Kevin 🤖🕵️🍺
banner
stark4n6.bsky.social
Kevin 🤖🕵️🍺
@stark4n6.bsky.social
Lethal forensicator, researcher, developer, blogger, curator of many fine t-shirt designs, resident #DFIR beer drinker

https://startme.stark4n6.com
Pinned
New here? Check out my one stop shop of #DFIR resources startme.stark4n6.com
Reposted by Kevin 🤖🕵️🍺
Per chi desidera fare pratica di #InformaticaForense o testare nuovi software, The Evidence Locker di @KevinPagano3 raccoglie e cataloga numerose immagini forensi pronte per il download!

#DigitalForensics #DFIR
The Evidence Locker - A DFIR Image Compendium
  What started as an idea a month or two ago, has become a reality. Introducing The Evidence Locker , a compiled repository of publicly avai...
www.stark4n6.com
November 13, 2025 at 4:35 PM
Reposted by Kevin 🤖🕵️🍺
Weekly update. New features in OneDriveExplorer, Onedrive Evolution and schema updates. #DFIR
malwaremaloney.blogspot.com/2025/11/oned...
OneDrive updates
What's new in OneDriveExplorer OnedDriveExplorer v2025.11.07 now includes a dedicated parser for Microsoft.FilesOnDemand....
malwaremaloney.blogspot.com
November 7, 2025 at 2:54 PM
Reposted by Kevin 🤖🕵️🍺
CyberPipe-Timeliner was developed to integrate Magnet Response collections with ForensicTimeliner. This tool automates the workflow of EZTools, and transforms collection data into a unified forensic timeline. #DFIR
CyberPipe-Timeliner: From Collection to Timeline in One Script
CyberPipe-Timeliner was developed in response to a colleague's query about integrating Magnet Response collections with ForensicTimeliner. This tool automates the workflow, transforming collection data into a unified forensic timeline. With features like date filtering and flexible input options, it streamlines the timeline generation process, making it efficient and user-friendly. #DFIR
bakerstreetforensics.com
November 5, 2025 at 4:23 PM
I cannot stress this enough, asset management should be a big part of your cybersecurity response plan
October 28, 2025 at 2:26 PM
Reposted by Kevin 🤖🕵️🍺
A common theme in #DFIR is putting the target behind the keyboard. One way to help is around the use of passcodes and especially the use of biometrics. On Oct 29, join us for our next #MobileUnpacked where @cscottvance.bsky.social will dive deeper into these topics: ow.ly/p1r550XgvXb
S3:E10 // Picking apart the passcodes: Determining the method of unlock on devices - Magnet Forensics
A common theme in digital forensics is putting the target behind the keyboard. One way to help this is around the use of passcodes and especially the use of biometrics. How can we determine though wha...
ow.ly
October 22, 2025 at 7:01 PM
Reposted by Kevin 🤖🕵️🍺
On October 22, join us for a webinar where we'll share common challenges in #MobileForensics within #WorkplaceInvestigations, and how the combined power of Magnet #Verakey & #AxiomCyber help solve them: ow.ly/Erk350XeoFs #DFIR
Overcoming mobile forensics challenges in workplace investigations - Magnet Forensics
Mobile devices have become indispensable tools in the modern workplace, enabling more than just checking email. Employees now browse the web, access sensitive company data, and conduct daily business ...
ow.ly
October 17, 2025 at 8:58 PM
Reposted by Kevin 🤖🕵️🍺
Did a little digging in Microsoft.FileUsageSync.db. Found some information to piece together OneDrive Quick Access. #DFIR
malwaremaloney.blogspot.com/2025/10/oned...
MALoney (It's in the name): OneDrive Quick Access
What is Quick access? Quick access makes it simple to find your frequently used storage locations, inclu...
malwaremaloney.blogspot.com
October 16, 2025 at 3:42 AM
Reposted by Kevin 🤖🕵️🍺
CyberPipe, a PowerShell script for digital evidence collection, has been updated with enhancements in collection, capabilities, and reliability. New features include intelligent collection with dual disk space validation, a QuickTriage profile, and improved BitLocker recovery. #DFIR
Streamline Digital Evidence Collection with CyberPipe 5.2
CyberPipe, developed for incident response, is a PowerShell script facilitating efficient digital evidence collection in enterprise settings. Recent updates include improved collection methods, capabilities like QuickTriage for faster artifact gathering, and enhanced reliability with advanced error handling. Version 5.2 aims to streamline operations while ensuring forensic integrity and transparency. #DFIR
bakerstreetforensics.com
October 16, 2025 at 2:24 PM
Anyone else's work issued laptop just bluescreen crash weekly or is it just me?!
October 14, 2025 at 7:56 PM
Reposted by Kevin 🤖🕵️🍺
Did a little digging in Microsoft.FileUsageSync.db. Found some information to piece together OneDrive Quick Access. #DFIR
malwaremaloney.blogspot.com/2025/10/oned...
MALoney (It's in the name): OneDrive Quick Access
What is Quick access? Quick access makes it simple to find your frequently used storage locations, inclu...
malwaremaloney.blogspot.com
October 8, 2025 at 9:37 PM
Reposted by Kevin 🤖🕵️🍺
A trick and a treat this week with a quiet milestone for cross-platform DFIR tooling — MalChelaGUI now runs seamlessly inside Windows through Ubuntu WSL2, with zero configuration required. #DFIR #MalwareAnalysis
Cross-Platform DFIR Tools: MalChelaGUI on Windows
A trick and a treat this week with a quiet milestone for cross-platform DFIR tooling — MalChelaGUI now runs seamlessly inside Windows through Ubuntu WSL2, with zero configuration required. #DFIR #MalwareAnalysis
bakerstreetforensics.com
October 7, 2025 at 7:50 PM
Reposted by Kevin 🤖🕵️🍺
The 13th annual @volatilityfoundation.org #PluginContest is now OPEN! This is a meaningful way to contribute to open source forensics & gain community-wide visibility for your work. And, as always, winners get cash prizes!

