This Week In 4n6: Recent Episodes

None

Your weekly roundup of Digital Forensics and Incident Response news

View Details

ThinkDFIRCached screenshots on Windows 11 Akash PatelLet’s Talk About HTTP — The Backbone of the Web (And a Goldmine for DFIR Folks) BelkasoftAutomating Digital Forensic Workflows with Belkasoft X Christopher Eng at Ogmini SSD Forensics – Flex Capacity Expectations vs Reality – Digital Forensic Science Master’s Degree Part 8 Windows Notepad – Recent Files (New Option) Windows […]

View Details

Akash Patel Where Do We Begin? A Network Forensic Investigator’s Steps The Silent Journey: A Cautionary Tale in Cyber Risk John Hyla at Blue Crew ForensicsiOS Stream Names Christopher Eng at Ogmini Zeltser Challenge – Fifth Month Accomplishments 2025 New York State Cybersecurity Conference RDCMan – Cracking DPAPI w/mimikatz Windows Notepad Parser – Documentation Update […]

View Details

Akash PatelMaster Wireshark tool Like a Pro: — The Ultimate Packet Analysis Guide for Real-World Analysts CCL SolutionsInvestigating PolyBuzz on Android Christopher Eng at Ogmini Remote Desktop Manager – Artifacts Part 6 Random Thoughts – System Naming RDCMan – Verifying DPAPI Activity WinFE Training – Completed RDCMan – Importance of DPAPI Activity SANS – Ransomware Summit 2025 […]

View Details

Akash PatelForensic Analysis of SQLite Databases Alexis Brignoni at ‘Initialization Vectors’Extraction, Processing, & Querying Apple Unified Logs from an iOS Device Alexander Fehrmann at AmpedProcessing Impression Evidence in Amped FIVE Brian MaloneyOneDrive Evolution and Schema Updates Christopher Eng at Ogmini DPAPI – Audit DPAPI Activity Remote Desktop Manager – Artifacts Remote Desktop Manager – Artifacts […]

View Details

Akash Patel Proxies in DFIR– Deep Dive into Squid Log & Cache Forensics with Calamaris and Extraction… BPF Ninja: Making Sense of Tcpdump, Wireshark, and the PCAP World Brian MaloneyOneDriveExplorer now supports Microsoft.FileUsageSync.db Christopher Eng at Ogmini Reading up on Volatility Pearson – Cyberattack Volatility3 – Windows 11 24H2 Memory Dump issues? WinFE Training – […]

View Details

Akash Patel Linux File System Analysis and Linux File Recovery: EXT2/3/4 Techniques Using Debugfs, Ext4magic &… Understanding Linux: Kernel Logs, Syslogs, Authentication Logs, and User Management Alexander Fehrmann at AmpedForensic Shoeprint Documentation and Analysis with Amped FIVE Atola TechnologyTips for Finding Evidence on Linux File Systems & Storage Devices Christopher Eng at Ogmini Revisiting ShimCache/AmCache […]

View Details

Adam at HexacornMinority (forensic) report aka defending forward w/o hacking back Akash Patel Creating a Timeline for Linux Triage with fls, mactime, and Plaso (Log2Timeline) Understanding Linux Service Management Systems and Persistence Mechanisms in System Compromise Timestomping in Linux: Techniques, Detection, and Forensic Insights BelkasoftSkype Forensics Postmortem: Why DFIR Specialists Should Still Care Christopher Eng […]

View Details

Akash Patel Understanding Rootkits: The Ultimate Cybersecurity Nightmare and Direct Kernel Object Manipulation Understanding Userland Hooks and Rootkits in Real-World Investigations Extracting Memory Objects with MemProcFS/Volatility3/Bstrings: A Practical Guide Disk Imaging (Part 1) : Memory Acquisition & Encryption Checking Digital Forensics (Part 2): The Importance of Rapid Triage Collection — Kape vs FTK Imager Amped Forensic Fingerprint Analysis: […]

View Details

Akash Patel P13 Analyzing Safari Browser, Apple Mail Data and Recents Database Artifacts on macOS Intrusion Analysis and Incident Response on macOS: File Quarantine, Antivirus Mechanisms, and… P14 Using APOLLO for macOS investigation Christopher Eng at Ogmini Expectations vs Reality – Digital Forensic Science Master’s Degree Part 7 David Cowen Sunday Funday Challenge – Browser […]

