SlideShare a Scribd company logo
1 of 30
Presentation on Sumuri
December 2016 Presentation
Hello & Welcome
Tony Godfrey is the CEO / Linux Consultant of
Falconer Technologies (est 2003) specializing in Linux.
He has written several articles on the body of knowledge
of security administration, is a regular contributor to a
variety of Linux publications, and has written technical
content for Linux education nation-wide at the college
level.
He also teaches topics covering Linux, Network
Security, Cisco routers, Cybercrime and System
Forensics.
Who is Sumuri?
Sumuri
Software
Recon – for Mac OSX
Paladin - 64-bit (more tools)
Edge - 32-bit (only disk imaging)
Carbon – Virtual Forensics Site (coming soon)
Udemy
Udemy
There is a difference
Sumuri is basing their Open Source on Ubuntu, so
apt-get/etc works really well if you need something
additional.
Edge – is only for 32-bit, is a basic-working Ubuntu
distro, and only has disk imaging as its main point.
Paladin – is for 64-bit, full functioning Ubuntu distro,
and 84 built-in forensics tools.
Basic Views
Basic Views
Basic Views
What’s in the box, Pandora?
What’s in the box, Pandora?
Antivirus Tools
ClamAV
Carving Tools
Bulk Extractor, Foremost, Photorec, Scalpel, Testdisk
Database Tools
SQLite database browser
What’s in the box, Pandora?
Development Tools
Active Python, Eric python IDE
Excryption Tools
FileVaultInfo, FileVaultMount, VeraCrypt
File Differential Tools
KDiff3, VBinDiff
What’s in the box, Pandora?
Forensic Suite
Autopsy3, DFF
DFF (Digital Forensics Framework) is a free and Open
Source computer forensics software built on top of a
dedicated Application Programming Interface (API).
dff -h
dff-gui
What’s in the box, Pandora?
Hardware Analysis
Hardinfo / hardinfo -r / hardinfo -r > pcinfo.txt
Hashing Tools
HashCash, MD5Deep, Quickhash
Hex Editor
Bless Hex Editor, GHex
What’s in the box, Pandora?
Internet Analysis
Pasco
An Internet Explorer activity forensic analysis tool.
./pasco index.dat > index.txt
Log Analysis
WindowsEventLogExport, WindowsEventLogInfo
WindowsXMLEventLogExport,WindowsXMLEventLogInf
o
What’s in the box, Pandora?
Mail Analysis
EML Viewer, Readdbx, Readoe, ReadPST
Malware Analysis
YARA
YARA is a tool aimed at (but not limited to) helping
malware researchers to identify and classify malware
samples. With YARA you can create descriptions of
malware families (or whatever you want to describe)
based on textual or binary patterns.
What’s in the box, Pandora?
Memory Analysis
Inception
Inception is a physical memory manipulation and
hacking tool exploiting PCI-based DMA. The tool can
attack over FireWire, Thunderbolt, ExpressCard, PC
Card and any other PCI/PCIe interfaces
What’s in the box, Pandora?
Memory Analysis
Rekall Console
http://www.rekall-forensic.com/
Rekall is the most complete Memory Analysis
framework. Rekall provides an end-to-end solution to
incident responders and forensic analysts
Rekall Web Console
What’s in the box, Pandora?
Messenger Forensics
Skype Extractor - offers a direct way to view
conversations by listed contacts with timestamps and
chat details
Metadata Analysis
Exif Tool (pictures), try  exiftool –h
exiftool <x>.jpg
LinkEditor - Rifiuti
What’s in the box, Pandora?
Mobile Device Analysis
iDeviceBackup, iDeviceBackup2, iDeviceDate,
iDevice_ID, iDeviceInfo, iDeviceName
Ipddump, iPhone Analyzer
Network Analysis
Wireshark
What’s in the box, Pandora?
Password Discovery
JTR Password Cracker, Ophcrack
Plist Analysis
Plist Analysis
Reporting Tools
RecordMyDesktop
What’s in the box, Pandora?
Social Media Analysis
Creepy
Allows users to gather already published and made
publicly available geolocation information from a number
of social networking platforms and image hosting
services
What’s in the box, Pandora?
Stegnography Tools
Outguess
Timeline Analysis
log2timeline
Virtual Machines
QtEmu, VirtualBox
Windows Registry
Fred, RegRipper
You mean….there’s more?
Say it ain’t so….Maresware Tools, anyone?
Maresware?
Maresware Tools (http://www.dmares.com/)
Bates_No, Copy_Ads, Date_Conv, Decimal_to_ip
DiskCat, EML Process, Hash64, HashCmp, HaskDup
Mak_HTML, MD5, MD5 Verify, Mdir, RMS, Search String
SSN Valid, Total, UpCopy, URL Search, Verticle
VSS, X-Ways Meta Processing
Presentation on Sumuri
Contact Info
TonyGodfrey@FalconerTechnologies.com
(216) 282-4TUX / (216) 282-4889
www.FalconerTechnologies.com
'Release your inner Penguin'
falconer-sumuri

