides you with an opportunity to dive deeper into Networking Fundamentals, at your own pace.

See also Networking Fundamentals - Channel 9

Another version perhaps or same one repackaged?

Introduction to Networking Fundamentals - Microsoft Virtual Academy

Educators, are you looking for a fast-paced and comprehensive introduction to network fundamentals? This on-demand, independent study course is just the ticket. Explore the basics of networking, and get a firm understanding of the underlying concepts. Each of these modules for educators and other learners runs about 30 minutes and covers new concepts, while reinforcing earlier topics. The course includes PowerPoint presentations for use individually or in the classroom.

Taught by educators with attention to the needs of school teachers and students, these courses address Local Area Networks (LANs), network definition using the OSI model, wired and wireless networks, Internet Protocol (IP), TCP/IP in the command line, networking services, wide area networks (WANs), and much more!

See these shorter supplemental videos for networking tips and tricks:

Active Directory

Active Directory Beginners Course - Microsoft Virtual Academy

This course provides students an introduction to Active Directory server roles in Windows Server. The course is intended for entry level students who want to get familiar with the Active Directory server roles and their basic functionality.

Introduction to Active Directory
This module provides an overview of the Active Directory roles available in Windows Server.

Active Directory Domain Services (DS)
This module provides an overview of Active Directory Domain Services in Windows Server.

Active Directory Certificate Services (CS)
This module provides an overview of Active Directory Certificate Services in Windows Server.

Active Directory Federation Services (FS)
This module provides an overview of Active Directory Federation Services in Windows Server.

Active Directory Rights Management Services (RMS)
This module provides an overview of Active Directory Rights Management Services in Windows Server.

Active Directory Lightweight Directory Services (LDS)
This module provides an overview of Active Directory Lightweight Directory Services in Windows Server.

See these supplemental videos for AD tips and tricks:

Security

Security Fundamentals Training Course - Microsoft Virtual Academy

With this Microsoft Technology Associate (MTA) Training course, you can prepare for MTA Exam 98-367. Build an understanding of security layers, operating system security, network security, and security software. The course leverages Microsoft Official Academic Course (MOAC) material for this exam.

Understanding Security Layers
Learn about defense in depth and the various options available for securing resources at the various layers at a high level.

Authentication, Authorization, and Accounting
Get an introduction to the topics of authentication, authorization, and accounting—what they are, how they are different, and how each is implemented and managed. Look at available options and how to use some of the tools in Windows for implementing each one.

Understanding Security Policies
Hear about security policies and how they may work in an organization. See how policies provided by Group Policy can prevent unauthorized access to an organization's resources.

Understanding Network Security
A network can be the most vulnerable part of an IT infrastructure. Learn some of the methods and options for securing these invaluable assets, and gain from a discussion of firewalls, Network Access Protection (NAP), protocols, and wireless networks, from a security standpoint.

Protecting the Server and Client
Learn about protecting the physical assets in your organization, including servers and clients—and the software running on them—and how to secure them.

Security in the Enterprise - Microsoft Virtual Academy

Do you know how cybercriminals work? Get helpful insight, in this cybersecurity course. As an IT Pro, you know that the computer threat landscape is continually changing and that increasingly sophisticated attacks are targeting your organization's infrastructure and confidential information.

Walk with experts through social media platforms to discover how they really work. Get tips and practical advice on social networking security. Plus, explore methods of developing a secure baseline and how to harden your Windows Enterprise architectures and applications from pass-the-hash and other advanced attacks, and look at system patching. Finally, learn how to help improve your organization's security with Microsoft operating systems and tools.

1 | Security Landscape of Today and Tomorrow
Learn about how the computer threat landscape is continually changing and how increasingly sophisticated attacks are targeting your organization’s infrastructure and confidential information.

2 | Social Media Security
In this eye-opening journey, venture into the very heart of social media platforms to discover how they really work. Get tips and practical advice on social networking security.

3 | Advanced Windows Defense
Explore methods of developing a secure baseline and how to harden your Windows Enterprise architectures and applications from pass-the-hash and other advanced attacks.

4 | Free Tools to Protect Your Windows Environment
Learn how Windows Clients are ready to mitigate some of these attacks and how you can utilize your security skills.

5 | Vulnerability and Patch Management
Do you patch your systems? How often? Do you know why you should take action against patching your systems? Find out, in this helpful module.

6 | Top Mitigation Methods to Protect Your Enterprise
Learn how to improve IT security with Microsoft operating systems and tools.

Get learning!

Claus Valca

Sunday, March 15, 2015

Did you overlook any patching last week?

What a crazy, patch-filled couple of weeks it has been!

I’m dizzy.

First there are the Windows patches

Next there are those Adobe patches

Go get ‘em!

And for good measure, sometime recently Oracle released it’s own patches for Java. I didn’t realize I was behind until I checked!

Go get ‘em

Considerations…

Living without plug-ins such as Flash or Java - gHacks Tech News

Two EASY ways to check if you are up to date on your plugins:

Stay patched my friends!

--Claus Valca

Sunday, February 08, 2015

New Software Finds – late edition

Honesty in blog titles here. Most of these finds came in late last month.

Turn ordinary photos into panoramas with Image Composite Editor updates from Microsoft - Next at Microsoft

The interface is seriously updated!

New ICE version 2.0.2 below

image

Old ICE version 1.4.4 below

image

If you do find you pine for the older version 1.4.4 version, Download.com has the older versions still available for now.

More fun tools and utilities

Note, I’ve long been a fan of and used eXpress FreshFiles Finder (XFFF) to accomplish the same thing. However Recent FIle Seeker seems to support some more advanced search options and is a more sophisticated utility.

