DailyDFIR

DailyDFIR

408 bookmarks
Custom sorting
#DailyDFIR 148: We've seen a big increase in virtual #DFIR events (which has been awesome!) including CTFs. If you want to build your own CTF @Russ_Taylor_ has a helpful guide documenting his experiences & advice on creating them: https://t.co/JJzl3Jm68k #CTF #Infosec
#DailyDFIR 148: We've seen a big increase in virtual #DFIR events (which has been awesome!) including CTFs. If you want to build your own CTF @Russ_Taylor_ has a helpful guide documenting his experiences & advice on creating them: https://t.co/JJzl3Jm68k #CTF #Infosec
https://twitter.com/_RyanBenson/status/1265837485893931008
·hatsoffsecurity.com·
#DailyDFIR 148: We've seen a big increase in virtual #DFIR events (which has been awesome!) including CTFs. If you want to build your own CTF @Russ_Taylor_ has a helpful guide documenting his experiences & advice on creating them: https://t.co/JJzl3Jm68k #CTF #Infosec
#DailyDFIR 147: If you write technical content about #DFIR this is a great resource. Going through the whole peer-review process for a traditional journal can be a bit daunting; @DFIRReview is a nice way to ease into that world. https://t.co/BorclJlLeN
#DailyDFIR 147: If you write technical content about #DFIR this is a great resource. Going through the whole peer-review process for a traditional journal can be a bit daunting; @DFIRReview is a nice way to ease into that world. https://t.co/BorclJlLeN
https://twitter.com/_RyanBenson/status/1265433216258682880
·twitter.com·
#DailyDFIR 147: If you write technical content about #DFIR this is a great resource. Going through the whole peer-review process for a traditional journal can be a bit daunting; @DFIRReview is a nice way to ease into that world. https://t.co/BorclJlLeN
#DailyDFIR 146: The papers from the 12th Conference on Cyber Conflict are up! 19 papers on how cyberspace & cyber conflict will evolve in the 2020s covering technical strategic & legal topics. https://t.co/DLcJTMLq61 Not exactly light holiday reading but good stuff! #DFIR
#DailyDFIR 146: The papers from the 12th Conference on Cyber Conflict are up! 19 papers on how cyberspace & cyber conflict will evolve in the 2020s covering technical strategic & legal topics. https://t.co/DLcJTMLq61 Not exactly light holiday reading but good stuff! #DFIR
https://twitter.com/_RyanBenson/status/1265044640396267520
·ccdcoe.org·
#DailyDFIR 146: The papers from the 12th Conference on Cyber Conflict are up! 19 papers on how cyberspace & cyber conflict will evolve in the 2020s covering technical strategic & legal topics. https://t.co/DLcJTMLq61 Not exactly light holiday reading but good stuff! #DFIR
#DailyDFIR 145: "Recovering & Replaying Garmin Voice Instructions" by @Cheeky4n6Monkey is a fun bit of analysis. It has data recovery log parsing & a script to "speak" the phonetic logs into audio files. https://t.co/gbm3HvvFOX You never know what a #DFIR case will entail!
#DailyDFIR 145: "Recovering & Replaying Garmin Voice Instructions" by @Cheeky4n6Monkey is a fun bit of analysis. It has data recovery log parsing & a script to "speak" the phonetic logs into audio files. https://t.co/gbm3HvvFOX You never know what a #DFIR case will entail!
https://twitter.com/_RyanBenson/status/1264754800190619648
·cheeky4n6monkey.blogspot.com·
#DailyDFIR 145: "Recovering & Replaying Garmin Voice Instructions" by @Cheeky4n6Monkey is a fun bit of analysis. It has data recovery log parsing & a script to "speak" the phonetic logs into audio files. https://t.co/gbm3HvvFOX You never know what a #DFIR case will entail!