More Related Content

Viewers also liked

First-Time Mom? 9 Trends To Know About Labor And Postpartum Care
First-Time Mom? 9 Trends To Know About Labor And Postpartum CareFirst-Time Mom? 9 Trends To Know About Labor And Postpartum Care
First-Time Mom? 9 Trends To Know About Labor And Postpartum CareMountainStar Health
 
Surrey Vacuum Repairs
Surrey Vacuum RepairsSurrey Vacuum Repairs
Surrey Vacuum RepairsRoyAHansen
 
Gsm сигнализация Sapsan
Gsm сигнализация SapsanGsm сигнализация Sapsan
Gsm сигнализация SapsanMikhail Galeichenko
 
Guest Lecture - UX Design in Jakamo, Timo Rossi 14 February 2017
Guest Lecture - UX Design in Jakamo, Timo Rossi 14 February 2017Guest Lecture - UX Design in Jakamo, Timo Rossi 14 February 2017
Guest Lecture - UX Design in Jakamo, Timo Rossi 14 February 2017Jakamo
 
Работа в КУРСКХЕЛП
Работа в КУРСКХЕЛПРабота в КУРСКХЕЛП
Работа в КУРСКХЕЛПMikhail Galeichenko
 
Sponsorbrochure A.S.R. Nereus
Sponsorbrochure A.S.R. NereusSponsorbrochure A.S.R. Nereus
Sponsorbrochure A.S.R. NereusElwin van Rooijen
 
What happened to Television?
What happened to Television? What happened to Television?
What happened to Television? karimgordon
 
Gravació del programa “El Gran Dictat”.
 Gravació del programa “El Gran Dictat”. Gravació del programa “El Gran Dictat”.
Gravació del programa “El Gran Dictat”.infoescolapiesfigueres
 
Sarina Homes. Our Values: the #culturecode
Sarina Homes. Our Values: the #culturecodeSarina Homes. Our Values: the #culturecode
Sarina Homes. Our Values: the #culturecodekamcampb
 
Презентация проекта
Презентация проекта Презентация проекта
Презентация проекта Mikhail Galeichenko
 
Hearthunters by ISG Finland Oy - outplacement-ohjelma, jota on vaikea nokittaa
Hearthunters by ISG Finland Oy - outplacement-ohjelma, jota on vaikea nokittaaHearthunters by ISG Finland Oy - outplacement-ohjelma, jota on vaikea nokittaa
Hearthunters by ISG Finland Oy - outplacement-ohjelma, jota on vaikea nokittaaPrepsikka Oy
 
Pastoral. Sant Josep de Calassanç 2016
Pastoral. Sant Josep de Calassanç 2016Pastoral. Sant Josep de Calassanç 2016
Pastoral. Sant Josep de Calassanç 2016infoescolapiesfigueres
 
Введение в КУРСКХЕЛП
Введение в КУРСКХЕЛПВведение в КУРСКХЕЛП
Введение в КУРСКХЕЛПMikhail Galeichenko
 

Viewers also liked (20)

First-Time Mom? 9 Trends To Know About Labor And Postpartum Care
First-Time Mom? 9 Trends To Know About Labor And Postpartum CareFirst-Time Mom? 9 Trends To Know About Labor And Postpartum Care
First-Time Mom? 9 Trends To Know About Labor And Postpartum Care
 
