DailyDFIR

DailyDFIR

408 bookmarks
Oldest
#DailyDFIR 290: @ShaneHuntley on what @Google's Threat Analysis Group is seeing: Phishing by APT groups targeting US elections Threat actors targeting drug companies & COVID-19 researchers Tackling state-sponsored DDoS attacks Post: https://t.co/ummLRFP5pE #DFIR
#DailyDFIR 290: @ShaneHuntley on what @Google's Threat Analysis Group is seeing: Phishing by APT groups targeting US elections Threat actors targeting drug companies & COVID-19 researchers Tackling state-sponsored DDoS attacks Post: https://t.co/ummLRFP5pE #DFIR
http://twitter.com/_RyanBenson/status/1317304361203109890
·blog.google·
#DailyDFIR 290: @ShaneHuntley on what @Google's Threat Analysis Group is seeing: Phishing by APT groups targeting US elections Threat actors targeting drug companies & COVID-19 researchers Tackling state-sponsored DDoS attacks Post: https://t.co/ummLRFP5pE #DFIR
#DailyDFIR 291: Want to know what information you can extract from the @Apple HomePod and other HomeKit devices? Check out this presentation by @mattiaep from the @SANSInstitute @DFIRSummit 2020: https://t.co/0P3kgv6LB6 #DFIR #Apple #iOS
#DailyDFIR 291: Want to know what information you can extract from the @Apple HomePod and other HomeKit devices? Check out this presentation by @mattiaep from the @SANSInstitute @DFIRSummit 2020: https://t.co/0P3kgv6LB6 #DFIR #Apple #iOS
http://twitter.com/_RyanBenson/status/1317663967888637952
·youtube.com·
#DailyDFIR 291: Want to know what information you can extract from the @Apple HomePod and other HomeKit devices? Check out this presentation by @mattiaep from the @SANSInstitute @DFIRSummit 2020: https://t.co/0P3kgv6LB6 #DFIR #Apple #iOS
#DailyDFIR 292: The "Wellbeing" database on #Android devices tracks an incredible amount of things & can be used to create detailed timelines. Watch this video from @AlexisBrignoni & @josh_hickman1 to learn more about it: https://t.co/uIINhbgg9Q #DFIR #mobile4n6 #DFIRSummit
#DailyDFIR 292: The "Wellbeing" database on #Android devices tracks an incredible amount of things & can be used to create detailed timelines. Watch this video from @AlexisBrignoni & @josh_hickman1 to learn more about it: https://t.co/uIINhbgg9Q #DFIR #mobile4n6 #DFIRSummit
http://twitter.com/_RyanBenson/status/1318025836293885952
·youtube.com·
#DailyDFIR 292: The "Wellbeing" database on #Android devices tracks an incredible amount of things & can be used to create detailed timelines. Watch this video from @AlexisBrignoni & @josh_hickman1 to learn more about it: https://t.co/uIINhbgg9Q #DFIR #mobile4n6 #DFIRSummit
#DailyDFIR 294: Kubernetes is great and all but what happens if you have a security incident and need to investigate the cluster? @jason_solomon explains how to deploy and use GRR to dig into incidents in #k8s: https://t.co/GHy4s9jKQ4 #DFIR #Kubernetes #Docker
#DailyDFIR 294: Kubernetes is great and all but what happens if you have a security incident and need to investigate the cluster? @jason_solomon explains how to deploy and use GRR to dig into incidents in #k8s: https://t.co/GHy4s9jKQ4 #DFIR #Kubernetes #Docker
http://twitter.com/_RyanBenson/status/1318760666233122817
·osdfir.blogspot.com·
#DailyDFIR 294: Kubernetes is great and all but what happens if you have a security incident and need to investigate the cluster? @jason_solomon explains how to deploy and use GRR to dig into incidents in #k8s: https://t.co/GHy4s9jKQ4 #DFIR #Kubernetes #Docker
#DailyDFIR 295: @FIRSTdotOrg has released an ethics framework for #DFIR and #infosec teams divided into 12 principles: https://t.co/MIlWHDYEQC Those of us in #DFIR positions often have incredible access power and trust; we need to act ethically and responsibly.