View Details

Akash Patel Making Sense of macOS Logs(Part1): A User-Friendly Guide A Curious Case with SentinelOne: Same Rule, Different Behavior? P11 macOS Tracking Users Activity, Autoruns and Application-Level Firewall and Forensic Insights Bayaz NetDetection — Evidence Of Execution In Linux? Manny Kressel at BitmindzApple T2 Chip and Silicon Mac Acquisition using NBFTools NETRE Ben Bowman at Black Hills […]

View Details

Akash Patel Box Cloud Storage Forensic Investigations: Logs, Cached Files, and Metadata Analysis Cloud Storage Affect on file Timestamps and collection with KAPE: A Forensic Guide Volume Shadow Copy extraction with KAPE(including data/file recovery) Metadata Investigation(Exiftool): A Powerful Tool in Digital Forensics Remote Collections Artifacts Using KAPE including UNC and Over the Internet(ZeroTier) BelkasoftWindows Forensics: […]

View Details

Akash Patel Investigating Google Drive for Desktop: A Forensic Guide Automating Google Drive Forensics: Tools & Techniques Dropbox Forensic Investigations: Logs, Activity Tracking, and External Sharing BelkasoftLessons Learned from the Silk Road Investigation Brian MaloneyOneDrive Offline Mode (Recallish vibes) Christopher Eng at Ogmini CISSP – Study Plan Diving Deep – LevelDB Part 3 CISA IR […]

View Details

Added something new to the site this week; a couple of training vendors have reached out to offer readers a discount on their next training class purchase. Using these discount codes will also support the site 🙂 Adam at HexacornBeing a tool while using a tool   Akash Patel Forensic Challenges in Cloud Storage Investigations […]

View Details

ThinkDFIRSRUMday Funday! Akash PatelHandling Incident Response: A Guide with Velociraptor and KAPE BelkasoftEmail Forensics with Belkasoft X Christopher Eng at Ogmini Homelab Part 1 – The Current Setup David Cowen Sunday Funday Challenge – SRUM Validation Expectations vs Reality – Digital Forensic Science Master’s Degree Part 2 Investigating Lab Automation – MSLab CISA IR Training […]

View Details

Atola TechnologyMastering Drive Wiping: Ensuring Data Security Akash Patel Lateral Movement Analysis: Using Chainsaw, Hayabusa, and LogParser for Cybersecurity Investigations Tracing Reused $MFT Entries Paths : Recovering Deleted File Paths Forensically with CyberCX… BelkasoftWindows Browser Forensics 101 Brian MaloneyAutopsy Hardening Guide: Part 1 Dr. Brian Carrier at Cyber TriageInformation Artifacts: Simplify DFIR Analysis David Cowen at […]

View Details

Akash Patel SentinelOne(P7- Activity/Reports): A Practical Guide/An Practical Training SentinelOne (P8- SentinelOne Automation) : Guide / Training to Forensic Collection, KAPE… SentinelOne(P9- Settings): A Practical Guide/An Practical Training Cyber 5WGuide to Mobile Forensics with ALEAPP David Cowen at the ‘Hacking Exposed Computer Forensics’ blog Daily Blog #705: AI Prompts that help me Daily Blog #706: Using […]

View Details

Akash Patel Update on My Azure Incident Response Series SentinelOne(P5- Incidents): A Practical Guide SentinelOne(P6- ISPM/Application Management): An Practical Training Digital Forensics Myanmar Mobile Forensics (Note-1) Mobile Forensics (Note-2) Dr. Tristan Jenkinson at ‘The eDiscovery Channel’Bellingcat Challenge – Week 3 Writeup ForensafeInvestigating iOS Uber Iram Jack Processes and Network Communication Windows vs. Linux Endpoint Investigations […]

View Details

Arshiya JamadarMobile Forensics – Analyzing Data Stored by Meetup Application on iOS Devices Dr. Neal Krawetz at ‘The Hacker Factor Blog’Labeling AI Dr. Tristan Jenkinson at ‘The eDiscovery Channel’Bellingcat Challenge – Week 2 Writeup Eric CapuanoThe Role of Fuzzy Hashes in Security Operations ForensafeInvestigating Samsung Wipe History Odysseus at HackTheBoxMemory dump analysis with Signal decryption […]

