Week 42 – 2022

John Lukach at 4n6irAmazon Linux Triage for Anyone and Everyone ArcPointGetting started with ALEAPP | ArcPoint Forensics Cyrill Brunschwiler at Compass SecurityTutorial on how to Approach Typical DFIR Cases with Velociraptor ForensafeInvestigating Ouick Access Harel Segev at ‘RAT In Mi Kitchen’The Forensic Value of the (Other) WSH Registry Key Lina Lau at InversecosHow to Investigate […]

Week 41 – 2022

Andre Maccarone and John Ailes at AonAmazon Web Services: Exploring the Cost of Exfil CERT-SE CTF2022CERT-SE CTF2022 CyberJunnkieIncident Response LetsDefend : Detecting Web App attack and detecting persistence Forensafe Investigating LogMeIN Investigating ExpressVPN Kathryn HedleyWindows 11 Time Rules Magnet ForensicsSRUM: Forensic Analysis of Windows System Resource Utilization Monitor Carl Purser at OpenTextApple property list parsing with […]

Week 40 – 2022

Chris Vance at ‘D20 Forensics’ iOS 16 Breaking Down the Biomes Part 2 – AppInstalls, AppLaunch, & AppIntents iOS 16 – Breaking Down the Biomes (Part 3) – Keeping up with CarPlay iOS 16 – Breaking Down the Biomes (Part 4) – Surfin’ with Safari iOS 16 – Breaking Down the Biomes Part 5 — […]

Week 39 – 2022

Chris Vance at ‘D20 Forensics’ iOS 16 – “Paul unsent a message.” … OR DID HE?! iOS 16 – Now You ‘C’ It, Now You Don’t — Breaking Down The Biomes Part 1 Krzysztof Gajewski at CyberDefNerdC:\ProgramData\Microsoft\Event Viewer\ExternalLogs – artifacts showing what Windows Event Logs were opened on the suspected device. Joseph Moronwi at Digital […]

Week 38 – 2022

Digital Forensics Myanmar Digital Forensics Myths & Reality DFIR Field Mistake How To Use Forensics Reader And Viewer Joseph Moronwi at Digital InvestigatorFile Signature And Hash Analysis Oleg Afonin at ElcomsoftEntering DFU: iPhone 8, 8 Plus, and iPhone X Forensafe Investigating WordPad Recent Files Investigating Windows Startup Programs Forensics [Insider]Basic Concepts in Mobile Device Forensics […]

Week 37 – 2022

Jessica Hyde at HexordiaPeer Review for Mobile Forensics Joseph Moronwi at Digital InvestigatorFile Carving In Windows Forensafe Investigating Microsoft Management Console (MMC) MRU Investigating WordPad Recent Files Lina Lau at InversecosForensic Detection of Files Deleted via SDelete Magnet ForensicsWhat is MRU (Most Recently Used)? Mattia Epifani at Zena ForensicsAndroid Forensics References: a curated list Muhammed […]

Week 36 – 2022

Alican KirazThreat Hunting for Windows Registry Blake ReganPicking the right gear for your DFIR write-blocker kit Derek EiriAssembling a Go-Bag, Re: Write Block Options? Joseph Moronwi at Digital InvestigatorUsing The Wayback Machine For OSINT Forensafe Investigating WinZip Investigating Swap File URL’s ForensiumFirmware extraction from BT headset 2 InfoSec Write-upsS3 Bucket: Cloud Trail Log Analysis Kevin […]

Week 35 – 2022

Cado SecurityAWS EC2 Incident Response CovertshellDFIR triage and Timeline Analysis Danus MinimusThe guide for a freeloader Threat Intelligence Analyst and Malware Researcher Digital Forensic ForestBlue Team Cheat Sheets Digital Forensics Myanmar NTFS Index Attributes B-Trees (NTFS) IOS Crash & Sysdiagnose Log – PDF Oleg Afonin at ElcomsoftLow-Level Extraction of iOS 15.2-15.3.1 Forensafe ArtiFast ShimCache Parser […]

Week 34 – 2022

BelkasoftSQLite Forensics with Belkasoft X Cyber TriageWhat is a Windows Recents Folder Artifact? Joshua I. James at DFIRScienceiLEAPP and RLEAPP updates and dev thoughts Elcomsoft Probing Linux Disk Encryption: LUKS2, Argon 2 and GPU Acceleration Breaking Windows Passwords: LM, NTLM, DCC and Windows Hello PIN Compared Erik Hjelmvik at NetresecWhat is PCAP over IP? ForensafeLast […]

Week 33 – 2022

Jessica Hyde at HexordiaCreating Synthetic Test Data Asger SGeolocating IP addresses in Velociraptor Gary Warner at CyberCrime & Doing TimeThree UK-based Nigerian BEC Scammers Used Construction Intelligence Service to Target Victims Joshua I. James at DFIRScienceModular artifact scripts coming to iLEAPP Muhammed AygünBAM/DAM Analizi N00b_H@ck3rLetsDefend: Memory Dumper Oxygen ForensicsExtract Data from OnlyFans App with Oxygen […]