21st.dev Magic MCP — AI-powered UI component generation via natural language. Access to 21st.dev component library, SVGL brand logos, and real-time preview. Generate React/Tailwind components with /ui command.
日本語の概要は準備中です。原文の説明を表示しています。
Disk imaj forensics — The Sleuth Kit (TSK), Autopsy, deleted file recovery, MFT/inode analizi, slack space, EWF/RAW imajlar
インストールする前に、エージェントに与えられる指示の中身を確認できます。
CTF'te genelde .dd, .raw, .img veya .E01 formatında disk imajı verilir. Hedef: silinmiş dosyaları kurtarmak, gizli partitionları bulmak, slack space'ten flag çıkarmak.
.dd / .raw / .img / .E01 / .vmdk dosyası# The Sleuth Kit + Autopsy
sudo apt install -y sleuthkit autopsy
# File carving
sudo apt install -y foremost testdisk
# photorec = testdisk'in parçası
# EWF (Encase) support
sudo apt install -y ewf-tools libewf2
# NTFS özel araçlar
sudo apt install -y ntfs-3g
pip install analyzeMFT
pip install ntfs-tools
# Hex editor
sudo apt install -y bless wxhexeditor
# Disk montaj (read-only, forensics)
sudo modprobe loop
# 1. Dosya tipini tespit
file disk.img
# disk.img: DOS/MBR boot sector; partition 1 : ID=0x83, ...
# 2. EWF ise raw'a çevir
ewfmount disk.E01 /mnt/ewf
ls /mnt/ewf/ # ewf1 dosyası = RAW
# 3. Partition tablosunu oku
mmls disk.img
# Slot Start End Length Description
# 000: Meta 0000000000 0000000000 0000000001 Primary Table
# 002: 000:000 0000002048 0019531263 0019529216 Linux (0x83)
# 4. Filesystem stats
fsstat -o 2048 disk.img # offset = partition başlangıcı
# File System Type: Ext4
# Block Size: 4096
# Last Mount: ...
# 5. Tüm dosyaları listele (silinmişler dahil)
fls -r -o 2048 disk.img > all_files.txt
grep -v "^[r/]" all_files.txt # silinmiş dosyalar = "* " ile başlar
# Sleuth Kit recover (silinmiş + var olan dosyaları çıkarır)
mkdir output
tsk_recover -e -o 2048 disk.img output/
# Sonra grep
grep -r "flag" output/
grep -r "CTF{" output/
# 1. Silinmiş dosyaları listele
fls -d -r -o 2048 disk.img
# Çıktı:
# d/d * 12345: deleted_folder
# r/r * 67890: secret.txt
# 2. icat ile içeriği çek (inode kullanarak)
icat -o 2048 disk.img 67890 > recovered.txt
cat recovered.txt
# foremost — magic byte tabanlı
foremost -t all -i disk.img -o carved/
# Yapı:
# carved/jpg/00000123.jpg
# carved/png/00000456.png
# carved/zip/00000789.zip
# carved/audit.txt
# Sonra hepsini incele
ls -la carved/*/
# photorec — daha güçlü
photorec disk.img
# Interactive menu, partition seç, dosya tipleri seç
# scalpel (foremost'un fork'u, daha fast)
scalpel -c /etc/scalpel/scalpel.conf -o output disk.img
# Slack space = bir dosyanın ayrılan cluster'ından kalan kullanılmayan kısım
# Bazen silinmiş veri parçaları burada kalır
# blkls ile unallocated space çıkar
blkls -o 2048 disk.img > unallocated.dd
# Sonra strings + grep
strings unallocated.dd | grep -i flag
strings unallocated.dd | grep -E "CTF\{|flag\{|FLAG\{"
# Veya foremost unallocated üzerinde
foremost -i unallocated.dd -o slack_carved/
# Bilinen header için scan
xxd disk.img | grep "89 50 4e 47" # PNG magic
# Veya binwalk ile
binwalk disk.img
binwalk -e disk.img # extract
# strings ile ASCII flag
strings -a disk.img | grep -E "flag\{|CTF\{|HTB\{"
# MFT extract
icat -o 2048 disk.img 0 > MFT_raw
# MFT analiz
analyzeMFT.py -f MFT_raw -o mft_parsed.csv
# Tüm MFT entries listele
mftecmd -f MFT_raw --csv mft.csv
# Alternate Data Streams
ntfscat disk.img secret.txt:hidden_stream
# Bilinen klasörler
icat -o 2048 disk.img <inode> | strings
# Inode bilgileri
istat -o 2048 disk.img 12345
# Journal (silinmiş dosyalar genelde journalde)
jcat -o 2048 disk.img
# extundelete (en güçlü ext silme kurtarma)
extundelete --restore-all disk.img --output-dir recovered/
# FAT inode = cluster numarası
mmls disk.img
# FAT genelde bilgisayar küçük partition
# tsk_recover normal ext gibi çalışır
tsk_recover -o 2048 disk.img out/
# Autopsy başlat
autopsy
# Tarayıcı aç: http://localhost:9999/autopsy
# 1. New Case
# 2. Add Host
# 3. Add Image (disk.img)
# 4. File Analysis tab → silinmiş dosyalar kırmızı
# 5. Keyword Search → "flag" ara
Modern Autopsy 4 (Java GUI):
# https://www.autopsy.com/download/
# Daha hızlı, daha fazla feature
# Tespit
file disk.img # "LUKS encrypted file"
