watanen
watanen.bsky.social
watanen
@watanen.bsky.social
Reposted by watanen
U.S. DoJ Dismantles Warzone RAT Infrastructure, Arrests Key Operators #cybersecurity #infosec #privacy #news thehackernews.com/20...
February 11, 2024 at 11:38 AM
Reposted by watanen
My team just released dfiq.org, which is "a collection of Digital Forensics Investigative Questions and the approaches to answering them."

The idea came from the will to organize investigative approaches to similar cases to increase consistency across response efforts. #dfir #infosec
Home - DFIQ (Digital Forensics Investigative Questions)
dfiq.org
August 14, 2023 at 11:18 AM
Reposted by watanen
"My arsenal of AWS security tools" is a catalog of open-source tools for AWS protection, including defensive, offensive, auditing, and DFIR solutions.

github.com/toniblyx/my-...
October 4, 2023 at 5:46 PM
Reposted by watanen
My team had an encounter in a recent #DFIR situation where we saw a #CobaltStrike feature in use by the perpetrators we hadn't seen before: "sleep mask", which obfuscates memory content while the beacon is inactive, making #Yara signatures come up empty. Blog post here:
cyber.wtf/2023/10/13/c...
October 13, 2023 at 2:41 PM
Reposted by watanen
DFIR Reference Frameworks

Large collection of links to documentation that explains the meaning of terms from different areas of DFIR.
Incident Response
Malware Analysis
Threat Intelligence
Proactive Response
Threat Hunting
Insider Threat
github.com/joshlemon/DF...
Contributor twitter.com/joshlemon
October 16, 2023 at 5:04 PM
Reposted by watanen
Digital Forensics Lab

(lesson slides)

- Basic Computer Skills for DFIR
- Basic Networking Skills for DFIR
- Computer and DFIR
- Computer Forensics Case Study
- Mobile/IoT Forensics Case Study
- Forensic Intelligence Repository
- AI for Forensics

github.com/frankwxu/dig...
October 19, 2023 at 11:55 PM
Reposted by watanen
This is my #autopsy #forensics install and tips list for my #DFIR analysis system.
Does anyone have other tips to share?

www.fancy4n6.com/docs/resourc...
Autopsy Forensics
Getting started with Autopsy # It can seem daunting when starting out in DFIR and looking at all the tools and how much money might need to be expended to get a lab set up to even practice. But don’...
www.fancy4n6.com
November 1, 2023 at 2:40 AM
I imported 7 friends from Twitter to Bluesky
Import your Twitter follows to Bluesky
skygaze.io
December 24, 2023 at 11:58 AM