ZecOps Research Team

forensics images acquired GreyShift

ZecOps Announces Support for Forensics Images Acquired by GrayShift

ZecOps is pleased to announce native support of mobile forensic images acquired with Graykey. With the latest release, ZecOps is capable of digesting filesystem archives acquired by GrayKey, GrayShift’s flagship product, providing cybersecurity insights and automatic analysis for ZecOps customers. ZecOps can automatically digest and analyze various data points that exist on the disk, including …

ZecOps Announces Support for Forensics Images Acquired by GrayShift Read More »

Mobile-Attacker-Mindset-2-Persistence

Persistence without “Persistence”: Meet The Ultimate Persistence Bug – “NoReboot”

Mobile Attacker’s Mindset Series – Part II Evaluating how attackers operate when there are no rules leads to discoveries of advanced detection and response mechanisms. ZecOps is proudly researching scenarios of attacks and sharing the information publicly for the benefit of all the mobile defenders out there. iOs persistence is presumed to be the hardest …

Persistence without “Persistence”: Meet The Ultimate Persistence Bug – “NoReboot” Read More »

How iOS Malware Can Spy on Users Silently

Welcome to the first post of our latest blog series: Mobile Attacker’s Mindset In this blog series, we’re going to cover how mobile threat-actors think, and what techniques attackers use to overcome security protections and indications that our phones and tablets are compromised.  In this first blog, we’ll demonstrate how the recently added camera & …

How iOS Malware Can Spy on Users Silently Read More »

Use-After-Free in Voice Control: CVE-2021-30902 Write-up

By: 08Tc3wBB Voice Control is a powerful feature introduced by Apple in iOS 13 and macOS Catalina. It acts as a substitute for all the touch gestures on the screen, letting you interact with the device using your voice to tap, swipe, type, and more. com.apple.SpeechRecognitionCore.speechrecognitiond Crashes com.apple.SpeechRecognitionCore.speechrecognitiond is a system XPCService process that handles …

Use-After-Free in Voice Control: CVE-2021-30902 Write-up Read More »