# LUKS unlock
sudo cryptsetup luksOpen disk.img mycrypt
sudo mount /dev/mapper/mycrypt /mnt/decoded
# Şifre brute (challenge'da verili olabilir)
# BitLocker
dislocker -V disk.img -p<recovery_key> -- /mnt/bitlocker
# /mnt/bitlocker/dislocker-file = decrypted raw, mount edilebilir
# VeraCrypt
veracrypt --mount disk.img /mnt/vera
# Disk'in sonunda fazla byte var mı?
ls -la disk.img # boyut
mmls disk.img | tail # son partition sonu
# Eğer disk.img > son partition end + sektör boyutu, fazlalık var
# Çıkar:
dd if=disk.img of=hidden_after.bin bs=512 skip=$END_SECTOR
# strings + analiz
strings hidden_after.bin
# Magic byte tablosu (yaygınlar)
# FFD8FF JPEG
# 89504E47 PNG
# 504B0304 ZIP
# 25504446 PDF
# 7F454C46 ELF
# 4D5A PE/EXE
# 1F8B08 gzip
# 425A6839 bzip2
# Tarama
xxd disk.img | grep -E "(89 50 4e 47|ff d8 ff|50 4b 03 04)" | head
# Belirli offset'ten dosya çıkar
dd if=disk.img of=image.png bs=1 skip=12345 count=2048
# Verilen: pollution.E01
# 1. EWF mount
mkdir /tmp/ewf
ewfmount pollution.E01 /tmp/ewf/
file /tmp/ewf/ewf1
# 2. Partition listele
mmls /tmp/ewf/ewf1
# 3. NTFS olarak görünür (Slot 002)
# offset = sector_start * 512 = 2048 * 512 = 1048576
# 4. fls ile listele
fls -r -o 2048 /tmp/ewf/ewf1 | grep -i "secret\|flag\|hidden"
# 5. Silinmiş dosya bulundu, icat ile çıkar
icat -o 2048 /tmp/ewf/ewf1 12345 > secret.txt
file secret.txt
strings secret.txt | head
# 6. Eğer şifreli, başka skill'lere git
-o) sektör cinsinden ama bazı durumlarda byte cinsinden. mmls çıktısı sektör. Yanlış offset = "no filesystem found"..E01 zaten sıkıştırılmış. Uncompress etmek için ewfmount yeterli.mftecmd veya analyzeMFT.py ile recombine.file ile her çıkanı doğrula.Disk imaj challenge → mount + partition analizi
├── Silinmiş dosya → tsk_recover / extundelete
├── File carving → foremost / photorec
├── Slack space → blkls + strings
├── MFT (NTFS) → analyzeMFT
├── Encrypted partition → şifre bul, decrypt
├── Memory dump bulundu → volatility-memory-analysis skill
├── PCAP bulundu → pcap-network-analysis skill
└── Stego image → steganography-image skill
# Temel
sudo apt install sleuthkit autopsy foremost testdisk ewf-tools
# Python
pip install pytsk3 analyzeMFT
# Windows Live forensics (eğer Windows işletim sistemi varsa)
# FTK Imager (Windows)
# X-Ways Forensics (komersiyel)
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
21st.dev Magic MCP — AI-powered UI component generation via natural language. Access to 21st.dev component library, SVGL brand logos, and real-time preview. Generate React/Tailwind components with /ui command.
日本語の概要は準備中です。原文の説明を表示しています。
AES CBC/ECB modlarına karşı kriptografik bütünlük saldırıları — bit flipping, IV manipulation, ECB cut-and-paste, CBC-MAC length extension, IV reuse
日本語の概要は準備中です。原文の説明を表示しています。
AES-GCM ve ChaCha20-Poly1305 nonce yeniden kullanımı saldırısı — GF(2^128) polinom kök bulma ile Hash Key kurtarma ve MAC sahteciliği.
日本語の概要は準備中です。原文の説明を表示しています。
tespit etmeabnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetObject spikes), and potential data exfiltration using statistical baselines and time-series anomaly Tespit.
日本語の概要は準備中です。原文の説明を表示しています。
Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to tespit etmereentrancy, integer overflow, access control, and other vulnerability classes before Dağıt:ment to Ethereum mainnet.
日本語の概要は準備中です。原文の説明を表示しています。
Parses Kubernetes API server audit logs (JSON lines) to tespit etmeexec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat Tespit rules from audit event patterns. Use investigating yaparken Kubernetes cluster compromise or building k8s-specific SIEM Tespit rules.
日本語の概要は準備中です。原文の説明を表示しています。