DailyDFIR

DailyDFIR

408 bookmarks
Oldest
#DailyDFIR 318: I'm seeing write-ups on #Malware hosted on #Discord but this is nothing new. Reminder that @Discord file attachments have an embedded timestamp (that tells when the file was uploaded) and Unfurl can parse that out for you: https://t.co/oFgrN4OxYh #DFIR #RE https://t.co/Qbj0OZCNL6
#DailyDFIR 318: I'm seeing write-ups on #Malware hosted on #Discord but this is nothing new. Reminder that @Discord file attachments have an embedded timestamp (that tells when the file was uploaded) and Unfurl can parse that out for you: https://t.co/oFgrN4OxYh #DFIR #RE https://t.co/Qbj0OZCNL6
http://twitter.com/_RyanBenson/status/1327453385075822593
·dfir.blog·
#DailyDFIR 318: I'm seeing write-ups on #Malware hosted on #Discord but this is nothing new. Reminder that @Discord file attachments have an embedded timestamp (that tells when the file was uploaded) and Unfurl can parse that out for you: https://t.co/oFgrN4OxYh #DFIR #RE https://t.co/Qbj0OZCNL6
#DailyDFIR 318: I'm seeing write-ups on #Malware hosted on #Discord but this is nothing new. Reminder that @Discord file attachments have an embedded timestamp (that tells when the file was uploaded) and Unfurl can parse that out for you: https://t.co/oFgrN4OxYh #DFIR #RE https://t.co/Qbj0OZCNL6
#DailyDFIR 318: I'm seeing write-ups on #Malware hosted on #Discord but this is nothing new. Reminder that @Discord file attachments have an embedded timestamp (that tells when the file was uploaded) and Unfurl can parse that out for you: https://t.co/oFgrN4OxYh #DFIR #RE https://t.co/Qbj0OZCNL6
http://twitter.com/_RyanBenson/status/1327453385075822593
·twitter.com·
#DailyDFIR 318: I'm seeing write-ups on #Malware hosted on #Discord but this is nothing new. Reminder that @Discord file attachments have an embedded timestamp (that tells when the file was uploaded) and Unfurl can parse that out for you: https://t.co/oFgrN4OxYh #DFIR #RE https://t.co/Qbj0OZCNL6
#DailyDFIR 319: When I look at #SQLite DBs 3 tools I use often are: sqlite3 CLI DB Browser for SQLite (https://t.co/Hekxentu6g) #OpenSource cross-platform SQLite Expert (https://t.co/ip6W34tO3r) Free version/Windows only If you like a different one what is it? #DFIR
#DailyDFIR 319: When I look at #SQLite DBs 3 tools I use often are: sqlite3 CLI DB Browser for SQLite (https://t.co/Hekxentu6g) #OpenSource cross-platform SQLite Expert (https://t.co/ip6W34tO3r) Free version/Windows only If you like a different one what is it? #DFIR
http://twitter.com/_RyanBenson/status/1327821731524792321
·sqlitebrowser.org·
#DailyDFIR 319: When I look at #SQLite DBs 3 tools I use often are: sqlite3 CLI DB Browser for SQLite (https://t.co/Hekxentu6g) #OpenSource cross-platform SQLite Expert (https://t.co/ip6W34tO3r) Free version/Windows only If you like a different one what is it? #DFIR
#DailyDFIR 319: When I look at #SQLite DBs 3 tools I use often are: sqlite3 CLI DB Browser for SQLite (https://t.co/Hekxentu6g) #OpenSource cross-platform SQLite Expert (https://t.co/ip6W34tO3r) Free version/Windows only If you like a different one what is it? #DFIR
#DailyDFIR 319: When I look at #SQLite DBs 3 tools I use often are: sqlite3 CLI DB Browser for SQLite (https://t.co/Hekxentu6g) #OpenSource cross-platform SQLite Expert (https://t.co/ip6W34tO3r) Free version/Windows only If you like a different one what is it? #DFIR
http://twitter.com/_RyanBenson/status/1327821731524792321
·sqliteexpert.com·