Cheers,

--Claus Valca

Sunday, September 14, 2014

WinFE LinkFest

It really hurts to get behind in my postings.  Brett Shavers has been running in overdrive mode lately over at the WinFE blog.

In case you have been living under a rock, or just been busy and harried like me, here is a sampling of the exciting news and events over at WinFE blog.

Which was quickly followed by new update posts…

WinFE Course and Free WinFE course, and finally the big announcement Windows Forensic Environment – WinFE Online Course Now Available - WinFE blog

Just in case anyone isn’t clear, the course page is linked below so everyone can find is easily. I’m probably blind this morning but didn’t seem able to find a big/direct course-reference link from the drop-down menu options or displayed prominently on the side-bar.

Note: There are two “preview” course sections you can look at without first having to sign up if you are curious.

WinFE blog points to this course review by Ken Pryor at the Digital Forensics Blog if you are curious on what to expect before signing up: Windows Forensic Environment Training Course Review

And a review of these posts should bring pretty current one current on the WinFE world.

Kudos to Brett Shavers and all the hard work he is doing for the community!

Cheers,

--Claus Valca

Sunday, August 10, 2014

I’m sure there is a better way to accomplish this…

In my GSD blog post Anti-Malware Response "Go Kit" I outlined a variety of tool-sets and standalone tools that I carry on my USB flash drive for dealing with malware responses on friends/family systems.

Keeping the IR tool-sets (Confessor, MIR-ROR, rapier, TR3 Tool Kit v2, and triage-ir) updated is a lower priority for a number of reasons.

  1. It’s a lot of work,
  2. the developers often require (due to licensing) the end user (me and you) to download the supporting binaries directly from the developers’ sites, and
  3. you always run the risk that a later utility update may break the way the scripts run on the package.

None of those are deal-breakers, but because of that, keeping those updated (aside from the main IR package) leads me to not update them as frequently, maybe once a quarter to biannually.

The ones that I do update frequently are the ones that are used to to sweeps for malware and/or viruses.

Most of these are signature based, and if they are updated, there there is a high likelihood a scan with an older tool may miss something critical!

So to keep them updated, I have a bookmark folder with URL links to all the tools. I then go down the list, click, download, copy to USB, rinse and repeat.

So yesterday I wondered if I could automate the process a bit. Kind of like a poor-man’s version of NirLauncher or KLS SOFT’s WSCC - Windows System Control Center.

I’m sure there is a better way to do this, but this was my “it works for me” result.  I’m not posting the actual files (at least in fullness for now) but will show you the basics so you can build your own if you want.

First, I considered (and may still go to) a process/script that uses Wget for Windows - GnuWin32.

But I wanted to start with what I knew (or thought I did) for now.

To get the ball rolling, I made a “landing zone” folder on my Windows system at C:\TEMP\AMW_Packages

This is where I wanted to download the updated files into. I wanted to keep it separate in case I decided I didn’t want to end up overwriting any of my previous files. So once all the packages are downloaded here, I will manually copy them over onto my USB drive folder where they reside full-time.

I then created a Windows BAT file called “a-AMW_Package downloader.bat”

It does a few things.

It deletes all the files/folders in the “C:\TEMP\AMW_Packages” location to get a clean start.

It then runs down a list of the utilities I need to get/update, and downloads them into the “C:\TEMP\AMW_Packages” folder using PowerShell. (I know! Cool!)

Then, there are some packages that have some fancy dynamic page tricks/EULA’s that make getting those binary files a bit of a hassle. Some of those I was able to work around with the PowerShell commands below. However others were not so cooperative. And that was OK.

So at the end of the BAT file, it calls a custom EXE called “a-BAT-IECall.exe”.  That file was a different PowerShell script block I came up with to open up all those “problem” site URL’s in a single Internet Explorer window session, each in a different tab; more on it in a bit.

The resulting automatically opened IE window allows me to review/download those “manually” as needed.  (I guess I could put it at the front so I could be manually downloading those as the script continues to run in the background. But this made sense to me. I also dropped some FYI URL pages as well there to remind me of some tricks I keep forgetting or to see if any new tools are available that I may want to add to my tool-kit.

Here is an abbreviated version of the BAT file “a-AMW_Package downloader.bat” contents. You should be able to get the gist of what I am doing and add more lines for other resources you may want/need.

:: Anti-Malware Response “Go-Kit” Downloader

:: Clean Up Download folder first

set folder="C:\Temp\AMW_Packages"
cd /d %folder%
for /F "delims=" %%i in ('dir /b') do (rmdir "%%i" /s/q || del "%%i" /s/q)

:: Now Let's Get the Files!

:: Process Explorer
powershell -Command "(New-Object Net.WebClient).DownloadFile('
http://download.sysinternals.com/files/ProcessExplorer.zip', 'ProcessExplorer.zip')"
powershell -Command "Invoke-WebRequest
http://download.sysinternals.com/files/ProcessExplorer.zip -OutFile C:\temp\AMW_Packages\ProcessExplorer.zip"

:: AutoRuns
powershell -Command "(New-Object Net.WebClient).DownloadFile('
http://download.sysinternals.com/files/Autoruns.zip', 'Autoruns.zip')"
powershell -Command "Invoke-WebRequest
http://download.sysinternals.com/files/Autoruns.zip -OutFile C:\temp\AMW_Packages\Autoruns.zip"

:: Microsoft Safety Scanner & Malicious Software Removal Tool  (+ download others manually in a bit)
powershell -Command "(New-Object Net.WebClient).DownloadFile('
http://go.microsoft.com/fwlink/?LinkId=212732', 'msert.exe')"
powershell -Command "Invoke-WebRequest
http://go.microsoft.com/fwlink/?LinkId=212732 -OutFile C:\temp\AMW_Packages\msert.exe"

::And so on, and so forth for all the other tools as needed

:: Trend Micro Anti-Threat Toolkit  (download manually in a bit)
:: VIPRE Rescue (download manually in a bit)
:: AdwCleaner (download manually in a bit)
:: ComboFix (download manually in a bit)
:: Rootkit Buster - x86 - Trend Micro  (download manually in a bit)
:: System Explorer (download manually in a bit)

:: Misc Tools and Utilities (Now we fire up IE via a PowerShell script) so we can launch IE and the link URLs in tabs for manual download if we need them.

a-BAT-IECall.exe

Exit

Just add more of those download lines for all the tools you need as long as the URL download links are functional with this method.