#DailyDFIR 143: @errno_fail's blog has a lot of great technical deep dives into different artifacts with an emphasis on NTFS & Windows artifacts: https://t.co/jIK1J8hGJD He is constantly looking at new releases of Windows for changed or new artifacts! Very helpful. #DFIR
#DailyDFIR 143: @errno_fail's blog has a lot of great technical deep dives into different artifacts with an emphasis on NTFS & Windows artifacts: https://t.co/jIK1J8hGJD He is constantly looking at new releases of Windows for changed or new artifacts! Very helpful. #DFIR
https://twitter.com/_RyanBenson/status/1263988673726435328
·dfir.ru·
#DailyDFIR 143: @errno_fail's blog has a lot of great technical deep dives into different artifacts with an emphasis on NTFS & Windows artifacts: https://t.co/jIK1J8hGJD He is constantly looking at new releases of Windows for changed or new artifacts! Very helpful. #DFIR
#DailyDFIR 139: "Introduction to DFIR" by @sroberts is older (2016) but holds up well especially a section at the end: T Shaped People. https://t.co/Fl1D7m1YyG #DFIR has many subdisciplines; we can't be equally great in all areas. That's ok. Find others that compliment you. https://t.co/iNwq3tvhPv
#DailyDFIR 139: "Introduction to DFIR" by @sroberts is older (2016) but holds up well especially a section at the end: T Shaped People. https://t.co/Fl1D7m1YyG #DFIR has many subdisciplines; we can't be equally great in all areas. That's ok. Find others that compliment you. https://t.co/iNwq3tvhPv
https://twitter.com/_RyanBenson/status/1262399170494689280
·medium.com·
#DailyDFIR 139: "Introduction to DFIR" by @sroberts is older (2016) but holds up well especially a section at the end: T Shaped People. https://t.co/Fl1D7m1YyG #DFIR has many subdisciplines; we can't be equally great in all areas. That's ok. Find others that compliment you. https://t.co/iNwq3tvhPv
#DailyDFIR 138: I've said it before but I'll say it again: check out @phillmoore's "This Week in 4n6" weekly round-up. Lots of great blog posts presentations and videos on #DFIR #RE threat hunting and more! Every week. https://t.co/mOmTBCzY9B
#DailyDFIR 138: I've said it before but I'll say it again: check out @phillmoore's "This Week in 4n6" weekly round-up. Lots of great blog posts presentations and videos on #DFIR #RE threat hunting and more! Every week. https://t.co/mOmTBCzY9B
https://twitter.com/_RyanBenson/status/1262226924174102530
·twitter.com·
#DailyDFIR 138: I've said it before but I'll say it again: check out @phillmoore's "This Week in 4n6" weekly round-up. Lots of great blog posts presentations and videos on #DFIR #RE threat hunting and more! Every week. https://t.co/mOmTBCzY9B
#DailyDFIR 137: Another great post from @josh_hickman1 on detailed timeline artifacts (including from deleted apps) on @Android: https://t.co/sMLKZfixMr I love how detailed Josh's research and write-ups are; great Saturday reading material. #DFIR #Android
#DailyDFIR 137: Another great post from @josh_hickman1 on detailed timeline artifacts (including from deleted apps) on @Android: https://t.co/sMLKZfixMr I love how detailed Josh's research and write-ups are; great Saturday reading material. #DFIR #Android
https://twitter.com/_RyanBenson/status/1261851654896271361
·thebinaryhick.blog·
#DailyDFIR 137: Another great post from @josh_hickman1 on detailed timeline artifacts (including from deleted apps) on @Android: https://t.co/sMLKZfixMr I love how detailed Josh's research and write-ups are; great Saturday reading material. #DFIR #Android
#DailyDFIR 134: Want to try to write an Unfurl parser but need an idea? How about Zoom? I hear it's popular these days . If you want to try this I'd be happy to help & answer any questions. I made a GitHub issue (https://t.co/A3GwmdFDMa) with some references. #DFIR #Python
#DailyDFIR 134: Want to try to write an Unfurl parser but need an idea? How about Zoom? I hear it's popular these days . If you want to try this I'd be happy to help & answer any questions. I made a GitHub issue (https://t.co/A3GwmdFDMa) with some references. #DFIR #Python