#DailyDFIR 295: @FIRSTdotOrg has released an ethics framework for #DFIR and #infosec teams divided into 12 principles: https://t.co/MIlWHDYEQC Those of us in #DFIR positions often have incredible access power and trust; we need to act ethically and responsibly.
http://twitter.com/_RyanBenson/status/1319134907847725057
·ethicsfirst.org·
#DailyDFIR 295: @FIRSTdotOrg has released an ethics framework for #DFIR and #infosec teams divided into 12 principles: https://t.co/MIlWHDYEQC Those of us in #DFIR positions often have incredible access power and trust; we need to act ethically and responsibly.
#DailyDFIR 299: The #CellebriteCTF just went live! Check it out for some mobile forensics challenges! https://t.co/yb7CTmcAtE Even if you are new to analyzing phones give it a try. There's no better way to learn than getting your hands dirty. #DFIR
#DailyDFIR 299: The #CellebriteCTF just went live! Check it out for some mobile forensics challenges! https://t.co/yb7CTmcAtE Even if you are new to analyzing phones give it a try. There's no better way to learn than getting your hands dirty. #DFIR
http://twitter.com/_RyanBenson/status/1320583630482108416
·cellebrite.ctfd.io·
#DailyDFIR 299: The #CellebriteCTF just went live! Check it out for some mobile forensics challenges! https://t.co/yb7CTmcAtE Even if you are new to analyzing phones give it a try. There's no better way to learn than getting your hands dirty. #DFIR
#DailyDFIR 300: I'll be on #CacheUp tomorrow morning! Come watch live or catch the replay/podcast version later. If there's any specific questions or things you'd like to see on the episode let me know! #DFIR https://t.co/BHsW1vqt0n
#DailyDFIR 300: I'll be on #CacheUp tomorrow morning! Come watch live or catch the replay/podcast version later. If there's any specific questions or things you'd like to see on the episode let me know! #DFIR https://t.co/BHsW1vqt0n
http://twitter.com/_RyanBenson/status/1320873146002542597
·twitter.com·
#DailyDFIR 300: I'll be on #CacheUp tomorrow morning! Come watch live or catch the replay/podcast version later. If there's any specific questions or things you'd like to see on the episode let me know! #DFIR https://t.co/BHsW1vqt0n
#DailyDFIR 301: Today on #CacheUp with @B1N2H3X I talked a little about how I've generated test "user data" for every version of Chrome to use for tool development. If you'd like more info on the process I use check out: https://t.co/jgm2m5ZxRr #DFIR #Chrome #dataviz #Python
#DailyDFIR 301: Today on #CacheUp with @B1N2H3X I talked a little about how I've generated test "user data" for every version of Chrome to use for tool development. If you'd like more info on the process I use check out: https://t.co/jgm2m5ZxRr #DFIR #Chrome #dataviz #Python
http://twitter.com/_RyanBenson/status/1321289441248530432
·dfir.blog·
#DailyDFIR 301: Today on #CacheUp with @B1N2H3X I talked a little about how I've generated test "user data" for every version of Chrome to use for tool development. If you'd like more info on the process I use check out: https://t.co/jgm2m5ZxRr #DFIR #Chrome #dataviz #Python
#DailyDFIR 304: @ElcomSoft's blog just hit the 500 posts mark! That's quite the accomplishment. In addition to the hundreds of posts they've written they also list some free or open source tools you can add to your arsenal: https://t.co/VBwbgeN5ZD #DFIR #mobile4n6
#DailyDFIR 304: @ElcomSoft's blog just hit the 500 posts mark! That's quite the accomplishment. In addition to the hundreds of posts they've written they also list some free or open source tools you can add to your arsenal: https://t.co/VBwbgeN5ZD #DFIR #mobile4n6
http://twitter.com/_RyanBenson/status/1322377417634193408
·blog.elcomsoft.com·
#DailyDFIR 304: @ElcomSoft's blog just hit the 500 posts mark! That's quite the accomplishment. In addition to the hundreds of posts they've written they also list some free or open source tools you can add to your arsenal: https://t.co/VBwbgeN5ZD #DFIR #mobile4n6
