Forensic Analysis of the NetWire Stack

June 2nd, 2023
By:  Mark Spencer

Joakim has recently gone on some adventures involving the NetWire RAT (Remote Access Trojan) that we believe all our colleagues in digital forensics should start digging into as soon as possible.

Read More
June 2nd, 2023
 |  Topic(s):  NewsNew Release

Quick Tour of New Features in Arsenal Image Mounter v3.2.128

August 12th, 2020
Arsenal Image Mounter’s Windows authentication bypass is already more powerful than any other tools we are aware of, but that has not stopped us from continuing to push boundaries.
Read More

Quick Tour of New Features in Arsenal Image Mounter v3.2.126

June 15th, 2020
When the United States Army asked us if Arsenal Image Mounter’s Windows authentication bypass could be extended to handle domain accounts protected by smart cards, we were not sure it would be possible…
Read More

Accessing Protected Content using Windows Domain Controllers and Workstations

June 9th, 2020
While Windows password bypassing (particularly with AIM, which can bypass all types of Windows passwords) provides digital forensics practitioners with great opportunities, there are certain things...
Read More

Free Arsenal Educational Subscriptions

May 6th, 2020
Arsenal is dramatically expanding our educational program providing free subscriptions each semester not only to professors at colleges and universities, but to students as well.
Read More

The Interesting Case of Windows Hibernation and BitLocker

April 24th, 2020
Read More

An Inside View of Office Document Cache Exploitation

April 9th, 2020
Multiple versions of Microsoft Office documents could be extracted from FSD files found within Office Document Cache (on many kinds of devices, not just Windows workstations!).
Read More

Quick Tour of New Features in Arsenal Image Mounter v3.1.101

March 16th, 2020
The workflow for launching virtual machines has been significantly improved in Arsenal Image Mounter v3.1.101!
Read More

A Brief Note About Our Mission

November 14th, 2019
Arsenal is unlike other digital forensics software vendors in the sense that we are consultants involved in casework first and software developers second.
Read More

BitLocker for DFIR – Part II

October 30th, 2019
Launching virtual machines from BitLockered disk images using Arsenal Image Mounter
Read More

Join the List

Arm yourself with updates about Arsenal tools, training, and research. Our mailing list is double opt-in so you will need to check your email and confirm your subscription before receiving our mailings.