Doug Metz
banner
dwmetz.bsky.social
Doug Metz
@dwmetz.bsky.social
#DFIR 🫆@ Magnet Forensics
Blog ✍️ @ BakerStreetForensics.com
Opinions are my own and are subject to change.
CyberPipe-Timeliner was developed to integrate Magnet Response collections with ForensicTimeliner. This tool automates the workflow of EZTools, and transforms collection data into a unified forensic timeline. #DFIR
CyberPipe-Timeliner: From Collection to Timeline in One Script
CyberPipe-Timeliner was developed in response to a colleague's query about integrating Magnet Response collections with ForensicTimeliner. This tool automates the workflow, transforming collection data into a unified forensic timeline. With features like date filtering and flexible input options, it streamlines the timeline generation process, making it efficient and user-friendly. #DFIR
bakerstreetforensics.com
November 5, 2025 at 4:23 PM
CyberPipe v5.3: Enhanced PowerShell Compatibility and Reliability

I'm pleased to announce the release of CyberPipe v5.3, bringing critical compatibility improvements for Windows PowerShell 5.1 and enhanced reliability across all PowerShell environments. The Problem After releasing v5.2 with the…
CyberPipe v5.3: Enhanced PowerShell Compatibility and Reliability
I'm pleased to announce the release of CyberPipe v5.3, bringing critical compatibility improvements for Windows PowerShell 5.1 and enhanced reliability across all PowerShell environments. The Problem After releasing v5.2 with the new unified banner design, several users reported an interesting issue: CyberPipe would execute perfectly in PowerShell Core, but in Windows PowerShell 5.1, the script would complete the Magnet Response collection successfully—then immediately fail with an exit code error and stop before running EDD and BitLocker key recovery.
bakerstreetforensics.com
November 4, 2025 at 2:45 PM
Reposted by Doug Metz
You'll pry these Oxford commas out of my cold, dead, third thing hands
October 23, 2025 at 7:30 PM
CyberPipe, a PowerShell script for digital evidence collection, has been updated with enhancements in collection, capabilities, and reliability. New features include intelligent collection with dual disk space validation, a QuickTriage profile, and improved BitLocker recovery. #DFIR
Streamline Digital Evidence Collection with CyberPipe 5.2
CyberPipe, developed for incident response, is a PowerShell script facilitating efficient digital evidence collection in enterprise settings. Recent updates include improved collection methods, capabilities like QuickTriage for faster artifact gathering, and enhanced reliability with advanced error handling. Version 5.2 aims to streamline operations while ensuring forensic integrity and transparency. #DFIR
bakerstreetforensics.com
October 16, 2025 at 2:24 PM
Swore I was reading @theonion.com
cnn.com CNN @cnn.com · Oct 10
"President Donald Trump’s extraordinary public lobbying campaign for a Nobel Peace Prize hasn’t proven very convincing," writes Aaron Blake. | Analysis https://cnn.it/4hdLbWP
October 10, 2025 at 12:13 AM
A trick and a treat this week with a quiet milestone for cross-platform DFIR tooling — MalChelaGUI now runs seamlessly inside Windows through Ubuntu WSL2, with zero configuration required. #DFIR #MalwareAnalysis
Cross-Platform DFIR Tools: MalChelaGUI on Windows
A trick and a treat this week with a quiet milestone for cross-platform DFIR tooling — MalChelaGUI now runs seamlessly inside Windows through Ubuntu WSL2, with zero configuration required. #DFIR #MalwareAnalysis
bakerstreetforensics.com
October 7, 2025 at 7:50 PM
Reposted by Doug Metz
On Oct 8, join us for a special episode of #CyberUnpacked where hosts @dwmetz.bsky.social & Jeff Rutherford will bring together a panel of #DFIR leaders to explore top challenges investigative teams face and the state of #DigitalInvestigations today: ow.ly/jRVq50X2r0L
S2:E4 // Voices from the field: Trends, challenges, and what’s next in DFIR - Magnet Forensics
Digital Forensics and Incident Response (DFIR) has evolved rapidly from purely reactive investigations to incorporating proactive approaches that utilize cloud-powered forensics and AI. But while the ...
ow.ly
September 25, 2025 at 7:29 PM
Reposted by Doug Metz
Masked ICE aren’t about safety; they’re about fear and evading responsibility. Demand transparency and accountability by adding your name to this petition:
Sign Petition: Stop Masked Immigration Raids. This Is Not How a Democracy Operates.
These agents are using masks to shield themselves from accountability for their willingness to participate in dangerous overreach. (51529 signatures on petition)
www.thepetitionsite.com
August 30, 2025 at 9:00 PM
In DFIR, reliable storage is essential for effective workflows. Crabwise, a USB benchmarking utility, addresses performance variability by calculating read and write speeds under direct conditions, bypassing caching and logs results for easy comparison. #DFIR
Is your USB device slowing down your forensic investigation?
In digital forensics, reliable storage is essential for effective workflows. Crabwise, a USB benchmarking utility, addresses performance variability by calculating read and write speeds under direct conditions, bypassing caching. It logs results for easy comparison, allowing users to optimize connections. This tool ensures informed decisions on hardware setups, improving efficiency and consistency in forensics tasks.
bakerstreetforensics.com
August 27, 2025 at 7:53 PM
MalChela 3.0.2 introduces MITRE Lookup, a tool that allows forensic investigators to search the MITRE ATT&CK framework offline. This feature enhances investigation speed by supporting keyword and Technique ID searches while providing tactic categories and detection guidance. #DFIR #MalwareAnalysis
Enhance Threat Hunting with MITRE Lookup in MalChela 3.0.2
The recent update of MalChela 3.0.2 introduces MITRE Lookup, a tool that allows forensic investigators to search the MITRE ATT&CK framework offline. This feature enhances investigation speed by supporting keyword and Technique ID searches while providing tactic categories and detection guidance. Users can save results directly for future reference, enhancing analysis efficiency.
bakerstreetforensics.com
August 2, 2025 at 8:22 PM
💙🐕 Toby ! :)
Read the latest DFIR news – Epstein video analysis by ex-FBI experts, stress warning signs in forensics, Raspberry Pi toolkit “Toby,” PDF tampering risks, SWGDE timing advance guidance, and more. www.forensicfocus.com/news/... #DigitalForensics
July 30, 2025 at 4:25 PM
Toby-Find is a terminal-based tool designed for digital forensics, providing users with an easy way to discover command-line tools available in KALI and REMnux. It allows quick searches for tools, descriptions, and examples, enhancing usability in forensic analysis. #DFIR #MalwareAnalysis
Toby-Find: Simplifying Command-Line Forensics Tools
Toby-Find is a terminal-based tool designed for digital forensics, providing users with an easy way to discover command-line tools available in KALI and REMnux. Initially created for a university course, it allows quick searches for tools, descriptions, and examples, enhancing usability in forensic analysis without memorization or manual searching.
bakerstreetforensics.com
July 29, 2025 at 5:30 PM
🎯 MalChela v3.0.1 is live