#DailyDFIR 306: Happy end of Daylight Savings Time! (maybe depending on where you are.) If all these clock shenanigans have ever driven you a bit nuts during an incident this guy can relate: https://t.co/sebzEbtucr #DFIR
#DailyDFIR 306: Happy end of Daylight Savings Time! (maybe depending on where you are.) If all these clock shenanigans have ever driven you a bit nuts during an incident this guy can relate: https://t.co/sebzEbtucr #DFIR
http://twitter.com/_RyanBenson/status/1323100022943014913
·youtube.com·
#DailyDFIR 306: Happy end of Daylight Savings Time! (maybe depending on where you are.) If all these clock shenanigans have ever driven you a bit nuts during an incident this guy can relate: https://t.co/sebzEbtucr #DFIR
#DailyDFIR 309: It can't help you understand the election but Unfurl can help you understand URLs! A new Unfurl release (20201102) is here! It adds: New examples page Improved parsing of Google & Bing searches Parsing #TikTok IDs & more! Try it: https://t.co/H5XHNrawum https://t.co/MYQy4taOAt
#DailyDFIR 309: It can't help you understand the election but Unfurl can help you understand URLs! A new Unfurl release (20201102) is here! It adds: New examples page Improved parsing of Google & Bing searches Parsing #TikTok IDs & more! Try it: https://t.co/H5XHNrawum https://t.co/MYQy4taOAt
http://twitter.com/_RyanBenson/status/1324068544808587265
·twitter.com·
#DailyDFIR 309: It can't help you understand the election but Unfurl can help you understand URLs! A new Unfurl release (20201102) is here! It adds: New examples page Improved parsing of Google & Bing searches Parsing #TikTok IDs & more! Try it: https://t.co/H5XHNrawum https://t.co/MYQy4taOAt
#DailyDFIR 310: UUIDv4 (random) is much more common than UUIDv1 (time- & MAC-based) online these days. But UUIDv1s still do appear & the embedded timestamp may be useful. Example: https://t.co/pxrrUAfUyD PS: Advertising emails are a great source of interesting URLs #DFIR https://t.co/AWzbteVcpO
#DailyDFIR 310: UUIDv4 (random) is much more common than UUIDv1 (time- & MAC-based) online these days. But UUIDv1s still do appear & the embedded timestamp may be useful. Example: https://t.co/pxrrUAfUyD PS: Advertising emails are a great source of interesting URLs #DFIR https://t.co/AWzbteVcpO
http://twitter.com/_RyanBenson/status/1324361326089564160
·dfir.blog·
#DailyDFIR 310: UUIDv4 (random) is much more common than UUIDv1 (time- & MAC-based) online these days. But UUIDv1s still do appear & the embedded timestamp may be useful. Example: https://t.co/pxrrUAfUyD PS: Advertising emails are a great source of interesting URLs #DFIR https://t.co/AWzbteVcpO
#DailyDFIR 310: UUIDv4 (random) is much more common than UUIDv1 (time- & MAC-based) online these days. But UUIDv1s still do appear & the embedded timestamp may be useful. Example: https://t.co/pxrrUAfUyD PS: Advertising emails are a great source of interesting URLs #DFIR https://t.co/AWzbteVcpO
#DailyDFIR 310: UUIDv4 (random) is much more common than UUIDv1 (time- & MAC-based) online these days. But UUIDv1s still do appear & the embedded timestamp may be useful. Example: https://t.co/pxrrUAfUyD PS: Advertising emails are a great source of interesting URLs #DFIR https://t.co/AWzbteVcpO
http://twitter.com/_RyanBenson/status/1324361326089564160
·twitter.com·
#DailyDFIR 310: UUIDv4 (random) is much more common than UUIDv1 (time- & MAC-based) online these days. But UUIDv1s still do appear & the embedded timestamp may be useful. Example: https://t.co/pxrrUAfUyD PS: Advertising emails are a great source of interesting URLs #DFIR https://t.co/AWzbteVcpO
#DailyDFIR 311: CyberChef is a fantastic utility that's incredibly useful (and easy to use) for a range of #DFIR & #RE tasks. @GlassSec walks through how to go from "Cybersecurity Zero to Hero with CyberChef" in his talk from @RVAsec 2019: https://t.co/wv1Rv6AdsM
#DailyDFIR 311: CyberChef is a fantastic utility that's incredibly useful (and easy to use) for a range of #DFIR & #RE tasks. @GlassSec walks through how to go from "Cybersecurity Zero to Hero with CyberChef" in his talk from @RVAsec 2019: https://t.co/wv1Rv6AdsM
http://twitter.com/_RyanBenson/status/1324933139534245888
