{"id":1489,"date":"2022-02-26T11:13:23","date_gmt":"2022-02-26T17:13:23","guid":{"rendered":"https:\/\/www.herbiez.com\/?p=1489"},"modified":"2022-02-26T12:08:19","modified_gmt":"2022-02-26T18:08:19","slug":"2022-02-21-quick-post-browser-add-ons-and-push-notifications","status":"publish","type":"post","link":"https:\/\/www.herbiez.com\/?p=1489","title":{"rendered":"2022-02-26 Quick Post &#8211; Push Notifications And Files Written To Disk"},"content":{"rendered":"<p><span style=\"color: #ff0000\"><strong>Note: It took me a little longer to get this post written and my VM had crashed on me, so the logs seen from Chrome or Edge may reflect more data than I had initially.<\/strong><\/span><\/p>\n<p>This is going to be slightly off topic from what I usually post about (malware) and is not deep in the weeds for someone that is wanting to do forensics. The lens that I am viewing this from is as a defender\/SOC analyst. For a more in-depth look into this topic from a forensics perspective please see these awesome resources below:<\/p>\n<ul>\n<li>Jai Minton&#8217;s\u00a0Digital Forensics and Incident Response cheat sheet &#8211; <a href=\"https:\/\/www.jaiminton.com\/cheatsheet\/DFIR\/#\" target=\"_blank\" rel=\"noopener\">https:\/\/www.jaiminton.com\/cheatsheet\/DFIR\/#<\/a><\/li>\n<li>A Digital Forensic View of Windows 10 Notifications by Patr\u00edcio Domingues, Lu\u00eds Andrade, and Miguel Frade &#8211; <a href=\"https:\/\/www.mdpi.com\/2673-6756\/2\/1\/7\/pdf\" target=\"_blank\" rel=\"noopener\">https:\/\/www.mdpi.com\/2673-6756\/2\/1\/7\/pdf\u00a0<\/a><\/li>\n<li>Microsoft&#8217;s <span style=\"font-family: 'Source Sans Pro'\">Web Push Notifications &#8211; <a href=\"https:\/\/webpushdemo.azurewebsites.net\/\" target=\"_blank\" rel=\"noopener\">https:\/\/webpushdemo.azurewebsites.net\/<\/a><\/span><\/li>\n<\/ul>\n<p>As a defender one of the things that I commonly see is when a user has triggered an alert for either POST or GET requests being blocked at the proxy due to a URL that had been flagged, only to find out that the alert stems from a browser add-on or a push notification for a site. This got me thinking about how EDRs, in general, dealt with this kind of activity since <em>something<\/em> has to be written to disk. The last time that I played with Crowdstrike (it&#8217;s been a while now) it did not flag on any browser add-ons or push notifications unless there was something questionable\/malicious about it (i.e.: see this <a href=\"https:\/\/www.reddit.com\/r\/crowdstrike\/comments\/ozaxmg\/anyone_else_getting_low_pup_detections_related_to\/\" target=\"_blank\" rel=\"noopener\">Reddit thread<\/a> about Wave Browser\/WebNavigator alerts) &#8211; so I am pretty sure this is the case for most other EDR products as well. With that being said, I wanted to see what would be written to disk, if anything was written to begin with, when a user accepted a push notification for a site on a Windows system. I am not looking at browser extensions for this post since it would be written to disk anyways and could be easily alerted on based on the path for the browser or blocked by GPO. For an <strong>excellent resource<\/strong> regarding forensics and the location of different artifacts check out <a href=\"https:\/\/www.jaiminton.com\/cheatsheet\/DFIR\/#t1176-browser-extensions\" target=\"_blank\" rel=\"noopener\">Jai Minton&#8217;s site<\/a> where it is all broken down in an easy to read format.<\/p>\n<p><span style=\"font-family: 'Source Sans Pro'\">When I started to look into this I discovered that there are a lot of resources out there that go quite in depth about push notifications and the Windows Notification System in general. One of the first sites that I came across was from Microsoft which explained it well <\/span><span style=\"font-family: 'Source Sans Pro'\">and made it pretty easy to understand from a client-server application perspective. It also has the ability of performing test pushes since it will allow you to subscribe to the site and play with it some. I also came across a well written and in-depth paper talking about the Windows 10 notifications system from a forensic&#8217;s perspective. That PDF can be found <a href=\"https:\/\/www.mdpi.com\/2673-6756\/2\/1\/7\/pdf\" target=\"_blank\" rel=\"noopener\">here<\/a>. I also found a site (<a href=\"https:\/\/pushalert.co\/\" target=\"_blank\" rel=\"noopener\">pushalert.co<\/a>) that would allow someone to create a free limited use account to do push notifications to a website. Leveraging Pushalert and the script that it generated, and a test site that I created on Github with the script from PushAlert, I started to play with things on my test Windows VM.