Sharper strings. Smarter signals.

This update includes:
✅ Improved mstrings output and MITRE mappings
🧠 Smarter regex
🔎 Built-in MITRE technique lookup (GUI)
📁 FileMiner gets “select all” + subtool optimizations
🦀 Compiled for performance

#DFIR #MalwareAnalysis
Sharper Strings and Smarter Signals: MalChela 3.0.1
🎯 MalChela v3.0.1 is live Sharper strings. Smarter signals. This update tightens forensic detection across the board: • ✅ Improved mstrings output and MITRE mappings • 🔎 Built-in MITRE technique lookup (GUI) • 📁 FileMiner gets “select all” + subtool optimizations • 🧠 Smarter regex, better signal-to-noise for analysts • 🦀 Compiled & tuned for --release performance Still a one-crab shop, but contributions welcome. 👉 🧰 Docs: #DFIR #MalwareAnalysis
bakerstreetforensics.com
July 28, 2025 at 7:15 PM
A MalChela 🦀 sighting in the wild
July 22, 2025 at 3:05 PM
Portable Forensics with Toby: A Raspberry Pi Toolkit

Toby is a compact, portable forensics toolkit built on a Raspberry Pi Zero 2 W, designed for ease of use in field analysis and malware triage.

bakerstreetforensics.com/2025/07/20/p...

#DFIR #MalwareAnalysis #RaspberryPi
Portable Forensics with Toby: A Raspberry Pi Toolkit
Toby is a compact, portable forensics toolkit built on a Raspberry Pi Zero 2 W, designed for ease of use in field analysis and malware triage. It operates headlessly via SSH or VNC, supports variou…
bakerstreetforensics.com
July 20, 2025 at 2:52 PM
Happy terrorize the dogs and veterans to all who celebrate.
July 5, 2025 at 2:42 AM
Still a work in progress but very happy with my GaZendo (gazebo/zendo) so far…
June 23, 2025 at 12:58 AM
If you’re working in #MalwareAnalysis I’d appreciate it if you gave MalChela a try and share your feedback. There’s a very comprehensive user guide to get started. github.com/dwmetz/MalCh...
github.com
June 21, 2025 at 3:44 PM
MalChela v3.0 enhances investigative workflows by introducing cases for organization, replacing MismatchMiner with FileMiner for improved file analysis, and suggesting tools based on file characteristics, streamlining the analysis process. #MalChela #DFIR #MalwareAnalysis
MalChela v3.0: Case Management, FileMiner, and Smarter Triage
MalChela v3.0 enhances investigative workflows by introducing cases for organization, replacing MismatchMiner with FileMiner for improved file analysis, and suggesting tools based on file characteristics, streamlining the analysis process. #MalChela #DFIR #MalwareAnalysis
bakerstreetforensics.com
June 21, 2025 at 2:15 AM
CyberPipe v5.1 is out with a few targeted improvements to make live response a bit smoother. Collection profiles can now be passed directly as arguments using -CollectionProfile. No need to modify the script or hardcode anything… bakerstreetforensics.com/2025/05/08/c... #DFIR
CyberPipe v5.1 – Streamlined Profiles, Better Flexibility
CyberPipe v5.1 is out with a few targeted improvements to make live response a bit smoother. What’s New: Collection profiles can now be passed directly as arguments using -CollectionProfile. No nee…
bakerstreetforensics.com
May 8, 2025 at 7:40 PM
Teepublic was kind enough to arrange a 30% + discount on MalChela swag to coordinate with the new release. Head on over and grab yourself something while the sale lasts. ~14 hrs. to go #DFIR #MalwareAnalysis #Rust www.teepublic.com/t-shirt/7325...
MalChela by baker-street-forensics
MalChela - the Rust based YARA and Malware analysis toolkit.
www.teepublic.com
May 2, 2025 at 4:23 PM