#DailyDFIR 319: When I look at #SQLite DBs 3 tools I use often are: sqlite3 CLI DB Browser for SQLite (https://t.co/Hekxentu6g) #OpenSource cross-platform SQLite Expert (https://t.co/ip6W34tO3r) Free version/Windows only If you like a different one what is it? #DFIR
#DailyDFIR 320: Interested in what happened on a #Linux (or #macOS) system? The .bash_history file is a valuable artifact - but it has its quirks. Check out "You Dont Know Jack About .bash_history" by @hal_pomeranz: https://t.co/4yH0F3g1X9 I found it very helpful! #DFIR
#DailyDFIR 320: Interested in what happened on a #Linux (or #macOS) system? The .bash_history file is a valuable artifact - but it has its quirks. Check out "You Dont Know Jack About .bash_history" by @hal_pomeranz: https://t.co/4yH0F3g1X9 I found it very helpful! #DFIR
http://twitter.com/_RyanBenson/status/1328179453273337856
·youtube.com·
#DailyDFIR 320: Interested in what happened on a #Linux (or #macOS) system? The .bash_history file is a valuable artifact - but it has its quirks. Check out "You Dont Know Jack About .bash_history" by @hal_pomeranz: https://t.co/4yH0F3g1X9 I found it very helpful! #DFIR
#DailyDFIR 323: Have a bunch of Sigma rules that you'd like to use on data you've collected into Timesketch? @alexanderjaeger has a write-up explaining how to get started: https://t.co/gDFLKhZPW0 #DFIR #Sigma #IOC
#DailyDFIR 323: Have a bunch of Sigma rules that you'd like to use on data you've collected into Timesketch? @alexanderjaeger has a write-up explaining how to get started: https://t.co/gDFLKhZPW0 #DFIR #Sigma #IOC
http://twitter.com/_RyanBenson/status/1329264275307732992
·osdfir.blogspot.com·
#DailyDFIR 323: Have a bunch of Sigma rules that you'd like to use on data you've collected into Timesketch? @alexanderjaeger has a write-up explaining how to get started: https://t.co/gDFLKhZPW0 #DFIR #Sigma #IOC
#DailyDFIR 326: Every year as part of #OSDFCon there is a contest for new Autopsy modules. A compilation video of this year's submissions is available: https://t.co/8m8fW7nGis Lots of interesting ideas! Thanks to all the participants for their additions to #OpenSource #DFIR!
#DailyDFIR 326: Every year as part of #OSDFCon there is a contest for new Autopsy modules. A compilation video of this year's submissions is available: https://t.co/8m8fW7nGis Lots of interesting ideas! Thanks to all the participants for their additions to #OpenSource #DFIR!
http://twitter.com/_RyanBenson/status/1330366622071197698
·youtube.com·
#DailyDFIR 326: Every year as part of #OSDFCon there is a contest for new Autopsy modules. A compilation video of this year's submissions is available: https://t.co/8m8fW7nGis Lots of interesting ideas! Thanks to all the participants for their additions to #OpenSource #DFIR!
#DailyDFIR 327: In this post @alexanderjaeger explores Garmin .Fit files including parsing them in #Python uploading to #Timesketch then analyzing the data with #Pandas: https://t.co/sGIaWSktuC Really puts the #DFIR in #DFIRFit!
#DailyDFIR 327: In this post @alexanderjaeger explores Garmin .Fit files including parsing them in #Python uploading to #Timesketch then analyzing the data with #Pandas: https://t.co/sGIaWSktuC Really puts the #DFIR in #DFIRFit!
http://twitter.com/_RyanBenson/status/1330736952849563648
·alexanderjaeger.de·
#DailyDFIR 327: In this post @alexanderjaeger explores Garmin .Fit files including parsing them in #Python uploading to #Timesketch then analyzing the data with #Pandas: https://t.co/sGIaWSktuC Really puts the #DFIR in #DFIRFit!