<\/span><\/p>\n<p>Like I stated above, initially I started to play with the web push notification site from Microsoft and PushAlert on my test VM and just ran Process Monitor to see what kind of results I would get. With the filtering in ProcMon set as the following:<\/p>\n<ul>\n<li>Path contains &#8220;wpndatabase&#8221; (this covers me from the user\/system perspective of the Windows push service)<\/li>\n<li>Path contains &#8220;C:\\Users\\bob\\AppData\\Local\\Google\\Chrome\\User Data\\Notification Resources\\&#8221;<\/li>\n<li>Path contains &#8220;C:\\Users\\bob\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Platform Notifications&#8221;\u2020<\/li>\n<li>Path contains &#8220;C:\\Users\\bob\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Service Worker\\Database\u201d\u2020<\/li>\n<\/ul>\n<p>\u2020 These paths can be swapped out for Edge as well (i.e.: C:\\Users\\%username%\\AppData\\Local\\Microsoft\\Edge\\User Data\\Default<\/p>\n<p>The image below is what I initially saw.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/procmon1.jpeg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1498\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/procmon1-1024x615.jpeg\" alt=\"\" width=\"900\" height=\"541\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/procmon1-1024x615.jpeg 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/procmon1-300x180.jpeg 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/procmon1-768x461.jpeg 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/procmon1-1536x922.jpeg 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/procmon1-150x90.jpeg 150w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/procmon1-250x150.jpeg 250w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/procmon1.jpeg 2021w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>The Chrome process wrote to a file called\u00a0<em>000003.log<\/em> in the &#8220;C:\\Users\\%username%\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Service Worker\\Database&#8221; location. Opening this file up I could see various hits for the push notifications from different sites that I was playing with (i.e.: Reddit, Yahoo, Webpushdemo, and PushAlert.io).<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/000003-log-chrome.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1501\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/000003-log-chrome-1024x541.png\" alt=\"\" width=\"900\" height=\"475\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/000003-log-chrome-1024x541.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/000003-log-chrome-300x158.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/000003-log-chrome-768x406.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/000003-log-chrome-1536x811.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/000003-log-chrome-2048x1082.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/000003-log-chrome-150x79.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a>Initially I thought the only thing that was missing here was where the push came from (more on that in a bit). Technically I can see that I had signed up for some push notifications from sites like Yahoo, and Reddit, but the one from PushAlert.io had no reference to the test site setup on Github.io that I could see. Also, I wanted to see what these would look like from a user using Edge, and this file did not have anything stating which browser got the alert. From a defender&#8217;s perspective, some bits are definitely missing (initially that is &#8211; more in a bit).<\/p>\n<p>So I bounced over to the path of &#8220;C:\\Users\\bob\\AppData\\Local\\Microsoft\\Windows\\Notifications&#8221; folder location to see what I may be able to find there since the service &#8220;svchost.exe&#8221; did some file operations on the &#8220;wpndatabase.db-shm\/wal&#8221; files.