View Details

John Lukach at 4n6irAdditional CloudFront Log Formats and Destinations Paul Lorentz at CellebriteDon’t Lose Your Evidence: What’s at Stake with the iOS 18 Changes Cyber Sundae DFIRCapabilityAccessManager.db Deep Dive, Part 2 Krzysztof Gajewski at CyberDefNerdWho Knows What Happened to My Logs? Tracking Event Log Deletion Django Faiola at ‘Appunti di Informatica Forense’iOS Foursquare Swarm – […]

View Details

Adam Harrison at 1234n6 Relationship between Microsoft Server and Desktop OS Versions Available Artifacts – Indicators of Execution Updated BelkasoftMobile Forensics Cheatsheet: iOS and Android System Artifacts John Hyla at Blue Crew ForensicsDEBA / MDPlist Files Decrypting a DefenseStrava and Data Brokers, Tech Eulogies, Social Media and the Fourth Amendment, the Future of Legal AI-d […]

View Details

David Spreadborough at AmpedProtecting Evidence: Lossless Data Extraction in Forensic Video Conversion Atola TechnologyUnveiling Tomorrow: New Technologies in Hard Drives Chris at AskCleesChrome Visited Links Krzysztof Gajewski at CyberDefNerdRunMRU is not the only one forensic artifact left by the “Run” Prompt Dr. Neal Krawetz at ‘The Hacker Factor Blog’SEAL of Approval ForensafeSolving Cellebrite CTF 2024 […]

View Details

David Spreadborough at AmpedBehind the Screen: Codecs and Formats Unveiled David Haddad at Breakpoint ForensicsSamsung Secure Health Data Parser — A Forensic Tool for Parsing & Analyzing Samsung Secure Health Databases Cyber Sundae DFIRCapabilityAccessManager.db Deep Dive, Part 1 Denis Szadkowski, Paul van Ramesdonk, Maike Orlikowski and Johann Aydinbas at DCSO CyTecUnransomware: From Zero to Full […]

View Details

Krzysztof Gajewski at CyberDefNerdWindows Artifacts: Analyzing the USN Journal on a Live System Clint Marsden at DFIR InsightsQuick Fixes for plaso / Log2timeline Error: Key Troubleshooting on Ubuntu Dr. Neal Krawetz at ‘The Hacker Factor Blog’ Account Payable Phishing Attacks C2PA and the All Adobe Show ForensafeSolvig Cellebrite CTF 2024 (Felixs’ iOS) Magnet ForensicsThat one […]

View Details

Oleg Afonin at ElcomsoftWhen Speed Matters: Imaging Fast NVMe Drives ForensafeInvestigating Android Gboard Magnet Forensics The importance of PowerShell logs in digital forensics  ShimCache vs AmCache: Key Windows Forensic Artifacts Faan Rossouw at Active CountermeasuresMalware of the Day – Specula Adam GossCollection Management Framework Template (+FREE Download) Assaf Morag at AquaThreat Alert: TeamTNT’s Docker Gatling […]

View Details

CyberJunnkieHackathon 24 Prequalifiers: Forensics Challenge “hacked” First blood Team deathstrik3 Dr. Neal Krawetz at ‘The Hacker Factor Blog’C2PA and Authenticated Disinformation Vladimir Katalov at ElcomsoftOutlook Forensic Toolbox Helps Access Deleted Messages ForensafeInvestigating Android Life360 Magnet Forensics Unraveling the clues: RDP artifacts in incident response  5 iOS forensics evidence sources to capture before they expire Matt […]

View Details

BelkasoftCase Study: From Hidden Databases to Key Evidence with Belkasoft X’s SQLite Viewer Cyber Sundae DFIRCapability Access Manager Forensics in Windows 11 Krzysztof Gajewski at CyberDefNerdLinux Artifacts: Timestamps of Last SUDO Command Execution Decrypting a DefenseSecure Messaging, Accessing Locked Phones, Retention of Seized Devices, Software Source Code, & More Dr. Neal Krawetz at ‘The Hacker […]