·youtube.com·
#DailyDFIR 311: CyberChef is a fantastic utility that's incredibly useful (and easy to use) for a range of #DFIR & #RE tasks. @GlassSec walks through how to go from "Cybersecurity Zero to Hero with CyberChef" in his talk from @RVAsec 2019: https://t.co/wv1Rv6AdsM
#DailyDFIR 312: @CiofecaForensic has some great write-ups of the recent @Cellebrite CTF. A fantastic thing is that their team used only free tools demonstrating that you can do top-notch analysis on a budget: https://t.co/KUnQBjFXKE #DFIR #mobile4n6 #OpenSource #CTF
#DailyDFIR 312: @CiofecaForensic has some great write-ups of the recent @Cellebrite CTF. A fantastic thing is that their team used only free tools demonstrating that you can do top-notch analysis on a budget: https://t.co/KUnQBjFXKE #DFIR #mobile4n6 #OpenSource #CTF
http://twitter.com/_RyanBenson/status/1325305914971230212
·ciofecaforensics.com·
#DailyDFIR 312: @CiofecaForensic has some great write-ups of the recent @Cellebrite CTF. A fantastic thing is that their team used only free tools demonstrating that you can do top-notch analysis on a budget: https://t.co/KUnQBjFXKE #DFIR #mobile4n6 #OpenSource #CTF
#DailyDFIR 313: Myself @el_killerdwarf & @alexanderjaeger will be presenting TOMORROW at 8am Pacific / 11am Eastern on how to use Timesketch and #Python notebooks to solve #DFIR challenges! Register: https://t.co/Ti4s5C9HOy Join us & ask questions! #OpenSource #OSDFCon
#DailyDFIR 313: Myself @el_killerdwarf & @alexanderjaeger will be presenting TOMORROW at 8am Pacific / 11am Eastern on how to use Timesketch and #Python notebooks to solve #DFIR challenges! Register: https://t.co/Ti4s5C9HOy Join us & ask questions! #OpenSource #OSDFCon
http://twitter.com/_RyanBenson/status/1325594897131319297
·basistech.com·
#DailyDFIR 313: Myself @el_killerdwarf & @alexanderjaeger will be presenting TOMORROW at 8am Pacific / 11am Eastern on how to use Timesketch and #Python notebooks to solve #DFIR challenges! Register: https://t.co/Ti4s5C9HOy Join us & ask questions! #OpenSource #OSDFCon
#DailyDFIR 314: iLEAPP & ALEAPP by @AlexisBrignoni (& others!) have been on a tear recently with new features: Autopsy integration: https://t.co/qERybp52Ts Map visualizations photo.sqlite parsing update DFRWS video posted: https://t.co/DE5sa8YkUk Check it out! #DFIR
#DailyDFIR 314: iLEAPP & ALEAPP by @AlexisBrignoni (& others!) have been on a tear recently with new features: Autopsy integration: https://t.co/qERybp52Ts Map visualizations photo.sqlite parsing update DFRWS video posted: https://t.co/DE5sa8YkUk Check it out! #DFIR
http://twitter.com/_RyanBenson/status/1326005235798609920
·autopsy.com·
#DailyDFIR 314: iLEAPP & ALEAPP by @AlexisBrignoni (& others!) have been on a tear recently with new features: Autopsy integration: https://t.co/qERybp52Ts Map visualizations photo.sqlite parsing update DFRWS video posted: https://t.co/DE5sa8YkUk Check it out! #DFIR
#DailyDFIR 314: iLEAPP & ALEAPP by @AlexisBrignoni (& others!) have been on a tear recently with new features: Autopsy integration: https://t.co/qERybp52Ts Map visualizations photo.sqlite parsing update DFRWS video posted: https://t.co/DE5sa8YkUk Check it out! #DFIR
#DailyDFIR 314: iLEAPP & ALEAPP by @AlexisBrignoni (& others!) have been on a tear recently with new features: Autopsy integration: https://t.co/qERybp52Ts Map visualizations photo.sqlite parsing update DFRWS video posted: https://t.co/DE5sa8YkUk Check it out! #DFIR
http://twitter.com/_RyanBenson/status/1326005235798609920
·youtube.com·
#DailyDFIR 314: iLEAPP & ALEAPP by @AlexisBrignoni (& others!) have been on a tear recently with new features: Autopsy integration: https://t.co/qERybp52Ts Map visualizations photo.sqlite parsing update DFRWS video posted: https://t.co/DE5sa8YkUk Check it out! #DFIR
#DailyDFIR 315: If you missed our talk on "Exploring the Wonders of Timesketch and Jupyter" yesterday (or want to watch it again at a slower speed we went through a lot) the recording is up! https://t.co/2ONWXOJerd We talked about using #Python to tackle a #DFIR challenge!
