Found 408 bookmarks
Newest
#DailyDFIR 278: I still have some Unfurl stickers left! If you'd like one send me a DM or email with where you'd like it sent (while they last). I've loved all the stickers being sent around in #DFIR; it makes not having live conferences a bit better. https://t.co/MpnnnnrxOH
#DailyDFIR 278: I still have some Unfurl stickers left! If you'd like one send me a DM or email with where you'd like it sent (while they last). I've loved all the stickers being sent around in #DFIR; it makes not having live conferences a bit better. https://t.co/MpnnnnrxOH
http://twitter.com/_RyanBenson/status/1312863712571617280
·twitter.com·
#DailyDFIR 278: I still have some Unfurl stickers left! If you'd like one send me a DM or email with where you'd like it sent (while they last). I've loved all the stickers being sent around in #DFIR; it makes not having live conferences a bit better. https://t.co/MpnnnnrxOH
#DailyDFIR 277: Nice post by @_D00mfist (from @SpecterOps) outlining a #macOS persistence technique. It uses the Dock and is similar in concept to persisting via Windows .LNK files: https://t.co/GEAsYB2sGT Bonus points for including detection tips as well! #DFIR
#DailyDFIR 277: Nice post by @_D00mfist (from @SpecterOps) outlining a #macOS persistence technique. It uses the Dock and is similar in concept to persisting via Windows .LNK files: https://t.co/GEAsYB2sGT Bonus points for including detection tips as well! #DFIR
http://twitter.com/_RyanBenson/status/1312602200380641283
·posts.specterops.io·
#DailyDFIR 277: Nice post by @_D00mfist (from @SpecterOps) outlining a #macOS persistence technique. It uses the Dock and is similar in concept to persisting via Windows .LNK files: https://t.co/GEAsYB2sGT Bonus points for including detection tips as well! #DFIR
#DailyDFIR 276: The #OSDFCon agenda has been released. It's online free and you can still register! Agenda: https://t.co/rCX3pZW8Yv Register: https://t.co/nrIU6KcrAf Come see talks about great #opensource #DFIR tools!
#DailyDFIR 276: The #OSDFCon agenda has been released. It's online free and you can still register! Agenda: https://t.co/rCX3pZW8Yv Register: https://t.co/nrIU6KcrAf Come see talks about great #opensource #DFIR tools!
http://twitter.com/_RyanBenson/status/1312220715370774528
·osdfcon.org·
#DailyDFIR 276: The #OSDFCon agenda has been released. It's online free and you can still register! Agenda: https://t.co/rCX3pZW8Yv Register: https://t.co/nrIU6KcrAf Come see talks about great #opensource #DFIR tools!
#DailyDFIR 276: The #OSDFCon agenda has been released. It's online free and you can still register! Agenda: https://t.co/rCX3pZW8Yv Register: https://t.co/nrIU6KcrAf Come see talks about great #opensource #DFIR tools!
#DailyDFIR 276: The #OSDFCon agenda has been released. It's online free and you can still register! Agenda: https://t.co/rCX3pZW8Yv Register: https://t.co/nrIU6KcrAf Come see talks about great #opensource #DFIR tools!
http://twitter.com/_RyanBenson/status/1312220715370774528
·osdfcon.org·
#DailyDFIR 276: The #OSDFCon agenda has been released. It's online free and you can still register! Agenda: https://t.co/rCX3pZW8Yv Register: https://t.co/nrIU6KcrAf Come see talks about great #opensource #DFIR tools!