View Details

Cyber 5WWindows Shell Items Analysis Derek EiriExploring UFADE to Extract Data From iOS Devices ForensafeInvestigating Android Samsung Browser J SmithSolving the 13Cubed Linux Memory Forensics Challenge Justin De Luna at ‘The DFIR Spot’Lateral Movement – Remote Desktop Protocol (RDP) Event Logs Husam Shbib at Memory ForensicInside Cridex – Memory Analysis Case Study Raj UpadhyayFeatureUsage — Evidence of […]

View Details

Adan AlvarezGaining AWS Persistence by Updating a SAML Identity Provider Alexandre DulaunoyImprove Your Forensic Analyses with hashlookup Alex Caithness at CCL SolutionsWhen is an app not an app? Investigating WebAPKs on Android Andreas Arnold at Compass SecurityEmail, Email on the Wall, Who Sent You, After All? Django Faiola at ‘Appunti di Informatica Forense’iOS Burner – […]

View Details

Chris Ray at Cyber TriageDFIR Breakdown: Impacket Remote Execution Activity – Smbexec ForensafeInvestigating Android Nike Run Club Johan BerggrenOpenRelik Lina Lau at XintraUnderstanding Tokens in Entra ID: A Comprehensive Guide Magnet Forensics A look into iOS 18’s changes 7 essential artifacts for macOS forensics Marco Fontani at Amped10 Ways to Detect Deepfakes Created by Text-to-image […]

View Details

Atola TechnologySynology RAID Reassembly and Image Acquisition David Spreadborough at AmpedGetting Started with Video Formats and Conversion Cyber 5WNetwork Forensics With Wireshark Mike Wilkinson at Cyber TriageDFIR Next Steps: What To Do After You Find A Suspicious Use Of Remote Monitoring & Management Tools Danny ZendejasLets Defend Write-up David Cowen at the ‘Hacking Exposed Computer […]

View Details

0xdf hacks stuffHTB Sherlock: Noxious Andrea Fortuna Forensic acquisition of ChromeOS devices The hidden risks of Cherry-Picking in Incident Response and Digital Forensics Belkasoft How to Investigate Telegram Crime without Arresting the Company’s CEO iOS Telegram Forensics. Part I: Acquisition and Database Analysis Brian MaloneyCracking OneDrive’s Personal Vault Justin Seitz at Bullsh*t HuntingThe Evidence Carnival: […]

View Details

CCL GroupLocal Storage and Session Storage in Mozilla Firefox (Part 1) DFIR ReviewLocation, Location, Location Dr. Tristan Jenkinson at ‘The eDiscovery Channel’eDiscovery Risks – Sending Documents for Disclosure via Email ForensafeInvestigating Android Tinder Emilia Chau, Marin Gheorge, and Muhammad Jawad at Jumpsec LabsBuilding Forensic Expertise: A Two-Part Guide to Investigating a Malicious USB Device (Part […]

View Details

0xdf hacks stuffHTB Sherlock: Reaper CellebritePerforming Collection from Mobile Devices in an MDM Environment Cyber TriageDFIR Next Steps: What To Do After You Find a Suspicious Use Of curl.exe Digital Forensics Myanmar eCDFP (Module-6) (Window Forensics) (Part – 7) eCDFP (Module-6) (Window Forensics) (Part – 8) eCDFP (Module-6) (Window Forensics) (Part – 9) ForensafeInvestigating Android […]

View Details

Andrea FortunaDigital Detectives vs. Android 14: overcoming new forensic challenges Digital Forensics MyanmareCDFP (Module-6) (Window Forensics) (Part – 6) ForensafeInvestigating Android Here WeGo Kevin StokesPlaso Super Timelines and CloudTrails Oxygen ForensicsmacOS Extraction of System Artifacts with Oxygen Forensic® KeyScout Kokab Rasool at Paraben CorporationMemory Forensics Tools Overview Rajendra Prasanth SFile System tunnelling John Brown at […]