So next, about that “a-BAT-IECall.exe”

This took a bit of creative work to generate.  There are other ways to launch IE in a standard BAT file, but it ended up opening each URL in a separate IE window that cluttered up my system, despite my best attempts. So this way worked perfectly, and because: PowerShell!

The PowerShell script that is the heart of the engine looks like this:

$ie = New-Object -ComObject InternetExplorer.Application
$ie.Navigate2("
http://systemexplorer.net/download.php")
$ie.Navigate2("http://www.vipreantivirus.com/live/",0x1000)
$ie.Navigate2("https://toolslib.net/downloads/viewdownload/1-adwcleaner/",0x1000)
$ie.Navigate2("http://www.bleepingcomputer.com/download/combofix/",0x1000)
$ie.Navigate2("http://www.bleepingcomputer.com/forums/t/403413/cannot-execute-exe-reg-regedit/",0x1000)
$ie.Navigate2("http://free.antivirus.com/us/rootkit-buster/index.html",0x1000)
$ie.Navigate2("http://www.microsoft.com/security/scanner/en-us/default.aspx",0x1000)
$ie.Navigate2("http://www.microsoft.com/en-us/download/malicious-software-removal-tool-details.aspx",0x1000)
$ie.Navigate2("http://windows.microsoft.com/en-us/windows/what-is-windows-defender-offline",0x1000)
$ie.Navigate2("http://esupport.trendmicro.com/solution/en-us/1059509.aspx",0x1000)
$ie.Navigate2("http://support.kaspersky.com/viruses/utility",0x1000)
$ie.Navigate2("http://firesage.com/mbrwizard.php?x=4x",0x1000)
$ie.Navigate2("http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html",0x1000)
$ie.Navigate2("http://www.bleepingcomputer.com/download/rkill/",0x1000)
$ie.Navigate2("http://www.bleepingcomputer.com/download/unhide/",0x1000)
$ie.Navigate2("http://www.bleepingcomputer.com/download/windows/security-utilities/",0x1000)
$ie.Navigate2("http://support.microsoft.com/kb/299357",0x1000)
$ie.Visible = $true
stop-process $PID
#

Add/remove/change URLs accordingly.

To create the EXE version for this PowerShell script to include the call to in your main BAT file:

  1. Edit the PowerShell script block above to add/change/remove any URLs
  2. Save it somewhere for quick future re-editing.
  3. Launch the PowerGUI Script Editor.
  4. Create a new workspace tab.
  5. Copy those lines into it.
  6. From the menu bar select “Tools” then “Compile Script…”
  7. Select where you want to save it...should be same place as the “a-AMW_Package downloader.bat” BAT file…and what name you want to give it, for me I used “a-BAT-IECall.exe”
  8. I left the Target framework set at “Microsoft .NET Framework 4.0” for my system.
  9. I guess you could give it a cool custom icon if you wanted. I didn’t for now.
  10. Select “OK” and let it build!
  11. Close stuff out when done.
  12. Find/test! (see result below)

3kq2ba2q.oox

Now, when I want to update my IR package tools, I just fire off the main BAT file and away it rips, leaving me to manually download just a few packages myself -- if desired -- from IE.

Misc Notes and references.

I wasn’t aware until composing this post that the PowerGUI project appears to have been taken over by Dell: Welcome to the New Home of PowerGUI. OK.

I’m sure there are WAY BETTER ways to deal with this with Wget, PowerShell, BAT files, but this works and I learned a lot in the process. I’m open to recommendations/suggestions.

The PowerShell commands in the BAT file are pretty flexible.

powershell -Command "(New-Object Net.WebClient).DownloadFile('URL-path-for-binary.file', 'binary.file’)"
powershell -Command "Invoke-WebRequest
URL-path-for-binary-file -OutFile C:\temp\AMW_Packages\binary.file"

This one is straight forward with the pattern:

:: AutoRuns
powershell -Command "(New-Object Net.WebClient).DownloadFile('
http://download.sysinternals.com/files/Autoruns.zip', 'Autoruns.zip')"
powershell -Command "Invoke-WebRequest
http://download.sysinternals.com/files/Autoruns.zip -OutFile C:\temp\AMW_Packages\Autoruns.zip"

I was able to make changes to some of the “binary.file” names to change the name as it got saved, and in some cases the URL path didn’t actually contain a binary.file name in the path but it still handled it OK. Once you have the format down you can experiment a bit. See below for one example:

:: Microsoft Safety Scanner & Malicious Software Removal Tool  (+ download others manually in a bit)
powershell -Command "(New-Object Net.WebClient).DownloadFile('
http://go.microsoft.com/fwlink/?LinkId=212732', 'msert.exe')"
powershell -Command "Invoke-WebRequest
http://go.microsoft.com/fwlink/?LinkId=212732 -OutFile C:\temp\AMW_Packages\msert.exe"

Here are the URL’s of many of the sites/tips I reviewed to get me to this stage, and a few that I wanted to do but couldn’t quite get to work like I wished.

Again, any tips, tricks or alternative suggestions would be appreciated!

Cheers!

--Claus V.

P.S. Microsoft has a number of tools for scanning/removing malware from a system.