https://twitter.com/_RyanBenson/status/1260759258758406144
·github.com·
#DailyDFIR 134: Want to try to write an Unfurl parser but need an idea? How about Zoom? I hear it's popular these days . If you want to try this I'd be happy to help & answer any questions. I made a GitHub issue (https://t.co/A3GwmdFDMa) with some references. #DFIR #Python
#DailyDFIR 133: Congrats everyone who played the @MagnetForensics CTF! The event is over but if you want to work through the challenges at your own pace it's still live at https://t.co/74h3lcAuVd. #MVS2020CTF #DFIR
#DailyDFIR 133: Congrats everyone who played the @MagnetForensics CTF! The event is over but if you want to work through the challenges at your own pace it's still live at https://t.co/74h3lcAuVd. #MVS2020CTF #DFIR
https://twitter.com/_RyanBenson/status/1260404472800374786
·mvs2020.ctfd.io·
#DailyDFIR 133: Congrats everyone who played the @MagnetForensics CTF! The event is over but if you want to work through the challenges at your own pace it's still live at https://t.co/74h3lcAuVd. #MVS2020CTF #DFIR
#DailyDFIR 132: We use hashes a lot in #DFIR; this script performs SHA-256 and shows all the steps! It's a really neat visual. The GitHub page also has nice smaller animations of different functions (shift rotate XOR) that nicely illustrate what they do. #DFIR https://t.co/ocDz3ukSt1
#DailyDFIR 132: We use hashes a lot in #DFIR; this script performs SHA-256 and shows all the steps! It's a really neat visual. The GitHub page also has nice smaller animations of different functions (shift rotate XOR) that nicely illustrate what they do. #DFIR https://t.co/ocDz3ukSt1
https://twitter.com/_RyanBenson/status/1260039175870414848
·twitter.com·
#DailyDFIR 132: We use hashes a lot in #DFIR; this script performs SHA-256 and shows all the steps! It's a really neat visual. The GitHub page also has nice smaller animations of different functions (shift rotate XOR) that nicely illustrate what they do. #DFIR https://t.co/ocDz3ukSt1
#DailyDFIR 130: A new version of Plaso is here! Highlights: Switch to libfsntfs from TSK for accessing NTFS Performance improvements Support for NTFS directories with case-sensitive entries Support Python 3.8 Blog post: https://t.co/MSU9XyUo1h #DFIR
#DailyDFIR 130: A new version of Plaso is here! Highlights: Switch to libfsntfs from TSK for accessing NTFS Performance improvements Support for NTFS directories with case-sensitive entries Support Python 3.8 Blog post: https://t.co/MSU9XyUo1h #DFIR
https://twitter.com/_RyanBenson/status/1259236194379939840
·osdfir.blogspot.com·
#DailyDFIR 130: A new version of Plaso is here! Highlights: Switch to libfsntfs from TSK for accessing NTFS Performance improvements Support for NTFS directories with case-sensitive entries Support Python 3.8 Blog post: https://t.co/MSU9XyUo1h #DFIR
#DailyDFIR 129: Part 3 of "Deciphering Browser Hieroglyphics" looks at #Chrome's FileSystem and the LevelDB databases behind it including examples from @MegaPrivacy & @Google Docs: https://t.co/zTXKd7XEGE #DFIR #LevelDB #Python
#DailyDFIR 129: Part 3 of "Deciphering Browser Hieroglyphics" looks at #Chrome's FileSystem and the LevelDB databases behind it including examples from @MegaPrivacy & @Google Docs: https://t.co/zTXKd7XEGE #DFIR #LevelDB #Python
https://twitter.com/_RyanBenson/status/1258963624816607232
·dfir.blog·
#DailyDFIR 129: Part 3 of "Deciphering Browser Hieroglyphics" looks at #Chrome's FileSystem and the LevelDB databases behind it including examples from @MegaPrivacy & @Google Docs: https://t.co/zTXKd7XEGE #DFIR #LevelDB #Python
#DailyDFIR 127: Digging into #Chrome or something Chromium-based (like Electron apps)? My "Deciphering Browser Hieroglyphics" post might help you. There is way more to Chrome than SQLite! Part 1 is "Introduction to Chromotopia": https://t.co/lL9jitTF4O #DFIR #TBT
#DailyDFIR 127: Digging into #Chrome or something Chromium-based (like Electron apps)? My "Deciphering Browser Hieroglyphics" post might help you. There is way more to Chrome than SQLite! Part 1 is "Introduction to Chromotopia": https://t.co/lL9jitTF4O #DFIR #TBT