#DailyDFIR 275: Hunting for webshells? Check out this tool & post by @Tstillz1. It's cross-platform multi-threaded and handles many obfuscation types: Post : https://t.co/DRMOGqCF6S Tool : https://t.co/V67UAGecqT #DFIR #webshell #Golang
#DailyDFIR 275: Hunting for webshells? Check out this tool & post by @Tstillz1. It's cross-platform multi-threaded and handles many obfuscation types: Post : https://t.co/DRMOGqCF6S Tool : https://t.co/V67UAGecqT #DFIR #webshell #Golang
http://twitter.com/_RyanBenson/status/1311878900109041664
·github.com·
#DailyDFIR 275: Hunting for webshells? Check out this tool & post by @Tstillz1. It's cross-platform multi-threaded and handles many obfuscation types: Post : https://t.co/DRMOGqCF6S Tool : https://t.co/V67UAGecqT #DFIR #webshell #Golang
#DailyDFIR 275: Hunting for webshells? Check out this tool & post by @Tstillz1. It's cross-platform multi-threaded and handles many obfuscation types: Post : https://t.co/DRMOGqCF6S Tool : https://t.co/V67UAGecqT #DFIR #webshell #Golang
#DailyDFIR 275: Hunting for webshells? Check out this tool & post by @Tstillz1. It's cross-platform multi-threaded and handles many obfuscation types: Post : https://t.co/DRMOGqCF6S Tool : https://t.co/V67UAGecqT #DFIR #webshell #Golang
http://twitter.com/_RyanBenson/status/1311878900109041664
·blog.stillztech.com·
#DailyDFIR 275: Hunting for webshells? Check out this tool & post by @Tstillz1. It's cross-platform multi-threaded and handles many obfuscation types: Post : https://t.co/DRMOGqCF6S Tool : https://t.co/V67UAGecqT #DFIR #webshell #Golang
#DailyDFIR 274: @SANSInstitute is hosting a free online event tomorrow (Oct-1) called "BIPOC in Cybersecurity Forum: From Inclusion to Equity" hosted by @hexplates & @stephenahart and featuring many more great speakers. Check it out! https://t.co/st0FGaZklk #DFIR #InfoSec
#DailyDFIR 274: @SANSInstitute is hosting a free online event tomorrow (Oct-1) called "BIPOC in Cybersecurity Forum: From Inclusion to Equity" hosted by @hexplates & @stephenahart and featuring many more great speakers. Check it out! https://t.co/st0FGaZklk #DFIR #InfoSec
http://twitter.com/_RyanBenson/status/1311463973343043584
·sans.org·
#DailyDFIR 274: @SANSInstitute is hosting a free online event tomorrow (Oct-1) called "BIPOC in Cybersecurity Forum: From Inclusion to Equity" hosted by @hexplates & @stephenahart and featuring many more great speakers. Check it out! https://t.co/st0FGaZklk #DFIR #InfoSec
#DailyDFIR 273: A few weeks ago I was on "Life Has No CtrlAltDel" with @HeatherMahalik giving an overview of Unfurl (https://t.co/H5XHNrawum) how to use it & walking through (many) examples. The video recording is now up! https://t.co/7vf7frXS3f #DFIR @Cellebrite_UFED
#DailyDFIR 273: A few weeks ago I was on "Life Has No CtrlAltDel" with @HeatherMahalik giving an overview of Unfurl (https://t.co/H5XHNrawum) how to use it & walking through (many) examples. The video recording is now up! https://t.co/7vf7frXS3f #DFIR @Cellebrite_UFED
http://twitter.com/_RyanBenson/status/1310989688606318594
·cellebrite.com·
#DailyDFIR 273: A few weeks ago I was on "Life Has No CtrlAltDel" with @HeatherMahalik giving an overview of Unfurl (https://t.co/H5XHNrawum) how to use it & walking through (many) examples. The video recording is now up! https://t.co/7vf7frXS3f #DFIR @Cellebrite_UFED
#DailyDFIR 271: In case you missed @DFRWS USA 2020 (like me) @ForensicFocus has a nice recap of the event: https://t.co/MrOhPecob4 Lots of interesting talks I'd love to see; anyone know if recordings will be posted? Since it was virtual I'm hoping there's a chance. #DFIR
#DailyDFIR 271: In case you missed @DFRWS USA 2020 (like me) @ForensicFocus has a nice recap of the event: https://t.co/MrOhPecob4 Lots of interesting talks I'd love to see; anyone know if recordings will be posted? Since it was virtual I'm hoping there's a chance. #DFIR
http://twitter.com/_RyanBenson/status/1310390684080173056
·forensicfocus.com·
#DailyDFIR 271: In case you missed @DFRWS USA 2020 (like me) @ForensicFocus has a nice recap of the event: https://t.co/MrOhPecob4 Lots of interesting talks I'd love to see; anyone know if recordings will be posted? Since it was virtual I'm hoping there's a chance. #DFIR
#DailyDFIR 270: Check out @joachimmetz's post on testing digital forensic data processing tools: https://t.co/h6MWv5Is6v The work we do in #DFIR is important; it can have serious consequences. It's important that our tools are as robust accurate & transparent as possible.