Microsoft Malicious Software Removal Tool - This is on most all Windows systems as the MRT.EXE file. Type “MRT.exe” in the RUN bar and you will be off to the races (assuming Windows Updates are current, otherwise download the file manually above or effectiveness will be diminished.)

Then there is the heavy-duty version Microsoft Safety Scanner which gets updated every 10 days.

And, in my original post I mentioned the Microsoft Standalone System Sweeper from Microsoft that was available only via the Microsoft Connect site unless you went through a third-part download source. See this Utility Spotlight: Repair Your PC Infection from TechNet Magazine to get more info on it.

Working on the URL/Download location for this one led me to discover the Windows Defender Offline tool that may have replaced (?) the Microsoft Standalone System Sweeper.  This one is for most “modern” versions of Windows but if you are running Windows 8.1 you will need to jump to this Windows Defender Offline Beta build page.

--cv

Saturday, August 02, 2014

Bargain Basement SysAdmin Link Sale!

It’s that time of the year again for Claus to unload all of the pending Sysadmin-related links that he’s been collecting.

Bear with me here…some of these are older than others and this is more of a link-dump then those posts that come with more commentary.

Think of it more like a “pop-up” edition without the actual pop-ups.

Actual SysAdmin Stuff

TinyApps bloggist recently thought I might be interested in a sysadmin-related site called System Administration Screencasts.

Indeed I was!  Though it mostly follows a *nix bent, there is lots of great material here. Most all of it is screen casting, however in most episodes a transcript can be found.  I’m working my way through these right now:

I really encourage you to also check out the About page as there are some great “recommended reading” links as well.

I’m particularly curious about The Visible Ops Handbook: Implementing ITIL in 4 Practical and Auditable Steps book to see if it can enhance the ITIL trainings I’ve already been to.

That also reminded me of this giant list of RSS feeds that the Standalone Sysadmin posts (with a OPML file for fast snagging) that TinyApps also shared with me in the past.

Oh, and one of my favorite miscellaneous sysadmin sites is the MoonPoint Support Weblog. I frequently find troubleshooting tidbits that are valuable. I also finally found the RSS feed for that weblog so now I can follow the postings much more easily.

Daniel Miessler’s blog is another of those sites that is a balance of tech, troubleshooting, and ponderings on deeper life stuff. I really appreciate all he posts and look forward to his frequent and new postings.

Mostly Microsoft & Active Directory Stuff

AD Info - Active Directory Reporting Tool - Ckwdev - free/$ versions - recently bumped to v 1.7.9. There are lots of other tools there as well but some of the most helpful might be AD Permissions Reporter, AD Info, and AD Tidy. Check out the software link for more info on those and many more.

Those reminded me of the Sysinternals tool AD Explorer which I love and use almost daily.  It hasn’t been updated since November 2012 but I guess it still does the job perfectly.

Weekend Scripter: Non-PowerShell Books for PowerShell People - Hey, Scripting Guy! Blog

New PowerShell Scripting Tools Released - The Deployment Guys

Windows PowerShell 4.0 Book and Guides from Microsoft - The Windows Club

Download Windows PowerShell 4.0 and Other Quick Reference Guides - Microsoft Download Center

Download Windows Management Framework 4.0 - Microsoft Download Center

Microsoft's USGCB Tech Blog - Aaron Margosis blogs here occasionally.

Utility and Software - New and Updated

Updates: Autoruns v12.0, Procdump v7.0 - Sysinternals Site Discussion

Updates: AccessChk v5.2; PsExec v2.11; Sigcheck v2.1; VMMap v3.12 - Sysinternals Site Discussion

PassMark MemTest86 - $/free versions updated to 5.1.0 back in May (hat-tip to RMPrepUSB, Easy2Boot and USB booting)

Svchost Process Analyzer - Neuber software - free tool to check out the svchost.exe loaded processes. No install needed.

Moo0 File Monitor 1.11 - Moo0 software - interesting tool to monitor file access activities on your system. Spotted via this AddictiveTips blog post.  Note it  reminds me a bit of this great NirSoft tool FolderChangesView.

CCEnhancer 4.0 - SingularLabs - This one got some pretty big feature updates recently.

ImDisk Virtual Disk Driver - Version 1.8.4 released July 2014.  See also this project: ImDisk Toolkit - reboot.pro

dErase - Foolish IT LLC - free tool (now at v2.0) that does file/folder deletions with secure optional secure delete routines.  Ignores file system ownership/permissions when executing so use carefully! 

dBug - Foolish IT LLC - interesting tool to use when dealing with malware impacted systems. Basically it removes auto-start items and exe runs from know problem locations. This should allow killing of malware auto-loads which may prevent effective system cleaning. Once remediated, the tool can be re-run then puts the changes back in place.

Windows Troubleshooting Tools and Tips

Case of the Office Hang on Launch - chentiangemalc

Using Process Monitor (procmon) to Analyze Windows File Share Access (by Paul Offord) - LoveMyTool blog

Guide to Freeing up Disk Space under Windows 8.1 - Scott Hanselman

Fix .NET 4.5/ 4.5.1 issues with Microsoft .NET Framework Repair Tool 1.2 - BetaNews

Download Debug Diagnostic Tool v2 Update 1 - Microsoft Download Center

Download Debug Diagnostic Tool from Microsoft - The Windows Club (info)

VirtMemTest: a utility to exercise memory and other operations - Aaron Margosis' Non-Admin, App-Compat and Sysinternals WebLog

Offline-Update: Get WSUS Content .NET Version 2.7 - Borns IT- und Windows-Blog (original language) and Google Translated link - This was a new “offline update” tool that I recently read about. You may want to see if the feature set it offers is better for your needs than other tools such as WSUS Offline Update (still my favorite), WHDownloader, Portable Update, or Windows Updates Downloader (WUD).