https://twitter.com/_RyanBenson/status/1258190556213075969
·dfir.blog·
#DailyDFIR 127: Digging into #Chrome or something Chromium-based (like Electron apps)? My "Deciphering Browser Hieroglyphics" post might help you. There is way more to Chrome than SQLite! Part 1 is "Introduction to Chromotopia": https://t.co/lL9jitTF4O #DFIR #TBT
#DailyDFIR 126: This is a great looking challenge! It's nice to see variety in device and OS types becoming more common in these #DFIR challenges; helps you refresh skills you might use on a daily basis. Thanks @champdfa! Now if only I can find the time... https://t.co/M5qUeDhEtT
#DailyDFIR 126: This is a great looking challenge! It's nice to see variety in device and OS types becoming more common in these #DFIR challenges; helps you refresh skills you might use on a daily basis. Thanks @champdfa! Now if only I can find the time... https://t.co/M5qUeDhEtT
https://twitter.com/_RyanBenson/status/1257883778627670016
·twitter.com·
#DailyDFIR 126: This is a great looking challenge! It's nice to see variety in device and OS types becoming more common in these #DFIR challenges; helps you refresh skills you might use on a daily basis. Thanks @champdfa! Now if only I can find the time... https://t.co/M5qUeDhEtT
#DailyDFIR 124: Browser extensions are great but those extra features they add can also add more forensic artifacts. @Russ_Taylor_ has a nice post on recovering browsing activities from NoScript on #Firefox: https://t.co/wI2OQgtCU9 #DFIR
#DailyDFIR 124: Browser extensions are great but those extra features they add can also add more forensic artifacts. @Russ_Taylor_ has a nice post on recovering browsing activities from NoScript on #Firefox: https://t.co/wI2OQgtCU9 #DFIR
https://twitter.com/_RyanBenson/status/1257079303390457856
·hatsoffsecurity.com·
#DailyDFIR 124: Browser extensions are great but those extra features they add can also add more forensic artifacts. @Russ_Taylor_ has a nice post on recovering browsing activities from NoScript on #Firefox: https://t.co/wI2OQgtCU9 #DFIR
#DailyDFIR 122: Want to learn #DFIR? There are many virtual conferences #CTFs & trainings in May! https://t.co/Pg1KC3Ar6y by @DfirDiva https://t.co/uaRwtnNQkd by @MagnetForensics https://t.co/HFaMRdskd9 by @DFIRTraining https://t.co/fSN5Iak9bK by @aboutdfir #DFIR
#DailyDFIR 122: Want to learn #DFIR? There are many virtual conferences #CTFs & trainings in May! https://t.co/Pg1KC3Ar6y by @DfirDiva https://t.co/uaRwtnNQkd by @MagnetForensics https://t.co/HFaMRdskd9 by @DFIRTraining https://t.co/fSN5Iak9bK by @aboutdfir #DFIR
https://twitter.com/_RyanBenson/status/1256383757029789696
·dfirdiva.com·
#DailyDFIR 122: Want to learn #DFIR? There are many virtual conferences #CTFs & trainings in May! https://t.co/Pg1KC3Ar6y by @DfirDiva https://t.co/uaRwtnNQkd by @MagnetForensics https://t.co/HFaMRdskd9 by @DFIRTraining https://t.co/fSN5Iak9bK by @aboutdfir #DFIR
#DailyDFIR 120: Did you hear @aarontpeterson talk about Turbinia on the Forensic Lunch & want to learn more? Resources: Forensic Lunch: https://t.co/Nh4eSiLFBo Blog Post: https://t.co/pr6WRpdB1e Code lab: https://t.co/QgsV8MVhIe GitHub: https://t.co/hx5tZScLfo #DFIR
#DailyDFIR 120: Did you hear @aarontpeterson talk about Turbinia on the Forensic Lunch & want to learn more? Resources: Forensic Lunch: https://t.co/Nh4eSiLFBo Blog Post: https://t.co/pr6WRpdB1e Code lab: https://t.co/QgsV8MVhIe GitHub: https://t.co/hx5tZScLfo #DFIR
https://twitter.com/_RyanBenson/status/1255705275874586624
·youtu.be·
#DailyDFIR 120: Did you hear @aarontpeterson talk about Turbinia on the Forensic Lunch & want to learn more? Resources: Forensic Lunch: https://t.co/Nh4eSiLFBo Blog Post: https://t.co/pr6WRpdB1e Code lab: https://t.co/QgsV8MVhIe GitHub: https://t.co/hx5tZScLfo #DFIR
#DailyDFIR 119: Want a test file for a #DFIR tool but don't want to use one you've created (for privacy/other reasons)? The Plaso test_data & the dfirlabs "specimens" may have what you need: https://t.co/Pcli2LPS1v https://t.co/RJra22Mmie Many app & file system artifacts!