View Details

Adam MesserCloud Digital Forensics and Incident Response — AWS IAM Privilege Escalation Leads to EC2… Craig Ball at ‘Ball in your Court’AI Prompt to Improve Keyword Search Mike Wilkinson at Cyber TriageDFIR Next Steps: What To Do After You Find a Suspicious Use Of certutil.exe Decrypting a DefenseOlympics Surveillance, Subway Weapons Detection System, Geofence Search Decision, Privacy […]

View Details

Digital Forensics MyanmareCDFP (Module-6) (Window Forensics) (Part – 5 ) Dr. Neal Krawetz at ‘The Hacker Factor Blog’Reversing Samsung Metadata ForensafeInvestigating Android Firefox Justin De Luna at ‘The DFIR Spot’RDP Bitmap Cache – Piece(s) of the Puzzle Kevin StokesPlaso Super Timelines in Splunk Magnet ForensicsSee the story of your geolocation data with Magnet Review’s Worldmap […]

View Details

Chris Ray at Cyber TriageDFIR Breakdown: Using Certutil To Download Attack Tools 0xdf hacks stuff HTB Sherlock: Tracer HTB Sherlock: Campfire-2 Baris Dincer Forensic Investigation Operations — Complex Linux Forensics Analysis Forensic Investigation Operations — Windows Base III BelkasoftAndroid System Artifacts: Forensic Analysis of Application Usage Digital Forensics Myanmar Digital Forensics with Myanmar Language PDF (View Or Download) eCDFP […]

View Details

Adam MesserCloud Digital Forensics and Incident Response — EC2 Compromise Leads to S3 Bucket Exfiltration Baris Dincer Forensic Investigation Operations — Windows Base I Forensic Investigation Operations — Windows Base II BelkasoftChallenges in Digital Forensics: The Case of the Trump Rally Shooter’s Phone Digital Forensics Myanmar eCDFP (Module-6) (Window Forensics) (Part – 2 ) eCDFP (Module-6) (Window Forensics) (Part – 3 […]

View Details

Atola TechnologiesNeed for Speed: How to Get a Forensic Image Quicker? Clint Marsden at DFIR Insights Exploring Host-Based Digital Forensics with Memory Analysis The role of Incident Response in Cyber Security Introduction to Digital Forensics: Preparing for the Unexpected with Volatility, Wireshark, Hayabusa and FTK Imager Cyber 5WGoogle Drive Forensics Digital Forensics Myanmar Thumbnail Or […]

View Details

Cyber 5WWindows Registry Analysis Decrypting a DefenseNYC ShotSpotter Report, Deepfakes, Video ID Decision, Digital Evidence Standards, & More Django Faiola at ‘Appunti di Informatica Forense’iOS Booking.com – Hotels & Travel ForensafeInvestigating Android Google Drive Ian Whiffin at DoubleBlakBrowserState.db last_viewed_time? (Again) Memory ForensicMemory Mystery Challenge Francis Guibernau at AttackIQEmulating the Sabotage-Focused Russian Adversary Sandworm– Part 2 […]

View Details

0xdf hacks stuffHTB Sherlock: Campfire-1 Any.Run Phishing Incident Report: Facts and Timeline  Analysis of the Phishing Campaign: Behind the Incident AT&T Cybersecurity Business Email Compromise (BEC): Tracking a Threat Actor’s Funny Business Memory Dump Analysis: Using LiME for Acquisition and Volatility for Initial Setup Dr. Giannis Tziakouris and Nadhem Al-Fardan at CiscoDigital Forensics for Investigating […]

View Details

Cesar Quezada at HexordiaFSEvents: How They Work and Why They Matter for Mac Analysis ForensafeInvestigating Android Device Health Services Neetrox at InfoSec Write-upsAnalyzing a Phishing Email Header InginformaticoTriage / Incident Response tools for Linux Justin De Luna at ‘The DFIR Spot’Windows Defender MP Logs – A Story of Artifacts N00b_H@ck3rLetsDefend: Discord Forensics Oliver Hartshorn and […]

View Details

0xdf hacks stuffHTB Sherlock: Noted Atola TechnologyFile Carving and Sector-Level Analysis Campaign and public sector information securitySysmon-Help an investigator out! Craig Ball at ‘Ball in your Court’Garden Variety: Byte Fed. v. Lux Vending Cyber 5WWindows Event Logs Analysis Dhiren Bhardwaj at Digital Forensic Forest Investigating a Data Exfiltration Scenario Transforming Python scripts into .exe – […]

