BBK
beanbagking.bsky.social
BBK
@beanbagking.bsky.social
DFIR, etc. @ https://nullsec.us
Reposted by BBK
🎉 It’s time for a new 13Cubed episode! We’ll briefly explore how process hollowing works and check out the relatively new windows.hollowprocesses plugin for Volatility 3. There are also two memory samples you can download for practice! www.youtube.com/watch?v=x5mG... #DFIR
A New(ish) Way to Detect Process Hollowing
YouTube video by 13Cubed
www.youtube.com
May 23, 2025 at 11:07 AM
Reposted by BBK
The argument for deterrence through vulnerability reduction has been favored as it allows for abdication of government responsibility & the transfer to private sector of task (& risks) of directly confronting hostile foreign military & intelligence services, something done in no other warfare domain
January 6, 2025 at 1:19 PM
Reposted by BBK
Happy New Year! 🎉🥳 The first 13Cubed episode of 2025 is here! Let's explore some groundbreaking research from CyberCX on “rewinding the NTFS USN Journal.” www.youtube.com/watch?v=GDc8... #DFIR
Be Kind, Rewind... The USN Journal
YouTube video by 13Cubed
www.youtube.com
January 6, 2025 at 12:36 PM
Ever since I was a wee lad, all I've wanted was an original physical copy of CSC-STD-002-85. Since I was disappointed yet again this year, I decided to make my own.

github.com/BeanBagKing/...
github.com
January 4, 2025 at 1:52 PM
Reposted by BBK
The XPlat Bundle includes:

-Investigating Windows Endpoints
-Investigating Windows Memory
-Investigating Linux Devices

Learn more about it here: training.13cubed.com/xplat-bundle
XPlat Bundle
Master XPlat (cross-platform) Windows and Linux forensic investigation with the ultimate bundle: 365-day access to Investigating Windows Endpoints, Investigating Windows Memory, and Investigating Linu...
training.13cubed.com
January 1, 2025 at 10:48 PM
Reposted by BBK
Happy New Year! I partnered with @13cubed.bsky.social for a giveaway of his XPlat training/certification Bundle!

To Enter: Like, Repost, and Leave a Comment

On January 12th, 1 winner will be chosen from LinkedIn and 1 winner will be chosen from Bluesky.

#DFIR #DigitalForensics #IncidentResponse
January 1, 2025 at 10:48 PM