#DailyDFIR 270: Check out @joachimmetz's post on testing digital forensic data processing tools: https://t.co/h6MWv5Is6v The work we do in #DFIR is important; it can have serious consequences. It's important that our tools are as robust accurate & transparent as possible.
http://twitter.com/_RyanBenson/status/1309931305916796928
·osdfir.blogspot.com·
#DailyDFIR 270: Check out @joachimmetz's post on testing digital forensic data processing tools: https://t.co/h6MWv5Is6v The work we do in #DFIR is important; it can have serious consequences. It's important that our tools are as robust accurate & transparent as possible.
#DailyDFIR 269: My "Tinkering with TikTok Timestamps" post finished peer-review and is posted on @DFIRReview! Check it out if you want to learn how to extract when a #TikTok video was posted from the URL alone (even if video is deleted or private). #DFIR https://t.co/lMJHmdYrBG https://t.co/lPI3NEjwr9
#DailyDFIR 269: My "Tinkering with TikTok Timestamps" post finished peer-review and is posted on @DFIRReview! Check it out if you want to learn how to extract when a #TikTok video was posted from the URL alone (even if video is deleted or private). #DFIR https://t.co/lMJHmdYrBG https://t.co/lPI3NEjwr9
http://twitter.com/_RyanBenson/status/1309609062271610880
·twitter.com·
#DailyDFIR 269: My "Tinkering with TikTok Timestamps" post finished peer-review and is posted on @DFIRReview! Check it out if you want to learn how to extract when a #TikTok video was posted from the URL alone (even if video is deleted or private). #DFIR https://t.co/lMJHmdYrBG https://t.co/lPI3NEjwr9
#DailyDFIR 269: My "Tinkering with TikTok Timestamps" post finished peer-review and is posted on @DFIRReview! Check it out if you want to learn how to extract when a #TikTok video was posted from the URL alone (even if video is deleted or private). #DFIR https://t.co/lMJHmdYrBG https://t.co/lPI3NEjwr9
#DailyDFIR 269: My "Tinkering with TikTok Timestamps" post finished peer-review and is posted on @DFIRReview! Check it out if you want to learn how to extract when a #TikTok video was posted from the URL alone (even if video is deleted or private). #DFIR https://t.co/lMJHmdYrBG https://t.co/lPI3NEjwr9
http://twitter.com/_RyanBenson/status/1309609062271610880
·twitter.com·
#DailyDFIR 269: My "Tinkering with TikTok Timestamps" post finished peer-review and is posted on @DFIRReview! Check it out if you want to learn how to extract when a #TikTok video was posted from the URL alone (even if video is deleted or private). #DFIR https://t.co/lMJHmdYrBG https://t.co/lPI3NEjwr9
@forensicmike1 @rasriis Yeah definitely. @CiofecaForensic has a great post on iteratively building a .proto (https://t.co/MiQWuMY3V6) and @SwiftForensics has one comparing different protobuf-decoding methods (https://t.co/uUnzmg9GAj)
@forensicmike1 @rasriis Yeah definitely. @CiofecaForensic has a great post on iteratively building a .proto (https://t.co/MiQWuMY3V6) and @SwiftForensics has one comparing different protobuf-decoding methods (https://t.co/uUnzmg9GAj)
http://twitter.com/_RyanBenson/status/1309517581175328769
·swiftforensics.com·
@forensicmike1 @rasriis Yeah definitely. @CiofecaForensic has a great post on iteratively building a .proto (https://t.co/MiQWuMY3V6) and @SwiftForensics has one comparing different protobuf-decoding methods (https://t.co/uUnzmg9GAj)
obsidianforensics/unfurl
obsidianforensics/unfurl
http://twitter.com/_RyanBenson/status/1309516888162988032
·github.com·
obsidianforensics/unfurl
nccgroup/blackboxprotobuf
nccgroup/blackboxprotobuf
http://twitter.com/_RyanBenson/status/1309516888162988032
·github.com·
nccgroup/blackboxprotobuf