Install Windows 8.1 from a USB stick with WinSetupFromUSB - 4sysops

The 12 step process to download Microsoft SQL Server Express 2014 - istartedsomething

Download SQL Server Express - Scott Hanselman

Download Visual Studio Express - Scott Hanselman

Booting Windows8.1ToGo from a USB Flash drive - RMPrepUSB, Easy2Boot and USB booting...:

Windows Performance Monitor Overview - Ask the Performance Team

Available for pre-order: Windows Performance Analysis Field Guide - Clint Huffman's Windows Troubleshooting in the Field Blog

Email Stuff

Mailviewer Opens Old Outlook, Thunderbird, and Windows Live Emails - Lifehacker

Mail Viewer - MiTeC homepage

PST Viewer - Kernel Data Recovery

OST Viewer - Kernel Data Recovery

Web-related Stuff

Advanced Gmail Filters to Manage Your Email Messages - Digital Inspiration

Browser plugin to highlight and copy text from any image - Tinyapps.org points us to the fun Project Naptha

For Internet Explorer 11 users, no update now means no security fixes - Ars Technica

Determining the default browser from the command line - MoonPoint Support Weblog

Moving from GoDaddy to DNSimple – an illustrated journey - Troy Hunt amuses and entertains again.

I Know Where Your Cat Lives - Project page - Scary - More project information here.

Enough lest we break the Interwebs…

Cheers!

--Claus Valca

Wednesday, June 04, 2014

TechEd in Houston Texas; and other troubleshooting bits

Microsoft TechEd North America 2014 rolled though Houston, Texas last month.

I didn’t have the opportunity to attend, but thankfully, Microsoft’s Channel 9 had the event well-covered.

Almost every presentation or session has an online video and/or slide-deck material for your review.

I’ve picked out a handful of ones that I found particularly interesting considering my IT focuses and am listing them here for future reference and playback.

Enjoy!

  • TechEd North America 2014 - Channel 9 main-page coverage of the Houston Texas event.
  • TechEd North America 2014 - Listing of all available presentations and sessions - Channel 9 - five very-long web-pages of items to pick through!
  • Defrag Tools: Live - TechEd 2014 - Mark Russinovich (~25 min) - Defrag Tools | Channel 9 - Mark spend some time highlighting updates to a selection of the Sysinternals tools.
  • TWC: Sysinternals Primer: TechEd 2014 Edition (~1 hr) - Channel 9 - Aaron Margosis presents tutorials on advanced usage of some of the core Sysinternals tools.
  • Case of the Unexplained: Troubleshooting with Mark Russinovich (~1 hr 20 min) - Channel 9 - Mark does his standard outstanding presentation on how to deep-dive into troubleshooting unusual Windows issues.
  • TWC: Bulletproofing Your Network Security (~1 hr 20 min) - Channel 9 - “This session demonstrates the best tools and techniques to harden your devices—from your laptop, to your cell phone, to your servers and your services.”
  • The State of Windows 8.1 Security: Malware Resistance (~1 hr 15 min) - Channel 9 - “Windows 8.1 offers an enormous leap forward when it comes to security, and when it comes to malware resistance that couldn’t be more true. … In this session we drill into the details of the malware threats that you’re facing and then show you how you can help your organization and users enjoy a malware free experience on Windows.”
  • Windows 8.1: Black Belt Troubleshooting (~1 hr 15 min) - Channel 9 - New tips and tricks in troubleshooting Windows 8.1
  • Windows 8 Security Internals (~1 hr 15 min) - Channel 9 - “Windows 8 extends the security and isolation capabilities of Windows to help build a far more trusted application experience. In this session, get a review of the Windows features that have been evolving since Windows Vista, and culminating in a whole new level of application isolation in Windows 8 Applications.”
  • TWC: Social Engineering: Manipulations, Targeted Attacks, and IT Security (~1 hr 15 min) - Channel 9 - “…explore how social engineering has grown over time and examine lessons learned from the field on how to best mitigate those traps.”
  • TWC: Pass-the-Hash: How Attackers Spread and How to Stop Them (~1 hr 15 min) - Channel 9 - “…deconstruct the PtH threat, show how the attack is performed, and how it can be addressed using new features and functionality recently introduced in Windows.”
  • JitJea: A Windows PowerShell Toolkit to Secure a Post-Snowden World (~1 hr 15 min) - Channel 9 - “It is a Windows PowerShell toolkit that you can use to “man up and defend yourselves” by allowing admins to perform functions without giving them admin privileges.”
  • Windows Performance Deep Dive Troubleshooting (~1 hr 10 min) - Channel 9 - “Join us for a deep dive on the free Windows Performance Toolkit (WPT), Windows Assessment Services (WAS) part of the Assessment and Deployment Toolkit (ADK), developed to help you troubleshoot and resolve these issues. Download the toolkit, and get ready to tackle performance issues that can impact organizations of all sizes running Windows Vista, Windows 7, and Windows 8.”

Not appearing at TechEd Houston, but very good presentations in line with the above topics.

--Claus Valca

Saturday, May 31, 2014

Lavie Struggles with Dreamweaver CS 5.5

One of Lavie’s new job duties in the land of re-employment is to maintain the website of her employer.

They use Dreamweaver CS 5.5 as their page development software.

So now that it is Lavie’s job, they had her enroll in an on-line Dreamweaver CS 5.5 continuing education class through the local community college. Great!

Only you really can’t buy Dreamweaver CS 5.5 any longer (well maybe you can but the pricing is either crazy high or questionably low) and the only installed copy was on another staff member’s system (who couldn’t leave for the few hours every few days Lavie would need to work on it) and the install disks have gone AWOL.

