A user reports that all the files in their documents/desktop folders are gone after returning to the office on Monday. They swear they didn’t delete them.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A user reports that all the files in their documents/desktop folders are gone after returning to the office on Monday. They swear they didn’t delete them.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
github.com/yetkind/Wind...
#Windows10 #Cybersecurity #Security #Infosec #Hardening
github.com/yetkind/Wind...
#Windows10 #Cybersecurity #Security #Infosec #Hardening
As they are "too difficult" or "not worth it."
Forget tool loyalties—as multi-tooling is vital.
DFIR experts, what's your take?
Why wouldn't they even try?
Is this the norm?
#DFIR #DigitalForensics
As they are "too difficult" or "not worth it."
Forget tool loyalties—as multi-tooling is vital.
DFIR experts, what's your take?
Why wouldn't they even try?
Is this the norm?
#DFIR #DigitalForensics
Check out dfir.pubpub.org to help with that.
While the process isn’t as fast as I would like it (we could use more reviewers and volunteers to help with publication)
Check out dfir.pubpub.org to help with that.
While the process isn’t as fast as I would like it (we could use more reviewers and volunteers to help with publication)
They are fully documented with timestamps.
They have been an invaluable resource when making parsers for the #LEAPPS.
Check them out.
#DigitalForensics
They are fully documented with timestamps.
They have been an invaluable resource when making parsers for the #LEAPPS.
Check them out.
#DigitalForensics
Use this emoji 📌 (pushpin emoji)!
BUT FIRST: Click this link. Like/Follow the feed. It'll take you to a bookmark feed where all of your bookmarks are in one place! Pin it, and you'll be able to access them easily.
Then, you can 📌 with ease!
bsky.app/profile/did:...
Use this emoji 📌 (pushpin emoji)!
BUT FIRST: Click this link. Like/Follow the feed. It'll take you to a bookmark feed where all of your bookmarks are in one place! Pin it, and you'll be able to access them easily.
Then, you can 📌 with ease!
bsky.app/profile/did:...
Current tools are missing a lot of data from these Private Spaces. Notice how #ALEAPP parses it out.
#MobileForensics
Current tools are missing a lot of data from these Private Spaces. Notice how #ALEAPP parses it out.
#MobileForensics
#DigitalForensics #DFIR #MobileForensics
#DigitalForensics #DFIR #MobileForensics