<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://forensicitguy.github.io/my-sans-dfir-netwars-experience/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/making-meterpreter-look-google-signed/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/adding-process-hiding-to-merlin/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/whitelisting-ld-preload-for-fun-and-no-profit/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/when-local-password-resets-arent-local/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/exploiting-yum-dnf-plugins-persistence/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/linux-edr-evasion-meterpreter-ld-preload/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/how-qbot-uses-esentutl/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/analyzing-empire-macos-pkg-stager/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/extracting-sfx-installer/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/rich-header-hashes-with-pefile/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/smarter-not-harder-malware-analysis/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/analyzing-log4shell-muhstik/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/analyzing-icedid-document/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/analyzing-magnitude-magniber-appx/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/a-tale-of-two-dropper-scripts/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/extracting-indicators-from-packed-mirai/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/adventures-in-yara-hashing-entropy/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/decoding-webshell-using-nodejs/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/powerpoint-macros-olevba/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/inspecting-powershell-cobalt-strike-beacon/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/analyzing-cactustorch-hta-cobaltstrike/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/emotet-excel4-macro-analysis/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/extracting-payloads-excel-dna-xlls/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/bazariso-analysis-advpack/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/hcrypt-injecting-bitrat-analysis/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/guloader-executing-shellcode-callbacks/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/strrat-attached-to-msi/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/njrat-installed-from-msi/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/agenttesla-rtf-dotnet-tradecraft/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/xloader-formbook-velvetsweatshop-spreadsheet/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/analyzing-stealer-msi-using-msitools/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/aggah-ppam-renamed-mshta/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/formbook-via-vbs-powershell-and-csharp/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/agenttesla-vba-certutil-download/</loc>
<lastmod>2022-03-28T23:09:20+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/snip3-crypter-dcrat-vbs/</loc>
<lastmod>2022-04-16T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/shortcut-to-emotet-ttp-change/</loc>
<lastmod>2022-04-24T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/analyzing-pirrit-adware-installer/</loc>
<lastmod>2022-05-13T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/analyzing-net-core-single-file-ducktail/</loc>
<lastmod>2022-08-07T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/pecheck-malware-weight-loss/</loc>
<lastmod>2022-10-15T20:53:49+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/malware-weight-loss-fast-foremost/</loc>
<lastmod>2022-10-22T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/net-downloader-originlogger/</loc>
<lastmod>2023-01-07T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/batloader-ursnif-redline-oh-my/</loc>
<lastmod>2023-01-23T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/netsupport-manager-malicious-installer/</loc>
<lastmod>2023-02-25T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/faster-malware-triage-yara/</loc>
<lastmod>2023-07-14T23:02:12+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/vhd-malware-an-excellent-choice/</loc>
<lastmod>2023-07-25T21:24:42+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/timelining-malware-vhd-intelligence/</loc>
<lastmod>2023-08-04T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/dissecting-java-pikabot-dropper/</loc>
<lastmod>2024-03-03T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/decompiling-jphp-loader-binwalk-cfr/</loc>
<lastmod>2024-07-20T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/exploring-venomrat-metadata-encryption-with-yara/</loc>
<lastmod>2025-01-02T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/squeezing-cobalt-strike-intel-from-shodan/</loc>
<lastmod>2025-05-19T01:31:42+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/</loc>
<lastmod>2025-08-27T01:33:01+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/</loc>
<lastmod>2025-08-27T01:33:01+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/archives/</loc>
<lastmod>2025-08-27T01:33:01+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/about/</loc>
<lastmod>2025-08-27T01:33:01+00:00</lastmod>
</url>
<url>
<loc>https://forensicitguy.github.io/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/sans/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/dfir/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/netwars/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/meterpreter/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/chrome/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/msfvenom/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/jar/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/metasploit/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/merlin/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/ld-preload/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/libprocesshider/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/linux/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/whitelisting/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/unix/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/ld-audit/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/libpreloadvaccine/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/windows/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/active-directory/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/domain-controllers/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/accounts/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/administrators/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/dnf/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/yum/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/linux/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/plugin/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/persistence/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/edr/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/evasion/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/qbot/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/malware/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/esentutil/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/macos/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/empire/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/pkg/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/7zip/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/sfx/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/self-extracting/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/installers/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/pefile/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/pe/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/rich/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/header/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/hash/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/virustotal/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/deobfuscation/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/powershell/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/net/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/log4jshell/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/java/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/muhstik/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/icedid/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/msword/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/mshta/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/regsvr32/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/magnitude/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/magniber/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/appx/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/agenttesla/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/javascript/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/vbs/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/mirai/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/upx/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/webshell/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/nodejs/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/powerpoint/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/macros/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/olevba/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/cobalt-strike/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/hta/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/emotet/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/excel4-macro/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/xll/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/excel-dna/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/bazariso/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/advpack/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/hcrypt/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/process-injection/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/bitrat/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/guloader/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/shellcode/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/callbacks/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/strrat/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/msi/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/oledump/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/njrat/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/rtf/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/equationeditor/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/xloader/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/formbook/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/xlsx/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/velvetsweatshop/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/msitools/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/stealer/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/ppam/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/macro/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/aggah/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/vbscript/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/csharp/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/certutil/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/dcrat/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/snip3/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/lnk/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/pirrit/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/pkg/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/postinstall/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/ducktail/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/net-core/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/pecheck/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/foremost/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/originlogger/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/iso/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/batloader/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/ursnif/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/redline/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/gpg/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/msidump/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/netsupport/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/rar/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/detectiteasy/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/tools/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/yara/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/vhd/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/plaso/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/spreadsheets/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/pikabot/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/jphp/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/binwalk/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/d3fck/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/venomrat/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/threat-intelligence/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/shodan/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/tags/cobaltstrike/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/education/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/security/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/red-team/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/linux/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/blue-team/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/windows/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/linux/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/malware/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/tools/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/yara/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/hashing/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/entropy/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/malware/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/categories/threat-intelligence/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/page2/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/page3/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/page4/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/page5/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/page6/</loc>
</url>
<url>
<loc>https://forensicitguy.github.io/googlea91a102f7d513586.html</loc>
<lastmod>2025-08-27T01:32:56+00:00</lastmod>
</url>
</urlset>