I was able to find a legitimate 30-day trial download for CS 5.5 available buried deep in the Adobe FTP site’s archives. That (and a VM) were able to get Lavie though the class successfully.

However, that is not a valid long-term solution. So unless the original CS 5.5 install disks turn up at her workplace allowing for the transfer of the license/software from the current worker’s system to Lavie’s, then we may have an issue.  There is no desire on anyone’s part to purchase the latest subscription based CS version model to just get Dreamweaver.

So I started looking for a Dreamweaver alternative that might closely match the foundational learning that Lavie has gone through.

I found two.

Microsoft Expression Web 4 (Free Version) - Official Microsoft Download Center - This product is 100% (just no support) and while professional web page developers have some valid points about the way it handles certain page-coding methods, as long as you know the basics of page code to clean things up to your liking, it seems to be a pretty good alternative. Lavie things the application workspace can be tweaked to appear very similar to the layout she became accustomed to in Dreamweaver.

openElement - Web Design & Authoring Software - The interface for this product is radically different from Dreamweaver and Microsoft Expression Web. However, it is being actively updated and once you get your project going, the interface becomes very navigable. Lavie actually liked the way this one seemed to operate over the more familiar Dreamweaver when she looked at it.

These other web articles provide some additional background on the above applications, as well as other alternatives that might meet other needs better.

Of course, all of these WYSWYG web page editors are no replacement for familiarity with web page code itself. There are lots of great resources to hone your skills. Here a just a few I myself find helpful.

Cheers.

--Claus Valca

Sunday, October 20, 2013

Forensic News Flashes - New Projects and learning opportunities galore!

It’s late and has been a super-long weekend.

Lavie isn’t too impressed I’m still sitting at my desk working on posts.

In the meantime, I’m commited to getting this last bit of ForSec linkage collected over the past few weeks out the door so you can have fun reviewing it this week.

Those young and crazy pups over at the Computer & Digital Forensics at Champlain program have clearly caught their dean napping. In an interesting series of posts, they attempt to wreak havoc on different hard-drives and then try to put humpty-dumpty back together again.

MantaRay Forensics - anTech Triage & Analysis System. As far as I can tell, this is the first time I have posted any mention of MantaRay Forensics here at GSD.  Spotted in this C&DF@C post Swimming with MantaRay Forensics

MantaRay was designed to automate processing forensic images, directories and individual files with open source tools. With support for numerous image formats, this tool provides a scalable base to utilize open source and custom exploitation tools. MantaRay was developed by two forensic analysts, Doug Koster and Kevin Murphy.

ForGe Forensic test image generator v1.1 - Git Hub project page. from the Overview description:

ForGe is a tool designed to build computer forensic test images. It was done as a MSc project for the University of Westminster. Its main features include:

  • Web browser user interface
  • Rapid batch image creation (only NTFS supported)
  • Possibility to define a scenario including trivial and hidden items on images
  • Variance between images. For example, if ForGe was told to put 10-20 picture files to a directory /holiday and create 10 images, all these images would have random pictures pulled from repository.
  • Variance in timestamps. Each trivial and hidden file can be timestamped to a specific time. Each scenario is given a time variance parameter in weeks. If this is set to 0, every image receives an identical timeline. If nonzero, a random amount of weeks up to the maximum set is added to each file on each image
  • Can modify timestamps to simulate certain disk actions (move, copy, rename, delete)
  • Implements several data hiding methods: Alternate data streams, extension change, file deletion, concatenation of files and file slack space.
  • New data hiding methods can be easily implemented. Adding a new file system is also documented.

Developer Hannu Visti goes shares a great post over the features and background of this tool over at Forensic Focus. ForGe – Computer Forensic Test Image Generator.  This could be a really fresh and innovative tool to help with both simulating forensic images for training and drill purposes. Very interesting and well worth the time to check out. It’s beyond my skill set to review and comment on but if any of the ForSec pros out there have any thoughts or comments, please feel free to drop them in the comments here for our community education.

Linkz 4 Free Infosec and IT Training - Journey Into Incident Response - Corey Harrell goes above and beyond with an outstanding listing of trainings, exercises, and learning resources that are ForSec focused and absolutely-friggin-free for the taking!  Corey promises to keep the listing updated so bookmark the page and check back often. I’m particularly interested in the CSIRT-like topics and materials listed like those in the ENISA CERT linkage. I’ve downloaded most all of the PDF versions already to review this week as time allows!

Many of these trainings have supplemental videos and VM’s for download too!

Other specific courses from Corey’s post I’m listing below so I can find them quickly…

What 'tier 2' & 'tier 3' tools do you load on your forensic workstation(s)? - ForensicKB blog - Lance Mueller has a great list of Tier 2 and Tier 3 apps he considers. I’m pleased to find more than a few in my toolkit already. Note that not all of the software listed here is necessarily free or open-source. More than a few are commercial applications. That’s not at all a bad thing, but just something to be aware of.

 Windows Incident Response: Shell Item Artifacts, Reloaded - Harlan Carvey undertakes some very methodical validation exercises on Windows shell item artifacts. Definitely worth reading.

Meanwhile, from another ForSec guy who appears to never sleep… Brett Shavers has been in a posing frenzy over at his Windows Forensic Environment blog site.

Best publicly available testing of WinFE I’ve seen to date - Windows Forensic Environment (Note post info is good but link in it has been superseded by one found in post below.

Updated link on the Mistype project - Windows Forensic Environment

WinFE - direct link to the article mentioned. I agree, it is a truly fascinating read for WinFE aficionados. I’m coming back to read this one carefully this week.

Mini-WinFE - Windows Forensic Environment - This post has tons and tons of screenshots to illustrate the new Mini-WinFE project as well as an introduction that goes over the project features. Very basically, this specific project (1 of 3 promised for alternative WinFE building) allows you to roll your own WinFE boot disk in a “minimal” configuration with FAU utilities, FTK Imager and support for X-Ways Forensics. Total build time is estimated at 10 minutes from start to media in your hand.