Surrey Vacuum Repairs
Surrey Vacuum RepairsSurrey Vacuum Repairs
Surrey Vacuum Repairs
 
Final Oral PPP
Final Oral PPPFinal Oral PPP
Final Oral PPP
 
Gsm сигнализация Sapsan
Gsm сигнализация SapsanGsm сигнализация Sapsan
Gsm сигнализация Sapsan
 
Capitulo4
Capitulo4Capitulo4
Capitulo4
 
Guest Lecture - UX Design in Jakamo, Timo Rossi 14 February 2017
Guest Lecture - UX Design in Jakamo, Timo Rossi 14 February 2017Guest Lecture - UX Design in Jakamo, Timo Rossi 14 February 2017
Guest Lecture - UX Design in Jakamo, Timo Rossi 14 February 2017
 
P-5. Sortida a Serinyà.
P-5. Sortida a Serinyà.P-5. Sortida a Serinyà.
P-5. Sortida a Serinyà.
 
Работа в КУРСКХЕЛП
Работа в КУРСКХЕЛПРабота в КУРСКХЕЛП
Работа в КУРСКХЕЛП
 
Sponsorbrochure A.S.R. Nereus
Sponsorbrochure A.S.R. NereusSponsorbrochure A.S.R. Nereus
Sponsorbrochure A.S.R. Nereus
 
What happened to Television?
What happened to Television? What happened to Television?
What happened to Television?
 
Gravació del programa “El Gran Dictat”.
 Gravació del programa “El Gran Dictat”. Gravació del programa “El Gran Dictat”.
Gravació del programa “El Gran Dictat”.
 
Sarina Homes. Our Values: the #culturecode
Sarina Homes. Our Values: the #culturecodeSarina Homes. Our Values: the #culturecode
Sarina Homes. Our Values: the #culturecode
 
Презентация проекта
Презентация проекта Презентация проекта
Презентация проекта
 
Hearthunters by ISG Finland Oy - outplacement-ohjelma, jota on vaikea nokittaa
Hearthunters by ISG Finland Oy - outplacement-ohjelma, jota on vaikea nokittaaHearthunters by ISG Finland Oy - outplacement-ohjelma, jota on vaikea nokittaa
Hearthunters by ISG Finland Oy - outplacement-ohjelma, jota on vaikea nokittaa
 
Pastoral. Sant Josep de Calassanç 2016
Pastoral. Sant Josep de Calassanç 2016Pastoral. Sant Josep de Calassanç 2016
Pastoral. Sant Josep de Calassanç 2016
 
Propiedades del color
Propiedades del colorPropiedades del color
Propiedades del color
 
Reunió de famílies 2015 2016
Reunió de famílies 2015 2016Reunió de famílies 2015 2016
Reunió de famílies 2015 2016
 
Введение в КУРСКХЕЛП
Введение в КУРСКХЕЛПВведение в КУРСКХЕЛП
Введение в КУРСКХЕЛП
 
教育改革の大きなうねり
教育改革の大きなうねり教育改革の大きなうねり
教育改革の大きなうねり
 
大学ポートレートの活用のために勉強会
大学ポートレートの活用のために勉強会大学ポートレートの活用のために勉強会
大学ポートレートの活用のために勉強会
 

Similar to falconer-sumuri

Bsides Tampa Blue Team’s tool dump.
Bsides Tampa Blue Team’s tool dump.Bsides Tampa Blue Team’s tool dump.
Bsides Tampa Blue Team’s tool dump.Alexander Kot
 
Linux/Unix Night - (PEN) Testing Toolkits (English)
Linux/Unix Night - (PEN) Testing Toolkits (English)Linux/Unix Night - (PEN) Testing Toolkits (English)
Linux/Unix Night - (PEN) Testing Toolkits (English)Jelmer de Reus
 
Staying Safe - Overview of FREE Encryption Tools
Staying Safe - Overview of FREE Encryption ToolsStaying Safe - Overview of FREE Encryption Tools
Staying Safe - Overview of FREE Encryption ToolsMicky Metts
 
Tsunami of Technologies. Are we prepared?
Tsunami of Technologies. Are we prepared?Tsunami of Technologies. Are we prepared?
Tsunami of Technologies. Are we prepared?msyukor
 
