This Month In 4n6 – July – 2018

A monthly wrap-up of the DFIR news for July 2018. Thank you to those Patreon donors for the last month. I decided to go with the value-for-value model rather than advertising. Alternatively, it would be great if you could leave an iTunes review. If you are a Patreon donor the show notes can be found here. Special thanks to […]

Week 30 – 2018

FORENSIC ANALYSIS Adam Harrison at 1234n6 answers Dave’s latest Sunday Funday challenge on identifying historical timezone configuration changes. Adam’s submission also won Methods to identify historical Time Zone configuration associated with a Windows PC Matt at Bit of Hex shares a short Python script “which will brute-force binary data looking for valid dates and times” […]

Week 29 – 2018

FORENSIC ANALYSIS Hideaki Ihara at the Port 139 blog looked into NTFS $REPARSE_POINTs and symbolic links, and by doing so was able to identify a bug in MFTECmd. NTFS $REPARSE_POINT and Symbolic link NTFS $REPARSE_POINT and Symbolic link(2) Dan Pullega at 4n6k describes how he investigated a previously unknown GUID identified in Shellbags. Dan also […]

Week 28 – 2018

FORENSIC ANALYSIS Adam Harrison at 1234n6 shares his answer to the recent Sunday Funday challenge regarding o365 logging. Adam’s solution also won him the challenge Investigating Office365 Account Compromise without the Activities API Brian Gerdon at Arsenal Recon walks through his process for cracking the password of a Windows XP domain account. An Adventure in […]

Week 27 – 2018

I’ve decided to formalise the support page for the project, which can now be accessed from the top menu. I figured that it would be a good idea to put it all in the one place. I’m still holding out from the advertising model, although I think that’s more of a personal preference more than […]

This Month In 4n6 – June – 2018

A monthly wrap-up of the DFIR news for June 2018. Thank you to those Patreon donors for the last month. I decided to go with the value-for-value model rather than advertising. Alternatively, it would be great if you could leave an iTunes review. If you are a Patreon donor the show notes can be found here. Special thanks to […]