Week 08 – 2024

ForensafeInvestigating Android WhatsApp Lionel NotariiOS Unified Logs – WiFi and AirPlane Mode Stephan BergerAWS Ransomware Teri RadichelInvestigating, Containing, and Removing Malware on a Mac The Sleuth SheetHow to Transition From OSINT Practitioner to Intelligence Analyst Tyler Hudak at TrustedSecMailItemsAccessed Woes: M365 Investigation Challenges Allan Liska at ‘Ransomware Sommelier’LockBit Down! Jinghua Bai at APNICDeep dive into […]

Week 07 – 2024

Cado Security How to be IR Prepared in AWS How to be IR prepared in Azure DCSO CyTecOverview: Evidence Collection of Ivanti Connected Secure Appliances ForensafeInvestigating iOS TikTok PasswareFrom FileVault to T2: How to Deal with Native Apple Encryption Phill Moore, Zach Stanford and Ross Brittain at CyberCXNetScalers are under attack. Or… they were… Bill […]

Week 06 – 2024

Alexis Brignoni at ‘Initialization Vectors’What is cacheV0.db and why are there only images in it? Bullsh*t HuntingBullshit Hunting: Digital Forensics Edition Django Faiola at ‘Appunti di Informatica Forense’iOS WAZE Dr. Tristan Jenkinson at ‘The eDiscovery Channel’COPA v Wright – The Identity Question Takes Centre Stage Oleg Afonin at ElcomsoftBootloader-Level Extraction for Apple Hardware ForensafeInvestigating Android […]

Week 05 – 2024

Andrew MalecIvanti Connect Secure Auth Bypass and Remote Code Authentication CVE-2024-21887 BelkasoftHow to Acquire Digital Evidence with Android Screen Capturer in Belkasoft X Amanda Berlin at BlumiraMasked Application Attack Incident Report CCL SolutionsAn expert deep-dive on data formats Felix Aeppli at Compass SecurityDevice Code Phishing – Add Your Own Sign-In Methods on Entra ID Dr. […]

Week 04 – 2024

Ann BransomHunting for File Deletion Artifacts in Google File Stream Data Monica Harris at CellebriteHow Cellebrite and Relativity’s Mobile Advisory Board is Shaping the Future of Mobile eDiscovery Bret at Cyber GladiusThe Active Directory Access Control List Explained Cyber TriageDFIR Next Steps: What To Do When You Find Mimikatz Was Run ForensafeInvestigating iOS Voice Triggers […]

Week 03 – 2024

Alexis Brignoni at ‘Initialization Vectors’SQLite 3.45 introducing binary JSON BelkasoftThe Investigator’s Guide to Android Acquisition Methods. Part I: Device Nate Bill at Cado SecurityContainerised Clicks: Malicious use of 9hits on vulnerable docker hosts CCL SolutionsSQLite’s New Binary JSON Format Foxton ForensicsInvestigating Microsoft Teams IndexedDB data International Journal of Electronic Security and Digital ForensicsVolume 16 Issue […]

Week 02 – 2024

Cyber 5W Memory Forensics – Practical Example, Detect Classic Remote Process Injection Malware Analysis – How to Bypass Anti-Debugging Tricks – Part 1 Oleg Afonin at ElcomsoftWhen Extraction Meets Analysis: Cellebrite Physical Analyzer Matt Shannon at F-ResponseF-Response and Apple, 2024 Edition ForensafeInvestigating iOS Calls Oxygen ForensicsHuawei Forensics: Data Extraction and Encryption Pending InvestigationsDissect vs SysInternals […]

Week 01 – 2024

Amged WagehDriveFS Sleuth — Revealing The Hidden Intelligence Cado Security The Importance of Depth: Cloud Forensics Beyond Log Analysis  The Cado Platform can now Capture AWS EC2 Systems into E01 Format ElcomsoftA Comprehensive Guide to Essential Tools for Elcomsoft iOS Forensic Toolkit ForensafeInvestigating iOS Venmo Gerardo Santos at Security Art WorkClusterización de Amenazas y Threat Hunting Taz […]

Week 52+1 – 2023

So I can’t count and started the year on Week 1 instead of Week 0. This is the last summary post of the year, and hopefully I find a bit of time to write a year summary later on. Ahmed BelhadjadjiPoisonedCredentials Challenge Walkthrough Oleg Afonin at ElcomsoftA Comprehensive Instruction Manual on Installing the Extraction Agent […]

Week 52 – 2023

(Turns out the first post of the year should have been week 0 instead of week 1….whoops….week 52 is 1 week early this year) Amged WagehDriveFS Sleuth — Investigating Google Drive File Stream’s Disk Artifacts David Spreadborough at AmpedCorrect the Aspect Ratio of CCTV Footage Oleg Afonin at ElcomsoftiOS 17.3 Developer Preview: Stolen Device Protection ForensafeSolving Cellebrite’s […]