<\/p>\n<p><strong>Note: This is the user notification location and not the system wide notification location as that is written to another path.<\/strong><\/p>\n<p>From here, as &#8220;A Digital Forensic View of Windows 10 Notifications&#8221; described, I found the SQLite file and the other supporting files as well.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/user-platform-notifications.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1504\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/user-platform-notifications-1024x193.png\" alt=\"\" width=\"900\" height=\"170\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/user-platform-notifications-1024x193.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/user-platform-notifications-300x57.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/user-platform-notifications-768x145.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/user-platform-notifications-150x28.png 150w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/user-platform-notifications.png 1247w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>I opened the &#8220;wpndatabase.db&#8221; file using &#8220;<a href=\"https:\/\/sqlitebrowser.org\/\" target=\"_blank\" rel=\"noopener\">DB Browser for SQLite<\/a>&#8221; and low and behold, here is some of the data that I was looking for. As you can see in the XML blobs, this at least tells me 1) where the push is coming from in an easier on the eyes format, and 2) which browser got the push notification since it gives you the path for where the image associated with the push notification is located.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/wpndatabase.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1507\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/wpndatabase-1024x376.png\" alt=\"\" width=\"900\" height=\"330\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/wpndatabase-1024x376.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/wpndatabase-300x110.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/wpndatabase-768x282.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/wpndatabase-1536x564.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/wpndatabase-150x55.png 150w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/wpndatabase.png 1787w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/github-io.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1506\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/github-io-1024x432.png\" alt=\"\" width=\"900\" height=\"380\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/github-io-1024x432.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/github-io-300x127.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/github-io-768x324.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/github-io-150x63.png 150w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/github-io.png 1262w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/yahoo.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1508\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/yahoo-1024x401.png\" alt=\"\" width=\"900\" height=\"352\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/yahoo-1024x401.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/yahoo-300x117.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/yahoo-768x301.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/yahoo-150x59.png 150w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/yahoo.png 1234w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>The other nice bit about this is the fact that you can see what kind of message the user got from that push notification since there are some attributes for it as seen above. For example, the one from Github.io has the title of the push notification that I used along with the body of for the push notification (both the same in all cases). If you look at the one from Yahoo, you can see the headline of the news that was pushed to the browser.<\/p>\n<p>Since I was there, I also wanted to see what was in the &#8220;wpndatabase.db-wal&#8221; file since it does serve as a transaction log and would be more recent then the actual &#8220;wpndatabase.db&#8221; file based on the documentation from <a href=\"https:\/\/sqlite.org\/wal.html\" target=\"_blank\" rel=\"noopener\">SQLite.org<\/a>. After reading the doc for the WAL file my testing made more sense since I was seeing the WAL and SHM files updating before the actual db file.