#DailyDFIR 328: How about a double-dose of @brianjmoran? Brian is a great guy who is active in the #DFIR & #DFIRFit communities. Check out: Interview on #CacheUp: https://t.co/W3TOkaLShl OSDFCon talk on reconstructing RDP activity images: https://t.co/W3TOkaLShl #DFIR
#DailyDFIR 328: How about a double-dose of @brianjmoran? Brian is a great guy who is active in the #DFIR & #DFIRFit communities. Check out: Interview on #CacheUp: https://t.co/W3TOkaLShl OSDFCon talk on reconstructing RDP activity images: https://t.co/W3TOkaLShl #DFIR
http://twitter.com/_RyanBenson/status/1331073771998900230
·youtube.com·
#DailyDFIR 328: How about a double-dose of @brianjmoran? Brian is a great guy who is active in the #DFIR & #DFIRFit communities. Check out: Interview on #CacheUp: https://t.co/W3TOkaLShl OSDFCon talk on reconstructing RDP activity images: https://t.co/W3TOkaLShl #DFIR
#DailyDFIR 329: Chrome 87 is here with its typical slew of fixes & new behind-the-scenes features (including tab throttling & back/forward cache). I've updated my interactive "Chrome Evolution" page: https://t.co/EFjQ4e9vKr #DFIR #Chrome #Visualization #infosec https://t.co/LWDfbMtB47
#DailyDFIR 329: Chrome 87 is here with its typical slew of fixes & new behind-the-scenes features (including tab throttling & back/forward cache). I've updated my interactive "Chrome Evolution" page: https://t.co/EFjQ4e9vKr #DFIR #Chrome #Visualization #infosec https://t.co/LWDfbMtB47
http://twitter.com/_RyanBenson/status/1331250721912745989
·twitter.com·
#DailyDFIR 329: Chrome 87 is here with its typical slew of fixes & new behind-the-scenes features (including tab throttling & back/forward cache). I've updated my interactive "Chrome Evolution" page: https://t.co/EFjQ4e9vKr #DFIR #Chrome #Visualization #infosec https://t.co/LWDfbMtB47
#DailyDFIR 330: @jaco_ZA has a post on the genesis evolution & future of #Emotet (complete with year-appropriate pop culture references): https://t.co/7BP9lYFuGh Easy to read & informative write-up about a complex and long-lived threat. Nice Jaco! #DFIR #Malware #infosec
#DailyDFIR 330: @jaco_ZA has a post on the genesis evolution & future of #Emotet (complete with year-appropriate pop culture references): https://t.co/7BP9lYFuGh Easy to read & informative write-up about a complex and long-lived threat. Nice Jaco! #DFIR #Malware #infosec
http://twitter.com/_RyanBenson/status/1331804978164289536
·dfir.co.za·
#DailyDFIR 330: @jaco_ZA has a post on the genesis evolution & future of #Emotet (complete with year-appropriate pop culture references): https://t.co/7BP9lYFuGh Easy to read & informative write-up about a complex and long-lived threat. Nice Jaco! #DFIR #Malware #infosec
#DailyDFIR 333: @iamevltwin's APOLLO tool for iOS & macOS uses #Python & SQL queries to extract a ton of information. Sarah's #OSDFCon talk shows how to get started analyzing this data for user activity application usage & more! https://t.co/HkWhGJNfXH #DFIR #openSource
#DailyDFIR 333: @iamevltwin's APOLLO tool for iOS & macOS uses #Python & SQL queries to extract a ton of information. Sarah's #OSDFCon talk shows how to get started analyzing this data for user activity application usage & more! https://t.co/HkWhGJNfXH #DFIR #openSource
http://twitter.com/_RyanBenson/status/1332829736284823554
·youtube.com·
#DailyDFIR 333: @iamevltwin's APOLLO tool for iOS & macOS uses #Python & SQL queries to extract a ton of information. Sarah's #OSDFCon talk shows how to get started analyzing this data for user activity application usage & more! https://t.co/HkWhGJNfXH #DFIR #openSource
#DailyDFIR 335: There's a great deal from @humble right now - while it's called the "Hacking 101" bundle it has great #DFIR titles from @nostarch like @mikesiko's Practical Malware Analysis & @chrissanders88's Practical Packet Analysis: https://t.co/AW0xinFFoM Check it out!
#DailyDFIR 335: There's a great deal from @humble right now - while it's called the "Hacking 101" bundle it has great #DFIR titles from @nostarch like @mikesiko's Practical Malware Analysis & @chrissanders88's Practical Packet Analysis: https://t.co/AW0xinFFoM Check it out!
http://twitter.com/_RyanBenson/status/1333582910402641925
·humblebundle.com·
#DailyDFIR 335: There's a great deal from @humble right now - while it's called the "Hacking 101" bundle it has great #DFIR titles from @nostarch like @mikesiko's Practical Malware Analysis & @chrissanders88's Practical Packet Analysis: https://t.co/AW0xinFFoM Check it out!
