Tool update: mac-robber.py

    Published: 2025-03-04. Last Updated: 2025-03-04 14:11:14 UTC
    by Jim Clausing (Version: 1)
    0 comment(s)

    Just a quick update. I fixed a big bug in my mac-robber.py script about 2 weeks ago, but realized I hadn't published a diary about it. I didn't go back and figure out how this one slipped in because I'm sure it worked originally, but it was generating bad output for soft/symbolic links. If. you are using the script, please update immediately.

    References:

    [1] https://github.com/att/docker-forensics/blob/master/mac-robber.py

    ---------------
    Jim Clausing, GIAC GSE #26
    jclausing --at-- isc [dot] sans (dot) edu

    Keywords: tools
    0 comment(s)
    ISC Stormcast For Tuesday, March 4th, 2025 https://isc.sans.edu/podcastdetail/9348

      Comments


      Diary Archives