Two-For-One Talk: Malware Analysis for Everyone
Two-For-One Talk: Malware Analysis for EveryoneTwo-For-One Talk: Malware Analysis for Everyone
Two-For-One Talk: Malware Analysis for EveryonePaul Melson
 
"Viruses Exploits Rootkits the Dilemma of a Linux Product Manager" by Alexand...
"Viruses Exploits Rootkits the Dilemma of a Linux Product Manager" by Alexand..."Viruses Exploits Rootkits the Dilemma of a Linux Product Manager" by Alexand...
"Viruses Exploits Rootkits the Dilemma of a Linux Product Manager" by Alexand...eLiberatica
 
BackTrack5 - Linux
BackTrack5 - LinuxBackTrack5 - Linux
BackTrack5 - Linuxmariuszantal
 
Open Source Forensics
Open Source ForensicsOpen Source Forensics
Open Source ForensicsCTIN
 
Cte I Computer Basics
Cte I    Computer BasicsCte I    Computer Basics
Cte I Computer Basicskpankajgujar
 

Similar to falconer-sumuri (20)

Understand study
Understand studyUnderstand study
Understand study
 
Bsides Tampa Blue Team’s tool dump.
Bsides Tampa Blue Team’s tool dump.Bsides Tampa Blue Team’s tool dump.
Bsides Tampa Blue Team’s tool dump.
 
Nullbyte 6ed. 2019
Nullbyte 6ed. 2019Nullbyte 6ed. 2019
Nullbyte 6ed. 2019
 
Linux/Unix Night - (PEN) Testing Toolkits (English)
Linux/Unix Night - (PEN) Testing Toolkits (English)Linux/Unix Night - (PEN) Testing Toolkits (English)
Linux/Unix Night - (PEN) Testing Toolkits (English)
 
Sectools
SectoolsSectools
Sectools
 
aaa
aaaaaa
aaa
 
Staying Safe - Overview of FREE Encryption Tools
Staying Safe - Overview of FREE Encryption ToolsStaying Safe - Overview of FREE Encryption Tools
Staying Safe - Overview of FREE Encryption Tools
 
Tsunami of Technologies. Are we prepared?
Tsunami of Technologies. Are we prepared?Tsunami of Technologies. Are we prepared?
Tsunami of Technologies. Are we prepared?
 
Two-For-One Talk: Malware Analysis for Everyone
Two-For-One Talk: Malware Analysis for EveryoneTwo-For-One Talk: Malware Analysis for Everyone
Two-For-One Talk: Malware Analysis for Everyone
 
Assingment 5 - ENSA
Assingment 5 - ENSAAssingment 5 - ENSA
Assingment 5 - ENSA
 
"Viruses Exploits Rootkits the Dilemma of a Linux Product Manager" by Alexand...
"Viruses Exploits Rootkits the Dilemma of a Linux Product Manager" by Alexand..."Viruses Exploits Rootkits the Dilemma of a Linux Product Manager" by Alexand...
"Viruses Exploits Rootkits the Dilemma of a Linux Product Manager" by Alexand...
 
BackTrack5 - Linux
BackTrack5 - LinuxBackTrack5 - Linux
BackTrack5 - Linux
 
Open Source Forensics
Open Source ForensicsOpen Source Forensics
Open Source Forensics
 
Deft v7
Deft v7Deft v7
Deft v7
 
Cutting out Malware
Cutting out MalwareCutting out Malware
Cutting out Malware
 
Backtrack
BacktrackBacktrack
Backtrack
 
Cte I Computer Basics
Cte I    Computer BasicsCte I    Computer Basics
Cte I Computer Basics
 
CTE Computer Basics
CTE    Computer BasicsCTE    Computer Basics
CTE Computer Basics
 