#DailyDFIR 268: If you've looked at Google search URLs you might have noticed the "ved" parameter in query string. Some fun facts about it: There are four versions of the "ved" Two versions contain timestamps More: https://t.co/HqnumPxVDZ #DFIR #OSINT #TBT https://t.co/Urc3bckXwa
#DailyDFIR 268: If you've looked at Google search URLs you might have noticed the "ved" parameter in query string. Some fun facts about it: There are four versions of the "ved" Two versions contain timestamps More: https://t.co/HqnumPxVDZ #DFIR #OSINT #TBT https://t.co/Urc3bckXwa
http://twitter.com/_RyanBenson/status/1309338218697908226
·dfir.blog·
#DailyDFIR 268: If you've looked at Google search URLs you might have noticed the "ved" parameter in query string. Some fun facts about it: There are four versions of the "ved" Two versions contain timestamps More: https://t.co/HqnumPxVDZ #DFIR #OSINT #TBT https://t.co/Urc3bckXwa
#DailyDFIR 268: If you've looked at Google search URLs you might have noticed the "ved" parameter in query string. Some fun facts about it: There are four versions of the "ved" Two versions contain timestamps More: https://t.co/HqnumPxVDZ #DFIR #OSINT #TBT https://t.co/Urc3bckXwa
#DailyDFIR 268: If you've looked at Google search URLs you might have noticed the "ved" parameter in query string. Some fun facts about it: There are four versions of the "ved" Two versions contain timestamps More: https://t.co/HqnumPxVDZ #DFIR #OSINT #TBT https://t.co/Urc3bckXwa
http://twitter.com/_RyanBenson/status/1309338218697908226
·twitter.com·
#DailyDFIR 268: If you've looked at Google search URLs you might have noticed the "ved" parameter in query string. Some fun facts about it: There are four versions of the "ved" Two versions contain timestamps More: https://t.co/HqnumPxVDZ #DFIR #OSINT #TBT https://t.co/Urc3bckXwa
#DailyDFIR 265: More #iOS14 #DFIR resources: @HeatherMahalik reviews different acquisition methods & common artifacts for iOS 14: https://t.co/7ujgXtEAfS checkra1n support for iOS 14 (older devices only): https://t.co/9FiJGm1p5N #mobile4n6
#DailyDFIR 265: More #iOS14 #DFIR resources: @HeatherMahalik reviews different acquisition methods & common artifacts for iOS 14: https://t.co/7ujgXtEAfS checkra1n support for iOS 14 (older devices only): https://t.co/9FiJGm1p5N #mobile4n6
http://twitter.com/_RyanBenson/status/1308255968292081664
·checkra.in·
#DailyDFIR 265: More #iOS14 #DFIR resources: @HeatherMahalik reviews different acquisition methods & common artifacts for iOS 14: https://t.co/7ujgXtEAfS checkra1n support for iOS 14 (older devices only): https://t.co/9FiJGm1p5N #mobile4n6
#DailyDFIR 265: More #iOS14 #DFIR resources: @HeatherMahalik reviews different acquisition methods & common artifacts for iOS 14: https://t.co/7ujgXtEAfS checkra1n support for iOS 14 (older devices only): https://t.co/9FiJGm1p5N #mobile4n6
#DailyDFIR 265: More #iOS14 #DFIR resources: @HeatherMahalik reviews different acquisition methods & common artifacts for iOS 14: https://t.co/7ujgXtEAfS checkra1n support for iOS 14 (older devices only): https://t.co/9FiJGm1p5N #mobile4n6
http://twitter.com/_RyanBenson/status/1308255968292081664
·smarterforensics.com·
#DailyDFIR 265: More #iOS14 #DFIR resources: @HeatherMahalik reviews different acquisition methods & common artifacts for iOS 14: https://t.co/7ujgXtEAfS checkra1n support for iOS 14 (older devices only): https://t.co/9FiJGm1p5N #mobile4n6
RT @Cheeky4n6Monkey: Watch @_RyanBenson's SANS DFIR Summit 2020 presentation to learn more about his cool tool "unfurl" here: https://t.co/UoPbnlNZmG Bonus: Ryan also highlights some interesting "hidden" URL parameter/metadata e.g. timestamps GUIDs. Aweseome stuff!