#DailyDFIR 336: I'm not sure how or when but I have a feeling that the M1 Mac clock ticking every 41.67 ns (instead of every 1 ns) is going to cause #DFIR pain: https://t.co/rNwjQmR0Ge @howardnoakley's blog is a great source of in-depth technical explanations on Mac topics!
#DailyDFIR 336: I'm not sure how or when but I have a feeling that the M1 Mac clock ticking every 41.67 ns (instead of every 1 ns) is going to cause #DFIR pain: https://t.co/rNwjQmR0Ge @howardnoakley's blog is a great source of in-depth technical explanations on Mac topics!
http://twitter.com/_RyanBenson/status/1333985252348346372
·eclecticlight.co·
#DailyDFIR 336: I'm not sure how or when but I have a feeling that the M1 Mac clock ticking every 41.67 ns (instead of every 1 ns) is going to cause #DFIR pain: https://t.co/rNwjQmR0Ge @howardnoakley's blog is a great source of in-depth technical explanations on Mac topics!
#DailyDFIR 337: @theAtropos4n6 has a post on examining Windows Event Logs to identify volumes & VSNs on USB drives: https://t.co/J8dwfGi731 This isn't a new artifact but the thorough research methodology could help you see something that otherwise might be overlooked. #DFIR
#DailyDFIR 337: @theAtropos4n6 has a post on examining Windows Event Logs to identify volumes & VSNs on USB drives: https://t.co/J8dwfGi731 This isn't a new artifact but the thorough research methodology could help you see something that otherwise might be overlooked. #DFIR
http://twitter.com/_RyanBenson/status/1334343970109812739
·atropos4n6.com·
#DailyDFIR 337: @theAtropos4n6 has a post on examining Windows Event Logs to identify volumes & VSNs on USB drives: https://t.co/J8dwfGi731 This isn't a new artifact but the thorough research methodology could help you see something that otherwise might be overlooked. #DFIR
#DailyDFIR 338: Looking for a #DFIR tool reference or video but aren't quite sure which one? @KevinPagano3 has a @startme page that might help you out: https://t.co/NKeITluoB4 I like looking through people's lists of tools & resources; I almost always find something new!
#DailyDFIR 338: Looking for a #DFIR tool reference or video but aren't quite sure which one? @KevinPagano3 has a @startme page that might help you out: https://t.co/NKeITluoB4 I like looking through people's lists of tools & resources; I almost always find something new!
http://twitter.com/_RyanBenson/status/1334701621381529602
·stark4n6.com·
#DailyDFIR 338: Looking for a #DFIR tool reference or video but aren't quite sure which one? @KevinPagano3 has a @startme page that might help you out: https://t.co/NKeITluoB4 I like looking through people's lists of tools & resources; I almost always find something new!
#DailyDFIR 339: A new version of APOLLO from @iamevltwin is out! Lots of updates for iOS14 & macOS 11 and also added "gather" functions to collect the SQLite DBs from target devices: Blog: https://t.co/83Jh8dKcYC Tool: https://t.co/myaQ8hv83g #DFIR #mac4n6 #Python
#DailyDFIR 339: A new version of APOLLO from @iamevltwin is out! Lots of updates for iOS14 & macOS 11 and also added "gather" functions to collect the SQLite DBs from target devices: Blog: https://t.co/83Jh8dKcYC Tool: https://t.co/myaQ8hv83g #DFIR #mac4n6 #Python
http://twitter.com/_RyanBenson/status/1335012080437481474
·mac4n6.com·
#DailyDFIR 339: A new version of APOLLO from @iamevltwin is out! Lots of updates for iOS14 & macOS 11 and also added "gather" functions to collect the SQLite DBs from target devices: Blog: https://t.co/83Jh8dKcYC Tool: https://t.co/myaQ8hv83g #DFIR #mac4n6 #Python
#DailyDFIR 339: A new version of APOLLO from @iamevltwin is out! Lots of updates for iOS14 & macOS 11 and also added "gather" functions to collect the SQLite DBs from target devices: Blog: https://t.co/83Jh8dKcYC Tool: https://t.co/myaQ8hv83g #DFIR #mac4n6 #Python
