<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Marco Ferrara · DFIR &amp; Forensic CTF</title><description>Research, forensic CTF writeups, and challenges by Marco Ferrara (imb0ru).</description><link>https://imb0ru.github.io/</link><language>en</language><item><title>Foreigner</title><link>https://imb0ru.github.io/blog/challenges/foreigner/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/challenges/foreigner/</guid><description>Geolocate a deceptively ordinary parking-lot photo. The title is the clue: an Italian goes abroad without ever boarding a plane.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>osint</category><category>geolocation</category><category>image</category></item><item><title>Cousin</title><link>https://imb0ru.github.io/blog/challenges/cousin/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/challenges/cousin/</guid><description>An attachment-less OSINT/CTI chain: from an ESET Botconf 2022 talk to the three TA410 sub-teams and the FlowCloud implant, ending in a SHA1-derived flag.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>osint</category><category>cti</category><category>apt</category><category>ta410</category><category>yara</category><category>malware</category></item><item><title>NFZ</title><link>https://imb0ru.github.io/blog/challenges/nfz/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/challenges/nfz/</guid><description>A seized DJI Mavic 3 microSD card with deleted photos. The flag survives in the EXIF thumbnail of a partially overwritten JPEG.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>forensics</category><category>drone</category><category>dji</category><category>exfat</category><category>file-carving</category><category>exif</category></item><item><title>Waypoint</title><link>https://imb0ru.github.io/blog/challenges/waypoint/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/challenges/waypoint/</guid><description>Fifty DJI flight logs from one &apos;test&apos; afternoon. Overlay every GPS trace and the drone&apos;s real message appears written in the sky.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>drone</category><category>flight-log</category><category>gps</category><category>misc</category></item><item><title>Downlink</title><link>https://imb0ru.github.io/blog/challenges/downlink/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/challenges/downlink/</guid><description>An SDR-captured RF recording hides MAVLink2 drone telemetry. Demodulate the FSK/Manchester signal and reassemble the flag from chunked STATUSTEXT messages.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>forensics</category><category>sdr</category><category>rf</category><category>mavlink</category><category>dsp</category><category>drone</category></item><item><title>UNCXXXX</title><link>https://imb0ru.github.io/blog/challenges/uncxxxx/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/challenges/uncxxxx/</guid><description>A trojanized RVTools installer infects a Windows workstation. Triage the disk image, trace the SMOKEDHAM kill chain across bytecode, PowerShell, a C2 capture, and OSINT to rebuild a 3-part flag.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>forensics</category><category>disk-forensics</category><category>malware-analysis</category><category>network-forensics</category><category>osint</category><category>smokedham</category><category>reversing</category></item><item><title>Gianbruno&apos;s Clicker</title><link>https://imb0ru.github.io/blog/writeups/gianbrunos-clicker/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/writeups/gianbrunos-clicker/</guid><description>Bhackari CTF forensics on Gianbruno&apos;s seized PC: one flag hides in a base64-encoded filename inside the .minecraft folder, the second is painted into the autoclicker GUI bitmap embedded in the PE.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>forensics</category><category>ntfs</category><category>prefetch</category><category>base64</category><category>pe</category><category>bitmap</category><category>minecraft</category></item><item><title>Gianbruno&apos;s Injection Client</title><link>https://imb0ru.github.io/blog/writeups/gianbrunos-injection-client/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/writeups/gianbrunos-injection-client/</guid><description>Bhackari CTF: the Titan Launcher on Gianbruno&apos;s disk is a red herring. The real Minecraft injection client is xproc64.exe hiding in System32. Part 1 reads the flag from its PE version info; Part 2 reverses the Rust binary to recover the XOR/AES-protected payload it injects.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>forensics</category><category>reversing</category><category>rust</category><category>ntfs</category><category>pe</category><category>aes</category><category>xor</category><category>sha256</category><category>minecraft</category></item><item><title>Another VolWeb PR: explicit YARA scan scope selection</title><link>https://imb0ru.github.io/blog/research/volweb-yara-scope-pr/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/research/volweb-yara-scope-pr/</guid><description>After the v3.16.0 release I kept working on VolWeb: a new pull request adds explicit YARA scan scope selection (VAD vs Kernel) and fixes the FileScan Dump button.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><category>volweb</category><category>yara</category><category>memory-forensics</category><category>dfir</category><category>open-source</category></item><item><title>VolWeb v3.16.0: my thesis fork merged into the official project</title><link>https://imb0ru.github.io/blog/research/volweb-v3-16-merge/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/research/volweb-v3-16-merge/</guid><description>After open-sourcing my VolWeb fork, the whole thing was merged into the official repository and shipped in the v3.16.0 release. I&apos;m now an official contributor to the project.</description><pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate><category>volweb</category><category>yara</category><category>volatility3</category><category>memory-forensics</category><category>dfir</category><category>open-source</category></item><item><title>YARA on VolWeb: my thesis extension, open-sourced</title><link>https://imb0ru.github.io/blog/research/volweb-thesis/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/research/volweb-thesis/</guid><description>My BSc thesis at the University of Bari: a VolWeb extension that natively integrates YARA pattern matching into the Volatility 3 web interface, now open source.</description><pubDate>Thu, 16 Oct 2025 00:00:00 GMT</pubDate><category>volweb</category><category>yara</category><category>volatility3</category><category>memory-forensics</category><category>dfir</category><category>open-source</category></item><item><title>Locked Shields 2025: forensics with Blue Team 13</title><link>https://imb0ru.github.io/blog/notes/locked-shields-2025/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/notes/locked-shields-2025/</guid><description>I took part in Locked Shields 2025, the world&apos;s largest live-fire cyber defence exercise (NATO CCDCOE). In Blue Team 13&apos;s forensics unit we analysed a compromised ICS and an infected mobile device, and placed 3rd overall.</description><pubDate>Tue, 03 Jun 2025 00:00:00 GMT</pubDate><category>locked-shields</category><category>nato-ccdcoe</category><category>blue-team</category><category>digital-forensics</category><category>incident-response</category><category>ics</category></item><item><title>HackInSchool: teaching cybersecurity to high-schoolers</title><link>https://imb0ru.github.io/blog/notes/hackinschool/</link><guid isPermaLink="true">https://imb0ru.github.io/blog/notes/hackinschool/</guid><description>A recap of HackInSchool: a cybersecurity day for around 140 high-school students at the University of Bari, where I ran a session on steganography and we held a Jeopardy CTF.</description><pubDate>Thu, 21 Mar 2024 00:00:00 GMT</pubDate><category>outreach</category><category>education</category><category>ctf</category><category>steganography</category><category>digital-forensics</category><category>mntcrl</category></item></channel></rss>