<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Matthew Green &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/author/matthew-green/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Fri, 01 Nov 2024 13:00:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Finding the LNK: Techniques and methodology for advanced analysis with Velociraptor</title>
		<link>https://noise.getoto.net/2024/11/01/finding-the-lnk-techniques-and-methodology-for-advanced-analysis-with-velociraptor/</link>
		
		<dc:creator><![CDATA[Matthew Green]]></dc:creator>
		<pubDate>Fri, 01 Nov 2024 13:00:00 +0000</pubDate>
				<category><![CDATA[Velociraptor]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=404c9ca6b77b4e59f6ede25a9d870678</guid>

					<description><![CDATA[In this post, we explore the structure of LNK files using Velociraptor, our open-source digital forensics and incident response (DFIR) tool.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/10/GettyImages-1340424095.jpg" length="0" type="" />

			</item>
		<item>
		<title>How To Hunt For UEFI Malware Using Velociraptor</title>
		<link>https://noise.getoto.net/2024/02/29/how-to-hunt-for-uefi-malware-using-velociraptor/</link>
		
		<dc:creator><![CDATA[Matthew Green]]></dc:creator>
		<pubDate>Thu, 29 Feb 2024 17:32:12 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Velociraptor]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=252e5684da4910d9113b8b3b731d4caf</guid>

					<description><![CDATA[<p>UEFI threats have historically been limited in number and mostly implemented by nation state actors as stealthy persistence. However, the recent proliferation of Black Lotus on the dark web, Trickbot enumeration module (late 2022), and Glupteba (November 2023) indicates that this historical trend may be changing. </p><p>With this context, it</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/02/GettyImages-1128503636-1.jpg" length="0" type="" />

			</item>
		<item>
		<title>Automating Qakbot decode at scale</title>
		<link>https://noise.getoto.net/2023/04/14/automating-qakbot-decode-at-scale/</link>
		
		<dc:creator><![CDATA[Matthew Green]]></dc:creator>
		<pubDate>Fri, 14 Apr 2023 14:16:44 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Velociraptor]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3ffe66f5cdd4b3254ab7d5c280f4c9a9</guid>

					<description><![CDATA[This is a technical post covering methodology to extract configuration data from recent Qakbot samples. I will provide background on Qakbot, walk through decode themes in an easy to visualize manner. I will then share a Velociraptor artifact to detect and automate the decode process at scale.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/04/qak.png" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 25/69 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-03-13 12:17:24 by W3 Total Cache
-->