#DailyDFIR 315: If you missed our talk on "Exploring the Wonders of Timesketch and Jupyter" yesterday (or want to watch it again at a slower speed we went through a lot) the recording is up! https://t.co/2ONWXOJerd We talked about using #Python to tackle a #DFIR challenge!
http://twitter.com/_RyanBenson/status/1326216403871952897
·youtube.com·
#DailyDFIR 315: If you missed our talk on "Exploring the Wonders of Timesketch and Jupyter" yesterday (or want to watch it again at a slower speed we went through a lot) the recording is up! https://t.co/2ONWXOJerd We talked about using #Python to tackle a #DFIR challenge!
#DailyDFIR 316: @j_duffy01 has a write-up on @Snapchat and what data can be extracted from the #iOS app: https://t.co/BH81Ni8Udw Nice analysis walkthrough touching on SQLite GUIDs timestamps & protobufs! #DFIR
#DailyDFIR 316: @j_duffy01 has a write-up on @Snapchat and what data can be extracted from the #iOS app: https://t.co/BH81Ni8Udw Nice analysis walkthrough touching on SQLite GUIDs timestamps & protobufs! #DFIR
http://twitter.com/_RyanBenson/status/1326729108806492161
·duffy.app·
#DailyDFIR 316: @j_duffy01 has a write-up on @Snapchat and what data can be extracted from the #iOS app: https://t.co/BH81Ni8Udw Nice analysis walkthrough touching on SQLite GUIDs timestamps & protobufs! #DFIR
#DailyDFIR 317: After reading @j_duffy01's post on @Snapchat for #iOS I was interested & looked at the #Android version (in @josh_hickman1's Android 11 image). It's different but still has protobufs in SQLite DBs. Unfurl can help with those! https://t.co/JpAy4Tx8mS #DFIR https://t.co/YjqYO3yDP4
#DailyDFIR 317: After reading @j_duffy01's post on @Snapchat for #iOS I was interested & looked at the #Android version (in @josh_hickman1's Android 11 image). It's different but still has protobufs in SQLite DBs. Unfurl can help with those! https://t.co/JpAy4Tx8mS #DFIR https://t.co/YjqYO3yDP4
http://twitter.com/_RyanBenson/status/1327093045242724352
·dfir.blog·
#DailyDFIR 317: After reading @j_duffy01's post on @Snapchat for #iOS I was interested & looked at the #Android version (in @josh_hickman1's Android 11 image). It's different but still has protobufs in SQLite DBs. Unfurl can help with those! https://t.co/JpAy4Tx8mS #DFIR https://t.co/YjqYO3yDP4
#DailyDFIR 317: After reading @j_duffy01's post on @Snapchat for #iOS I was interested & looked at the #Android version (in @josh_hickman1's Android 11 image). It's different but still has protobufs in SQLite DBs. Unfurl can help with those! https://t.co/JpAy4Tx8mS #DFIR https://t.co/YjqYO3yDP4
#DailyDFIR 317: After reading @j_duffy01's post on @Snapchat for #iOS I was interested & looked at the #Android version (in @josh_hickman1's Android 11 image). It's different but still has protobufs in SQLite DBs. Unfurl can help with those! https://t.co/JpAy4Tx8mS #DFIR https://t.co/YjqYO3yDP4
http://twitter.com/_RyanBenson/status/1327093045242724352
·twitter.com·
#DailyDFIR 317: After reading @j_duffy01's post on @Snapchat for #iOS I was interested & looked at the #Android version (in @josh_hickman1's Android 11 image). It's different but still has protobufs in SQLite DBs. Unfurl can help with those! https://t.co/JpAy4Tx8mS #DFIR https://t.co/YjqYO3yDP4