My next class:
LINUX Incident Response and Threat HuntingSan DiegoMay 5th - May 10th 2025

Tool update: mac-robber.py

Published: 2025-03-04. Last Updated: 2025-03-04 14:11:14 UTC
by Jim Clausing (Version: 1)
0 comment(s)

Just a quick update. I fixed a big bug in my mac-robber.py script about 2 weeks ago, but realized I hadn't published a diary about it. I didn't go back and figure out how this one slipped in because I'm sure it worked originally, but it was generating bad output for soft/symbolic links. If. you are using the script, please update immediately.

References:

[1] https://github.com/att/docker-forensics/blob/master/mac-robber.py

---------------
Jim Clausing, GIAC GSE #26
jclausing --at-- isc [dot] sans (dot) edu

Keywords: tools
0 comment(s)
My next class:
LINUX Incident Response and Threat HuntingSan DiegoMay 5th - May 10th 2025

Comments


Diary Archives