#DailyDFIR 119: Want a test file for a #DFIR tool but don't want to use one you've created (for privacy/other reasons)? The Plaso test_data & the dfirlabs "specimens" may have what you need: https://t.co/Pcli2LPS1v https://t.co/RJra22Mmie Many app & file system artifacts!
https://twitter.com/_RyanBenson/status/1255276499860705281
·github.com·
#DailyDFIR 119: Want a test file for a #DFIR tool but don't want to use one you've created (for privacy/other reasons)? The Plaso test_data & the dfirlabs "specimens" may have what you need: https://t.co/Pcli2LPS1v https://t.co/RJra22Mmie Many app & file system artifacts!
#DailyDFIR 117: If you are looking to learn mobile forensics @mattiaep's "Build Your Own Methodology" post/presentation has a fantastic collection of tools books scripts blogs and references: https://t.co/jJg0jqnXpM Bookmark & revisit later too so much good stuff #DFIR
#DailyDFIR 117: If you are looking to learn mobile forensics @mattiaep's "Build Your Own Methodology" post/presentation has a fantastic collection of tools books scripts blogs and references: https://t.co/jJg0jqnXpM Bookmark & revisit later too so much good stuff #DFIR
https://twitter.com/_RyanBenson/status/1254612204722073600
·blog.digital-forensics.it·
#DailyDFIR 117: If you are looking to learn mobile forensics @mattiaep's "Build Your Own Methodology" post/presentation has a fantastic collection of tools books scripts blogs and references: https://t.co/jJg0jqnXpM Bookmark & revisit later too so much good stuff #DFIR
#DailyDFIR 115: Some of @Google's #DFIR team will be on @HECFBlog's forensic lunch talking about our open source forensic tools! It's going to be packed with people tools & knowledge: https://t.co/Wa3ifEP5RY It's 90 min from NOW (at 8am Pacific / 11am Eastern) Don't miss it!
#DailyDFIR 115: Some of @Google's #DFIR team will be on @HECFBlog's forensic lunch talking about our open source forensic tools! It's going to be packed with people tools & knowledge: https://t.co/Wa3ifEP5RY It's 90 min from NOW (at 8am Pacific / 11am Eastern) Don't miss it!
https://twitter.com/_RyanBenson/status/1253677573202206721
·youtube.com·
#DailyDFIR 115: Some of @Google's #DFIR team will be on @HECFBlog's forensic lunch talking about our open source forensic tools! It's going to be packed with people tools & knowledge: https://t.co/Wa3ifEP5RY It's 90 min from NOW (at 8am Pacific / 11am Eastern) Don't miss it!
#DailyDFIR 114: Playing an online CTF? I created a Python notebook & write-up showing how I answered questions in the @MagnetForensics #CTF using open source tools: Plaso Timesketch Colab / #Python Blog: https://t.co/gqxATPnacm Notebook: https://t.co/nj9EMUuzd2 #DFIR
#DailyDFIR 114: Playing an online CTF? I created a Python notebook & write-up showing how I answered questions in the @MagnetForensics #CTF using open source tools: Plaso Timesketch Colab / #Python Blog: https://t.co/gqxATPnacm Notebook: https://t.co/nj9EMUuzd2 #DFIR
https://twitter.com/_RyanBenson/status/1253482673382633472
·dfir.blog·
#DailyDFIR 114: Playing an online CTF? I created a Python notebook & write-up showing how I answered questions in the @MagnetForensics #CTF using open source tools: Plaso Timesketch Colab / #Python Blog: https://t.co/gqxATPnacm Notebook: https://t.co/nj9EMUuzd2 #DFIR