Mini-WinFE is out of beta! - Windows Forensic Environment - See you waited too long! The first link was requesting Beta testers. Now it is released!  Direct project link here via Reboot.pro and extensive Mini-WinFE project documentation from Misty is linked here.

Quick video on building a Mini-WinFE - Windows Forensic Environment - a very short (3:33 min) YouTube video is available on this post page for those who want to check out the building process.

Since we are on a WinFE bender, let’s shift gears slightly and use that excuse to post a link on the WinFE’s kissable cousin for sysadmins who aren’t quite as focused on disk read-only preservation, WinPE.

How to Customize Windows PE Boot Images to Use in Configuration Manager - Chris Nackers Blog. Chris links to this Microsoft TechNet resource How to Customize Windows PE Boot Images to Use in Configuration Manager

New website and project roadmap - DEFT Linux - Computer Forensics live CD - The DEFT development team has put some fresh paint on their website as well as outlined where they plan to head in the coming months. Congratulations to DEFTA President Stefano Fratepietro and all the community and project contributors who have worked hard to make DEFT Linux a premiere Forensic live CD resource! From that post..

Here follows the forthcoming milestones concerning the new versions of DEFT 8, Virtual Appliance and User Manual.

  • DEFT Linux 8.1 with relevant news for Mobile Forensics – November 2013
  • DEFT 8 VMware Virtual Appliance – late November 2013
  • Roadmap of projects supported by donations – December 2013
  • DEFT 8 User Manual – February 2014
  • Third Italian National Conference DEFTCON 2014  – Polytechnic of Milano, April 11, 2014

Installing VMware Tools on Kali Linux and Some Debugging Basics - SpiderLabs Anterior - Christophe De La Fuente goes to the mat to show some advanced debugging skills in getting VMware Tools onto Kali Linux. As is pointed out in the comments, there are easier ways to do it, but the experience shared of the road taken makes us all a bit wiser. Which this post then led me to discover and add to my RSS feed pile…

Computer Howto's by Lewis Encarnacion - Lewis’s posts are great. Covering not just Windows 7 topics, but also some of the finer points in using and getting comfortable in Kali Linux.

FAU -version 1.3.0.2464 - Speaking of the Forensic Acquisition Utilities (FAU) it seems a new version came out in August 2013. I don’t think I caught that release. The link has a “what’s new” jump as well as the new binary set download link but for the lazy…from that source:

  • Volume_dump and DD now recognize drives with BusTypeSata as devices supporting the ATA feature set.  ATA specific attributes are reported for these drives.
  • Fixed a problem with the DD --verify option when writing an image to certain to certain drives.  Under certain circumstances the DD --verify option reported a spurious failure even though the reimaging of the target drive succeeded and the cryptographic checksum of the destination drive was in fact identical to the cryptographic checksum source image file or drive.  This problem did not affect the accuracy of the reimaged drive but required that the user to validate the target drive after the imaging process was complete.  Thanks to Suman Beros for reporting this problem.
  • When acquiring a physical drive DD now drops the block size down to the device block size when approaching the putative end of the source drive.  Hard drives often misreport their capacity either by over estimating or under estimating the true size.  The only reliable way to image a hard drive is to attempt to acquire beyond the purported end of the drive and see if valid data is returned.  However, we have encountered a few drives that freeze or hang the imaging process if you attempt to read beyond the end of the drive with a block size that is greater than the device block size.  Needless to say, this can be disconcerting when you have already read 1 TiB of data only to have the whole process hang on the last few sectors.  Dropping down to the device block size when approaching the end of a drive should produce more reliable acquisitions.  A disadvantage is that drive acquisition will be slower at the end of the drive.
  • Examples have been added to the DD help text which show how to acquire a physical drive.

That’s all for tonight!

Cheers my friends.

Claus Valca

In the SysAdmin Lounge

Tips, trainings and warnings for the sysadmins in IT.

Starting on December 1st, Universities that license Office Education for their faculty and staff can offer students Office 365 ProPlus for free thanks to a new program called Student Advantage. For students at these institutions, that means free access to Word, PowerPoint, Excel, OneNote, Outlook, Access, Publisher, and Lync. While many cheaper alternatives to Office have sprung up, many students still rely on Redmond’s good ol’ productivity tools.

Microsoft’s Virtual Academy has published a training course specifically for SysInternals Tools, including Process Explorer, ProcessMonitor, PS Tools, PsTools, Autoruns, etc.

Microsoft Premier Field Engineers step through a technical deep dive on utilizing SysInternals tools. This course focuses on key administrative and diagnostic utilities and addresses key insights, and best practices.

Cheers

Claus Valca

Sunday, July 28, 2013

SysAdmin Linkfest - Chock'-o’-Videos Edition (G-rated version)

This is a super-heavy linkpost filled to the rim with video presentation linkages. Make sure you have some extra time and bandwidth set aside for all these.

Seriously. You think I’m joking, but all it takes is one sysadm running around careless with streaming video file links and then “bam” someone ends up loosing their bandwidth.

As tempting as it is, I’m just providing the links to the video rather than embeds of the video in a player itself. Not that Mark and the Defrag Tool guys aren’t handsome or anything, its more because I just hate seeing the Flash SWP pre-load in everyone’s web-browser when I then get behind in posting and you fans are hit with it when you land on a GSD blog page with embedded video and you aren’t using a Flash-blocking plugin, or have it disabled for my blog.

w1fil0k5.j3p

(the evidence as seen in Process Explorer as happened back from April 2013 - late June 2013 )

General philosophy: wipe the baby and keep it, toss the diapers

Why wiping decommissioned IT assets should be a must - Help Net Security - Duh.