<\/p>\n<p>At first I used Notepad++ to open the WAL file up, but it was way to difficult to read. Next I tried Notepad and even then that was slow and clunky. I ended up using <a href=\"https:\/\/www.vim.org\/download.php#pc\" target=\"_blank\" rel=\"noopener\">GVIM<\/a> to open the file which made going through it a lot easier. As seen below, the WAL file allowed me to see push notifications that have been aged out of the &#8220;wpndatabase.db&#8221; file since Windows ages those out after three days. Compare this to the image above where the first date\/timestamp is from the 23rd of Feb and not the 21st of Feb.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/db-wal-file.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1505\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/db-wal-file-1024x630.png\" alt=\"\" width=\"900\" height=\"554\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/db-wal-file-1024x630.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/db-wal-file-300x185.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/db-wal-file-768x472.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/db-wal-file-1536x945.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/db-wal-file-150x92.png 150w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/02\/db-wal-file.png 1962w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>This still left me with one question left to answer &#8211; if someone does get a push notification, can I get information about where it came from possibly? Thinking about it again, I went back to the <em>000003.log <\/em>and this time used <a href=\"https:\/\/docs.microsoft.com\/en-us\/sysinternals\/downloads\/strings\" target=\"_blank\" rel=\"noopener\">SysInternals Strings<\/a> to just look at the strings in the file. Jackpot!<\/p>\n<pre class=\"brush: plain; light: false; title: Click here to expand...; toolbar: true; notranslate\" title=\"Click here to expand...\">\r\n\r\nBDATA:https_uk.yahoo.com_0\r\np#https:\/\/uk.yahoo.com\/#1Breaking News_1\r\nhttps:\/\/uk.yahoo.com\/\r\nBSecond COVID booster jab expected to be offered to most vulnerable\r\nA decision has reportedly been taken by the Joint Committee on Vaccination and Immunisation, with an announcement due in weeks.*\r\nBreaking News_12\r\nhttps:\/\/s.yimg.com\/uu\/api\/res\/1.2\/JNB6h9aDWHwpbVPBnOPt7A--\/cT03NTt3PTgwMDthcHBpZD15dGFjaHlvbjs-\/https:\/\/media.zenfs.com\/en\/the_independent_577\/a1b49603fd28596e804df7dbc2c4733e8\r\nfallback_&quot;\r\nuseNNSF&quot;\r\ntitle&quot;BSecond COVID booster jab expected to be offered to most vulnerable&quot;\r\nbody&quot;\r\nA decision has reportedly been taken by the Joint Committee on Vaccination and Immunisation, with an announcement due in weeks.&quot;\r\nurl&quot;Jhttps:\/\/uk.news.yahoo.com\/second-covid-booster-jab-expected-073039251.html&quot;\r\nuuid&quot;$e818a919-915a-377f-aa6e-9ede1e0d0c39&quot;\r\nfollowId_&quot;\r\ntimeline_name&quot;\r\nBreaking News&quot;\r\nmsg_id&quot;$78531c1e-f95a-4f43-8a76-1fc23090f9e6&quot;\r\nnotification_id_&quot;\r\npublish_time&quot;\r\n1645264860234&quot;\r\npublisher_msg_id&quot;$dfcbc394-d41f-4c4c-b389-fbc3fc03efeb&quot;\r\npl1I\r\nnotification_shownN\r\nwB{\r\nr@https:\/\/s.yimg.com\/cv\/apiv2\/notifications\/YCon_Badge_90_90_2.pngz\r\n*(p#https:\/\/uk.yahoo.com\/#1Breaking News_10\r\nk3c\r\n\r\nBDATA:https_uk.yahoo.com_0\r\np#https:\/\/uk.yahoo.com\/#1Breaking News_2\r\nhttps:\/\/uk.yahoo.com\/\r\n4Team GB wins first medal of the 2022 Winter Olympics\r\n&quot;eThe men's curling team had to make do with silver after suffering defeat in the final against Sweden.*\r\nBreaking News_22\r\nhttps:\/\/s.yimg.com\/uu\/api\/res\/1.2\/bXZOZU8N4FY_l39Mtl_hIQ--\/cT03NTt3PTgwMDthcHBpZD15dGFjaHlvbjs-\/https:\/\/media.zenfs.com\/en\/evening_standard_239\/f42048c283100e0fdfcc4d3916a47fdf8\r\nfallback_&quot;\r\nuseNNSF&quot;\r\ntitle&quot;4Team GB wins first medal of the 2022 Winter Olympics&quot;\r\nbody&quot;eThe men's curling team had to make do with silver after suffering defeat in the final against Sweden.