Submission Deadline: 31 December 2025

#dfir #memoryforensics
The 13th Annual Volatility Plugin Contest is Open!
We are excited to announce that the Volatility Plugin Contest is officially open for submissions! The annual Plugin Contest is your opportunity to: Directly contribute to the open source forensics …
volatilityfoundation.org
July 24, 2025 at 6:59 PM
This is gonna be a good one, I may be biased!
October 1, 2025 at 6:07 PM
Reposted by Kevin 🤖🕵️🍺
In case you missed it. New release of OneDriveExplorer. It has a dedicated parser for MicrosoftListSync.db (offline mode). #DFIR

malwaremaloney.blogspot.com/2025/09/oned...
MALoney (It's in the name): OneDrive. Let's take this offline
At the beginning of this year, I started adding data from the offline databases into OneDrive Explorer. This data enhanced...
malwaremaloney.blogspot.com
September 30, 2025 at 2:27 AM
Reposted by Kevin 🤖🕵️🍺
This week's #MobileUnpacked is going to be a big one! Join us as @cscottvance.bsky.social explores the brand-new #iOS26, including UX changes of #LiquidGlass, and updates to the Phone & Messages app that could have serious impacts. Save your spot now: ow.ly/zr8150X0bp7
S3:E9 // NOW That’s what I call iOS: 26 - Magnet Forensics
Apple has hit the jump to light speed and jumped from iOS 18 to iOS 26! In this episode of Mobile Unpacked we’ll explore the new changes and challenges Apple’s yearly upgrade cycle is bringing to the ...
ow.ly
September 22, 2025 at 1:42 PM
Reposted by Kevin 🤖🕵️🍺
PancakesCon & @comfyconau.bsky.social are THIS SUNDAY, September 21st. Here are some final notes on how to make the most of virtual conferences and where to find useful information! pancakescon.com/2025/09/17/f...
Final Pre-Conference Notes for 2025
PancakesCon is this coming Sunday, the 21st of September (running into the 22nd for some of us!). It will start at 6AM Central US Time (Chicago), for a very good reason. No, I have not become a mor…
pancakescon.com
September 18, 2025 at 2:55 AM
Reposted by Kevin 🤖🕵️🍺
The death of Robert Redford (RIP) means the window to rewatch Hackers in honor of the 30th anniversary has officially closed and it is now time to re-watch Sneakers. (Time to rewatch Sneakers will continue indefinitely.)
September 16, 2025 at 10:06 PM