#DailyDFIR 339: A new version of APOLLO from @iamevltwin is out! Lots of updates for iOS14 & macOS 11 and also added "gather" functions to collect the SQLite DBs from target devices: Blog: https://t.co/83Jh8dKcYC Tool: https://t.co/myaQ8hv83g #DFIR #mac4n6 #Python
http://twitter.com/_RyanBenson/status/1335012080437481474
·github.com·
#DailyDFIR 339: A new version of APOLLO from @iamevltwin is out! Lots of updates for iOS14 & macOS 11 and also added "gather" functions to collect the SQLite DBs from target devices: Blog: https://t.co/83Jh8dKcYC Tool: https://t.co/myaQ8hv83g #DFIR #mac4n6 #Python
#DailyDFIR 340: Expecting more evidence from a phone than you got? This post from @HeatherMahalik describes how you can determine if (& if so when) an #iOS device was wiped: https://t.co/e9XWyefTjo #DFIR #mobile4n6
#DailyDFIR 340: Expecting more evidence from a phone than you got? This post from @HeatherMahalik describes how you can determine if (& if so when) an #iOS device was wiped: https://t.co/e9XWyefTjo #DFIR #mobile4n6
http://twitter.com/_RyanBenson/status/1335284803843846147
·cellebrite.com·
#DailyDFIR 340: Expecting more evidence from a phone than you got? This post from @HeatherMahalik describes how you can determine if (& if so when) an #iOS device was wiped: https://t.co/e9XWyefTjo #DFIR #mobile4n6
#DailyDFIR 341: See search suggestions in the #Chrome omnibox with a picture & bit of context? If you click that suggestion and do the search the search results URL has a gs_ssp parameter. It's base64zipprotobuf & Unfurl (https://t.co/H5XHNrawum) can parse it for you! #DFIR https://t.co/DhpZoAmPOG
#DailyDFIR 341: See search suggestions in the #Chrome omnibox with a picture & bit of context? If you click that suggestion and do the search the search results URL has a gs_ssp parameter. It's base64zipprotobuf & Unfurl (https://t.co/H5XHNrawum) can parse it for you! #DFIR https://t.co/DhpZoAmPOG
http://twitter.com/_RyanBenson/status/1335758818601361411
·twitter.com·
#DailyDFIR 341: See search suggestions in the #Chrome omnibox with a picture & bit of context? If you click that suggestion and do the search the search results URL has a gs_ssp parameter. It's base64zipprotobuf & Unfurl (https://t.co/H5XHNrawum) can parse it for you! #DFIR https://t.co/DhpZoAmPOG
#DailyDFIR 342: @SwiftForensics will be talking about Spotlight indexing on #iOS & #macOS in a free webinar from @NW3CNews! Starts in two hours: 9am Pacific / 12pm Eastern Register: https://t.co/bBnHQM5QTQ There's very interesting data in Spotlight; it's a great for #DFIR
#DailyDFIR 342: @SwiftForensics will be talking about Spotlight indexing on #iOS & #macOS in a free webinar from @NW3CNews! Starts in two hours: 9am Pacific / 12pm Eastern Register: https://t.co/bBnHQM5QTQ There's very interesting data in Spotlight; it's a great for #DFIR
http://twitter.com/_RyanBenson/status/1335962267934892032
·nw3c.org·
#DailyDFIR 342: @SwiftForensics will be talking about Spotlight indexing on #iOS & #macOS in a free webinar from @NW3CNews! Starts in two hours: 9am Pacific / 12pm Eastern Register: https://t.co/bBnHQM5QTQ There's very interesting data in Spotlight; it's a great for #DFIR
#DailyDFIR 343: @B1N2H3X has a post about many ways to share in #DFIR: https://t.co/hCFjRAcUeq It's more than just "write a blog post" (although that is good to do!) There are so many ways to share & contribute and Jessica does a great job leading by example on this front.
#DailyDFIR 343: @B1N2H3X has a post about many ways to share in #DFIR: https://t.co/hCFjRAcUeq It's more than just "write a blog post" (although that is good to do!) There are so many ways to share & contribute and Jessica does a great job leading by example on this front.
http://twitter.com/_RyanBenson/status/1336468735385686016
·magnetforensics.com·
#DailyDFIR 343: @B1N2H3X has a post about many ways to share in #DFIR: https://t.co/hCFjRAcUeq It's more than just "write a blog post" (although that is good to do!) There are so many ways to share & contribute and Jessica does a great job leading by example on this front.