&quot;\r\nurl&quot;Ahttps:\/\/uk.news.yahoo.com\/team-gb-miss-men-curling-095225138.html&quot;\r\nuuid&quot;$f272d807-c46d-3ccf-af9c-f3f360713dd4&quot;\r\nfollowId_&quot;\r\ntimeline_name&quot;\r\nBreaking News&quot;\r\nmsg_id&quot;$a820dd0b-7c40-4a3a-9aed-4e5970b55ca8&quot;\r\nnotification_id_&quot;\r\npublish_time&quot;\r\n1645265716129&quot;\r\npublisher_msg_id&quot;$9147640a-5334-44b6-9257-499e0ad01d3f&quot;\r\npl1I\r\nnotification_shownN\r\nwB{\r\nr@https:\/\/s.yimg.com\/cv\/apiv2\/notifications\/YCon_Badge_90_90_2.pngz\r\n*(p#https:\/\/uk.yahoo.com\/#1Breaking News_20\r\n\r\nPDATA:https_bloomer1016.github.io_0\r\np#https:\/\/bloomer1016.github.io\/#1Msg61166680\r\nhttps:\/\/bloomer1016.github.io\/\r\nTest 1 - 1411\r\nTest 1 - 1411*\r\nMsg611666802Ahttps:\/\/cdn.pushalert.co\/img\/pushalert-square-icon.png?16454743088\r\nurl&quot;\r\nhttps:\/\/bloomer1016.github.io\/&quot;\r\nurl_id&quot;\r\n61166680&quot;\r\nuidI\r\neidI\r\ntype&quot;\r\nhrz\r\n*-p#https:\/\/bloomer1016.github.io\/#1Msg611666800\r\n\r\nPDATA:https_bloomer1016.github.io_0\r\np#https:\/\/bloomer1016.github.io\/#1Msg61167281\r\nhttps:\/\/bloomer1016.github.io\/\r\nTest 2 - 1423\r\nTest 2 - 1423*\r\nMsg611672812Ahttps:\/\/cdn.pushalert.co\/img\/pushalert-square-icon.png?16454743328\r\nurl&quot;\r\nhttps:\/\/bloomer1016.github.io\/&quot;\r\nurl_id&quot;\r\n61167281&quot;\r\nuidI\r\neidI\r\ntype&quot;\r\nhrz\r\n*-p#https:\/\/bloomer1016.github.io\/#1Msg611672810\r\n\r\n<\/pre>\n<p>So looking at the snippet from the log above, the push notifications from Yahoo are pretty clear cut (and one could argue that they were clear cut above as well). The interesting part is the one from my Github test page and how it is associated with the PushAlert URL for the icon file which is what I was looking for since I was thinking in terms of redirects in a push notification or something like that.<\/p>\n<p>So after all of this, what did I learn you may ask? Well, as a defender that is using an EDR within the security stack, I know it will not flag on when a user enables site notifications, or when there is a push notification sent to them from a site, but at least I now know some file paths and files that I can refer to and take a deeper look and that are written to disk. This was the case the other day as there was a user that got flagged on some outbound traffic being blocked by the proxy. Looking at the alert, I could see that the user-agent string was Edge, but when I looked at the extensions directory within Edge, there was nothing there. So knowing the Edge is a fork off of the Chromium project, the folders and logs used would be the same. And while there were no extensions, I could see that there were push notifications that had the flagged URLs for fake anti-virus pop-ups and the like in their <em>00000x.log<\/em>.<\/p>\n<p>Till next time.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Note: It took me a little longer to get this post written and my VM had crashed on me, so the logs seen from Chrome or Edge may reflect more data than I had initially. This is going to be slightly off topic from what I usually post about (malware) and is not deep in the weeds for someone that is wanting to do forensics. The lens that I am viewing this from is as a defender\/SOC analyst. For a more in-depth look into this topic from a forensics perspective please see these awesome resources below: Jai Minton&#8217;s\u00a0Digital Forensics and&#8230;<\/p>\n<p> <a class=\"continue-reading-link\" href=\"https:\/\/www.herbiez.com\/?p=1489\"><span>Continue reading<\/span><i class=\"crycon-right-dir\"><\/i><\/a> <\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[48],"class_list":["post-1489","post","type-post","status-publish","format-standard","hentry","category-packet-analysis","tag-soc"],"_links":{"self":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1489","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1489"}],"version-history":[{"count":17,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1489\/revisions"}],"predecessor-version":[{"id":1515,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1489\/revisions\/1515"}],"wp:attachment":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1489"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1489"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1489"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}