View Details

Zach Stanford, Yogesh Khatri, and Phill Moore at CyberCXForensic Applications of Microsoft Recall 0xdf hacks stuffHTB Sherlock: Constellation Adan AlvarezAutomating Incident Response in AWS: Blocking a Compromised Identity Center User Alex TeixeiraData Science & Exploratory Data Analysis: the Panda versus the Pony! Brett ShaversThe Multiverse of a DFIR Case Bret at Cyber GladiusIncident Response Plan: […]

View Details

0xdf hacks stuffHTB Sherlock: Nubilum-1 Amged WagehDriveFS Sleuth — Recovery Made Possible! Chris Ray at Cyber TriageDFIR Breakdown: Kerberoasting Dark Data DiscoveryThe 10 Common Data Carving Approaches ForensafeInvestigating Android Waze Forensic Science International: Digital InvestigationVolume 49 HaircutfishTryHackMe Room — Logstash: Data Processing Unit Kevin Beaumont at DoublePulsarRecall: Stealing everything you’ve ever typed or viewed on your own Windows PC […]

View Details

0xdf hacks stuffHTB Sherlock: Bumblebee Alexis Brignoni at ‘Initialization Vectors’Full File System extractions in Zip – MAC times Marco Fontani at AmpedDetecting AI-generated Images Obtained with Text-to-image Models in Amped Authenticate BelkasoftAndroid System Artifacts: Forensic Analysis of Device Information and Usage Cyber 5W “Email Forensics” Cyber TriageCollecting Linux DFIR Artifacts with UAC Dr. Neal Krawetz at […]

View Details

0xdf hacks stuffHTB Sherlock: Logjammer CTF导航Forensike, or Forensics for bad guys ForensafeInvestigating iOS Threema Scott Koenig at ‘The Forensic Scooter’iLEAPP Parsers & Photos.sqlite Queries Lee Kirkpatrick, Paul Jacobs, Sai Lakshmi Ghanasyam, Antoni Fertner, and Andy French at SophosExtracting data from encrypted virtual disks: six methods VolexityDetecting Compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect Devices […]

View Details

Atola TechnologyUncovering AFF4: File Format Essentials And Imaging Bret at Cyber GladiusIncident Response Plan: Windows Data Collection Brian Carrier at Cyber TriageAdaptive vs Static File Collections for DFIR Deagler’s 4n6 Blog Hexordia Weekly CTF Challenge 2024 – Week 3 Writeup Hexordia Weekly CTF Challenge 2024 – Week 4 Writeup Decrypting a DefenseConnected Cars, FCC Fines, […]

View Details

Alexander TasseSherlock — “Unit42” Justin Seitz at Bullsh*t HuntingFront Porch Digital Forensics Digital DanielaInvestigating an Apache Log in the Linux Command Line Dr. Tristan Jenkinson at ‘The eDiscovery Channel’Hexordia CTF – Week 3 Elcomsoft The Implications of Resetting the Screen Lock Passcode in iOS Forensics Elcomsoft Forensic Acquisition System (EFAS) Eric CapuanoPrefetch Analysis Lab ForensafeInvestigating Apple Known […]

View Details

Deagler’s 4n6 BlogHexordia Weekly CTF Challenge 2024 – Week 2 Writeup DS4N6 [BLOG] Cybersecurity & ChatGPT – Multi-part Blog Post Series, by Mario Pérez [BLOG] Cybersecurity & ChatGPT – Part 1 – A Gentle Introduction, by Mario Pérez [BLOG] Cybersecurity & ChatGPT – Part 2 – Generative AI for Blue Teams, by Mario Pérez [BLOG] […]

View Details

Bruno Fischer [EN] android app analysis kleinanzeigen.de (com.ebay.kleinanzeigen) [DE] Android App Analyse kleinanzeigen.de (com.ebay.kleinanzeigen) Amr Ashraf at Cyber 5WHard disk structure and analysis Deagler’s 4n6 BlogHexordia Weekly CTF Challenge 2024 – Week 1 Writeup Dr. Tristan Jenkinson at ‘The eDiscovery Channel’ Hexordia CTF – Week 1 Hexordia CTF – Week 2 Oleg Afonin at ElcomsoftAll […]