Hakin9 05 2013
Hakin9 05 2013Hakin9 05 2013
Hakin9 05 2013
 
File000173
File000173File000173
File000173
 

falconer-sumuri

  • 2. Hello & Welcome Tony Godfrey is the CEO / Linux Consultant of Falconer Technologies (est 2003) specializing in Linux. He has written several articles on the body of knowledge of security administration, is a regular contributor to a variety of Linux publications, and has written technical content for Linux education nation-wide at the college level. He also teaches topics covering Linux, Network Security, Cisco routers, Cybercrime and System Forensics.
  • 5. Software Recon – for Mac OSX Paladin - 64-bit (more tools) Edge - 32-bit (only disk imaging) Carbon – Virtual Forensics Site (coming soon)
  • 8. There is a difference Sumuri is basing their Open Source on Ubuntu, so apt-get/etc works really well if you need something additional. Edge – is only for 32-bit, is a basic-working Ubuntu distro, and only has disk imaging as its main point. Paladin – is for 64-bit, full functioning Ubuntu distro, and 84 built-in forensics tools.
  • 12. What’s in the box, Pandora?
  • 13. What’s in the box, Pandora? Antivirus Tools ClamAV Carving Tools Bulk Extractor, Foremost, Photorec, Scalpel, Testdisk Database Tools SQLite database browser
  • 14. What’s in the box, Pandora? Development Tools Active Python, Eric python IDE Excryption Tools FileVaultInfo, FileVaultMount, VeraCrypt File Differential Tools KDiff3, VBinDiff
  • 15. What’s in the box, Pandora? Forensic Suite Autopsy3, DFF DFF (Digital Forensics Framework) is a free and Open Source computer forensics software built on top of a dedicated Application Programming Interface (API). dff -h dff-gui
  • 16. What’s in the box, Pandora? Hardware Analysis Hardinfo / hardinfo -r / hardinfo -r > pcinfo.txt Hashing Tools HashCash, MD5Deep, Quickhash Hex Editor Bless Hex Editor, GHex
  • 17. What’s in the box, Pandora? Internet Analysis Pasco An Internet Explorer activity forensic analysis tool. ./pasco index.dat > index.txt Log Analysis WindowsEventLogExport, WindowsEventLogInfo WindowsXMLEventLogExport,WindowsXMLEventLogInf o
  • 18. What’s in the box, Pandora? Mail Analysis EML Viewer, Readdbx, Readoe, ReadPST Malware Analysis YARA YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns.
  • 19. What’s in the box, Pandora? Memory Analysis Inception Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard, PC Card and any other PCI/PCIe interfaces
  • 20. What’s in the box, Pandora? Memory Analysis Rekall Console http://www.rekall-forensic.com/ Rekall is the most complete Memory Analysis framework. Rekall provides an end-to-end solution to incident responders and forensic analysts Rekall Web Console
  • 21. What’s in the box, Pandora? Messenger Forensics Skype Extractor - offers a direct way to view conversations by listed contacts with timestamps and chat details Metadata Analysis Exif Tool (pictures), try  exiftool –h exiftool <x>.jpg LinkEditor - Rifiuti
  • 22. What’s in the box, Pandora? Mobile Device Analysis iDeviceBackup, iDeviceBackup2, iDeviceDate, iDevice_ID, iDeviceInfo, iDeviceName Ipddump, iPhone Analyzer Network Analysis Wireshark
  • 23. What’s in the box, Pandora? Password Discovery JTR Password Cracker, Ophcrack Plist Analysis Plist Analysis Reporting Tools RecordMyDesktop
  • 24. What’s in the box, Pandora? Social Media Analysis Creepy Allows users to gather already published and made publicly available geolocation information from a number of social networking platforms and image hosting services
  • 25. What’s in the box, Pandora? Stegnography Tools Outguess Timeline Analysis log2timeline Virtual Machines QtEmu, VirtualBox Windows Registry Fred, RegRipper
  • 26. You mean….there’s more? Say it ain’t so….Maresware Tools, anyone?
  • 27. Maresware? Maresware Tools (http://www.dmares.com/) Bates_No, Copy_Ads, Date_Conv, Decimal_to_ip DiskCat, EML Process, Hash64, HashCmp, HaskDup Mak_HTML, MD5, MD5 Verify, Mdir, RMS, Search String SSN Valid, Total, UpCopy, URL Search, Verticle VSS, X-Ways Meta Processing
  • 29. Contact Info TonyGodfrey@FalconerTechnologies.com (216) 282-4TUX / (216) 282-4889 www.FalconerTechnologies.com 'Release your inner Penguin'