The cost of cleaning up - ISC Diary

GrandStreamDreams blog has written heavily regarding securely wiping hard drives. It should be a no-brainer in today’s digital age…and coupled with some whole disk encryption (to boot). Likewise I just can’t grasp how it is cheaper to trash 170 PC’s because they were infected rather than having a secure-wipe/standard-image reload process. Don’t skip the ISC Diary article’s Comments section.

Sysinternals/Pass the Hash TechEd North America talks

Sysinternals - and Pass the Hash - at TechEd next week- Aaron Margosis' "Non-Admin" and App-Compat WebLog - These were five keynote talks back from June. In case you couldn’t stop by New Orleans last month, you got some serious catching up to do now!

The Case of…

Case of the Slow Logon – Anti-Virus vs 3rd Party Application - chentiangemalc

Case of the Windows 8 Explorer Hang – Part 1 - chentiangemalc

Defrag Tools takes on Windows Performance Toolkit

You may recall the GSD blog post Case of the Unexplained Donut of Death where I started out using Windows 7 Xperf tool to do some performance troubleshooting. I then jumped from it to the new WPT set in Windows 8 SDK and outlined just how amazing the level of logging detail and analysis was.

Windows Perfmance Analyzer SDK 8

As the time there was not a considerable amount of documentation out for us mere mortals on how leverage the true power the tools contained.

No more. The team at Channel 9 has hit the ground hard with a series of videos going into the details on the tool and its features. I suspect more will come. Now I can really start figuring out what all those indicators shown above really mean!

Offline Windows Updating

WSUS Offline Update - I have been a longtime fan of this tool, updated a few days ago to version 8.5. I never leave my cubicle to respond to a system or re-image/deployment without it on my USB stick. It is the #1 tool I know of to help conserve bandwidth and minimize impact at a site where we are doing a deployment. It remains highly Valca recommended! If you are a Windows PC deployment tech or analyst and you don’t have this tool, you either have some super-big circuits, an internal WSUS server, or you can swagger like Beckham and just don’t care.

Portable Update - This “bravo-ware” tool is new to me. Like WSUS Offline Updater, once built you can use it to redeploy Windows/MS patches to a target system. The process seems considerably different that USUS-OU but it may work better for your needs. I’m hoping to test it soon and have a better side-by-side experience to compare them against. For more information on the tool check out the application’s How to use page as well as this AddictiveTips post: Apply Windows Update To Multiple PCs From A USB Drive While Offline.

SysAdmin Tips

Run any app under the NT Authority\Local System account - TinyApps.org - Comparison between ETS (Elevate To System) tool (it has an optional GUI) and psexec.exe from Sysinternals.

FREE: Get Local Admins GUI – Find users with administrator rights - 4sysops

How To Make UEFI Bootable USB Flash Drive to Install Windows 8 - Next of Windows

Making a better, somewhat prettier, but definitely more functional Windows Command Line - Scott Hanselman’s ComputerZen blog

How To Quickly Unlock Local Administrator Account in Windows 8 - Next of Windows

Finally a Windows Task Manager Performance tab blog! - Ask the Performance Team

SysAdmin Utility & Software Leads

Updates: Mark's TechEd Sessions, Autoruns v11.61, Strings v2.52, ZoomIt v4.5 - Sysinternals Site Discussion

Updates: Autoruns v11.6, Procexp v15.31, Procmon v3.05, Sigcheck v1.92 - Sysinternals Site Discussion

Update: Autoruns v11.62 - Sysinternals Site Discussion

Free Windows virtual machines for Mac, Linux, or Windows - TinyApps.org blog - Official developer virtual machine files for XP, Vista, WIn7 and Win 8. These are really for Internet Explorer developers but are great for other software testing purposes. Even more details here: Making Internet Explorer Testing Easier with new IE VMs - Rey Bango.  Main VM’s download link here.

CopyToFlash - Foolish IT - This could be really dangerous. REALLY dangerous. Like most stuff over at Foolish IT. However it could just be dead-helpful for the right audience and application. Basically it just starts a drive monitoring process and then (with a few configuration actions) will copy the contents of a monitored source folder location to any USB flash drive that attaches to the system. Yeah. Dangerous but helpful if you are responsible for updating new content to tons of USB sticks. Oh, did you know it uses RoboCopy? Yep.

Office 2010 Service Pack 2 Released…(mostly)

Just in time after a major Office 2010 rollout at our coal-mine. Nice timing guys…

Microsoft delivers Office 2010 Service Pack 2 - ZDNet - Mary Jo Foley

Office 2010 and SharePoint 2010 Service Pack 2 Availability - Office Sustained Engineering Blog

Description of Office 2010 SP2 - Microsoft Support

How to obtain and install the service pack

Method 1: Microsoft Update (recommended)

Note In addition to the products in the Office 2010 suite, the service pack 2687455 also updates Microsoft Project 2010, Microsoft Visio 2010, and Microsoft SharePoint Designer 2010.

To download the service pack from Microsoft Update, go to the following Microsoft website:

Microsoft Update

You can opt in a computer to the Microsoft Update service, and then register that service with the Automatic updates to receive the SP2 update. Microsoft Update will detect which products that you have installed, and then apply all updates to the products.

Method 2: Download the SP2 package from Microsoft Download Center

The following files are available for download from the Microsoft Download Center:

For more information about how to download Microsoft support files, click the following article number to view the article in the Microsoft Knowledge Base:

119591 How to obtain Microsoft support files from online services

Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help prevent any unauthorized changes to the file.

For more information about a complete list of all released SP2 desktop packages, click the following article number to view the article in the Microsoft Knowledge Base:

2687521 List of all Office 2010 SP2 packages

Cheers,

Claus Valca