Skip to main content

Posts

Showing posts from September, 2026

How to activate Nessus professional in offline mode on windows platform

 In this blog, we will see how we can activate Nessus professional in windows platform but in offline mode.  Offline mode means there will be no internet access on that server where Nessus will be installed.  Here are the key steps: You need Nessus professional license key. Two systems. System A where internet access will be provided. System B where no internet access will be there. And in this System B, Nessus will be installed.  Download Nessus .msi package from their official website from System A and take it to the system B. Install Nessus professional on System B. Once the installation is over, a webpage will automatically be opened and suggest you to click on connect via SSL. Click there.  Once initialization is done, check the Register Offline check box and click on Continue.  Select Nessus Professional and click on continue.  Now you will be given a challenge code. You need to go to the offline registration site from system A and paste that ...

Rapid malware execution investigation via velociraptor, excel

 We will be using velociraptor and excel to find out malware execution on the system by differential analysis.  Context = Any true positive alert you get or you were targeted by a sophisticated advanced persistent threat. We need actionable intelligence to pivot more. Workflow : Following the below two links, collect the build the collector and collect the artifacts first from the fresh system and the infected system.  https://mahimfiroj.blogspot.com/2026/09/windows-rapid-triage-with-velociraptor.html https://github.com/secure-cake/win-mal-investigations (Preferred)  Reference file : SLIDES_Windows-Malware-Investigations-02082024.pdf (Saved on my ovi.it88 google drive) Here we also have some important script that will be helpful during IR. https://github.com/secure-cake/win-mal-investigations/tree/main/misc-powershell Once collection is done, now we need to follow the following workflow again from the 4th point: In this case the artifacts does not require parsing. H...

Windows rapid triage with velociraptor and kape

 During malware incidents or any cyber attack, we need to first triage the system to collect useful artifacts so that it can help in our analysis greatly.  The main link I followed: https://github.com/secure-cake/rapid-endpoint-investigations/wiki/REI-Wiki-Part-1:-Intro We will use velociraptor to collect artifacts and kape tool to parse those artifacts.  Let's first ready the tools. Download velociraptor from the below link: Velociraptor (download): https://docs.velociraptor.app/downloads/ Now register, download kape from the below link and save here C:\Tools\KAPE https://www.kroll.com/en/insights/publications/cyber/kroll-artifact-parser-extractor-kape Once the kape is installed, now we need to download some executables and put it in this folder  KAPE\Modules\bin NirSoft BrowsingHistoryView: https://www.nirsoft.net/utils/browsing_history_view.html (SAVE TO: ..KAPE\modules\bin\browsinghistoryview.exe NirSoft Browser Downloads View: https://www.nirsoft.net/utils/web_...

Linux rapid triage using velociraptor (offline collector - Linux IR)

Linux rapid triage using velociraptor offline collector with catscale  Today we will see how we can collect linux artifacts using velociraptor offline collector during malware incidents. For reference: https://github.com/secure-cake/malware-investigations/wiki/Velociraptor-Offline-Collector-with-CatScale-for-Linux Catscale will use linux living of the land tools to collect artifacts.  Step 1: Download the velociraptor from the below link on your analyst windows system: https://docs.velociraptor.app/downloads/ Step 2: Now we need to launch PowerShell or command prompt to execute the velociraptor gui by the following command. .\velociraptor-v0.XX.X-windows-amd64.exe gui  Step 3: In this step we will first import the catscale VR artifacts then select other artifacts. Here we have multiple steps. 1. From the VR welcome page, click on " Import Extra Artifacts ". 2. On the next dialogue box, follow below image instruction.  Remove all except Artifact Exchange and The Tria...