RT @Cheeky4n6Monkey: Watch @_RyanBenson's SANS DFIR Summit 2020 presentation to learn more about his cool tool "unfurl" here: https://t.co/UoPbnlNZmG Bonus: Ryan also highlights some interesting "hidden" URL parameter/metadata e.g. timestamps GUIDs. Aweseome stuff!
http://twitter.com/_RyanBenson/status/1308034716021317634
·t.co·
RT @Cheeky4n6Monkey: Watch @_RyanBenson's SANS DFIR Summit 2020 presentation to learn more about his cool tool "unfurl" here: https://t.co/UoPbnlNZmG Bonus: Ryan also highlights some interesting "hidden" URL parameter/metadata e.g. timestamps GUIDs. Aweseome stuff!
#DailyDFIR 264: New blog started by @theAtropos4n6 has some nice posts on cloud sync apps (Dropbox Google Drive) and the Chrome Logins database: https://t.co/llBImRkAPr Great job excited to see what comes next! #DFIR
#DailyDFIR 264: New blog started by @theAtropos4n6 has some nice posts on cloud sync apps (Dropbox Google Drive) and the Chrome Logins database: https://t.co/llBImRkAPr Great job excited to see what comes next! #DFIR
http://twitter.com/_RyanBenson/status/1307882782023012352
·atropos4n6.com·
#DailyDFIR 264: New blog started by @theAtropos4n6 has some nice posts on cloud sync apps (Dropbox Google Drive) and the Chrome Logins database: https://t.co/llBImRkAPr Great job excited to see what comes next! #DFIR
#DailyDFIR 263: This detailed post by @CiofecaForensic shows the iterative process of detective work used to build a .proto file for an unknown protobuf: https://t.co/MiQWuMY3V6 If you are interested in learning to decipher unknown protobufs this post is a great read. #DFIR
#DailyDFIR 263: This detailed post by @CiofecaForensic shows the iterative process of detective work used to build a .proto file for an unknown protobuf: https://t.co/MiQWuMY3V6 If you are interested in learning to decipher unknown protobufs this post is a great read. #DFIR
http://twitter.com/_RyanBenson/status/1307452374357737472
·ciofecaforensics.com·
#DailyDFIR 263: This detailed post by @CiofecaForensic shows the iterative process of detective work used to build a .proto file for an unknown protobuf: https://t.co/MiQWuMY3V6 If you are interested in learning to decipher unknown protobufs this post is a great read. #DFIR
#DailyDFIR 262: Check out the video of @williballenthin's talk on automatically identifying malware capabilities with their open source capa tool: https://t.co/xaVC4NxGDV Great talk from the @SANSInstitute @DFIRSummit. #DFIR #RE
#DailyDFIR 262: Check out the video of @williballenthin's talk on automatically identifying malware capabilities with their open source capa tool: https://t.co/xaVC4NxGDV Great talk from the @SANSInstitute @DFIRSummit. #DFIR #RE
http://twitter.com/_RyanBenson/status/1307165492147150848
·youtube.com·
#DailyDFIR 262: Check out the video of @williballenthin's talk on automatically identifying malware capabilities with their open source capa tool: https://t.co/xaVC4NxGDV Great talk from the @SANSInstitute @DFIRSummit. #DFIR #RE
#DailyDFIR 261: iOS 14 is here! Here's a few "what's changed for #DFIR" posts: https://t.co/Eg0QA60lNm & https://t.co/albpK5v6oR by @cScottVance https://t.co/aebZ5Mqpf9 by @CiofecaForensic tl;dr: it's mostly the same (minor changes). More differences will appear as we dig in.
#DailyDFIR 261: iOS 14 is here! Here's a few "what's changed for #DFIR" posts: https://t.co/Eg0QA60lNm & https://t.co/albpK5v6oR by @cScottVance https://t.co/aebZ5Mqpf9 by @CiofecaForensic tl;dr: it's mostly the same (minor changes). More differences will appear as we dig in.
http://twitter.com/_RyanBenson/status/1306692121160638464
·blog.d204n6.com·
#DailyDFIR 261: iOS 14 is here! Here's a few "what's changed for #DFIR" posts: https://t.co/Eg0QA60lNm & https://t.co/albpK5v6oR by @cScottVance https://t.co/aebZ5Mqpf9 by @CiofecaForensic tl;dr: it's mostly the same (minor changes). More differences will appear as we dig in.