View Details

AtolaRAID With Parity: Reassembly and Image Acquisition Alexis Brignoni at ‘Initialization Vectors’ New VLEAPP parser New parser for Uber app geo-locatios in iOS using iLEAPP BelkasoftBelkasoft CTF 6: Write-up Compass SecurityBehind The Scenes Of Ransomware Attacks Craig Ball at ‘Ball in your Court’Cloud Attachments: Versions and Purview ForensafeInvestigating Android Digital Wellbeing Joshua Hickman at ‘The […]

View Details

John Lukach at 4n6irDo NOT forget the AWS Amplify Logs Derek EiriLionel Notari’s iOS Unified Log Acquisition Tool Steve Bunting at DFIR ReviewHow Did That Photo Get On That iPhone ForensafeInvestigating iOS Calendar Hal Pomeranz at ‘Righteous IT’Orphan Processes in Linux Izzy Spering at HuntressAnalyzing a Malicious Advanced IP Scanner Google Ad Redirection | Huntress […]

View Details

Cyber 5WWindows Memory Forensics ForensafeInvestigating Apple Data Usage R Tec CybersecurityAbschlussbericht Security Incident Salvation DATAA Step-to-Step Guide for Data Extraction from Wechat Scott Koenig at ‘The Forensic Scooter’PhotoData – Photos.sqlite and Syndication Photo Library – Photos.sqlite Query Updates Nathanael Ndong at Last Blog ArticleVMware ESXi Forensic with Velociraptor Aaron Goldstein at Todyl Understanding Living-off-the-Land binaries and scripts (LOLBAS) […]

View Details

DFIR101 Magnet Forensics Virtual CTF 2024 – Cipher Challenges Magnet Forensics Virtual CTF 2024 – Android Challenges Forensafe Magnet Virtual Summit 2024 CTF (Cipher) Solving Magnet Virtual Summit 2024 CTF (iOS) Solving Magnet Virtual Summit 2024 CTF (Android) John Reeman at Cyooda SecurityHow To: Email Phishing, malicious payload analysis walkthrough Kairos (Hestia) Tay THM: Memory […]

View Details

BelkasoftAndroid WhatsApp Forensics. Part II: Analysis Cyber 5WNTFS Artifacts Analysis Dr. Brian Carrier at Cyber TriageDFIR Next Steps: What to do after you find a suspicious Windows Network Logon Session Doug Metz at Baker Street ForensicsMAGNET Virtual Summit 2024 Capture the Flag David Stenhouse at DS ForensicsMicrosoft Office Alerts (“OAlerts”) Elcomsoftcheckm8: Advancements in iOS 16 […]

View Details

Cado SecuritySpinning YARN – A New Linux Malware Campaign Targets Docker, Apache Hadoop, Redis and Confluence Django Faiola at ‘Appunti di Informatica Forense’ iOS Burner – Cache.db iOS Burner Forensic Science International: Digital InvestigationVolume 48 Invictus Incident ResponseThe mystery of the EnrichedOffice365AuditLogs solved Nik Alleyne at ‘Security Nik’TOTAL RECALL 2024 – Memory Forensics Self-Paced Learning/Challenge/CTF […]

View Details

Jessica Hyde at HexordiaMobile Forensic Images and Acquisition Priorities BelkasoftAndroid WhatsApp Forensics. Part I: Acquisition Cyber 5WChromium based browsers Investigation Cyber TriageWindows Scheduled Tasks for DFIR Investigations Hendrik Eckardt at cyber.wtfRecovering data from broken appliance VMDKs Dark Data DiscoveryData Carving vs File Carving vs Disk Carving Doug Metz at Magnet ForensicsComae Memory and Network Analysis: […]

View Details

ForensafeInvestigating Android WhatsApp Lionel NotariiOS Unified Logs – WiFi and AirPlane Mode Stephan BergerAWS Ransomware Teri RadichelInvestigating, Containing, and Removing Malware on a Mac The Sleuth SheetHow to Transition From OSINT Practitioner to Intelligence Analyst Tyler Hudak at TrustedSecMailItemsAccessed Woes: M365 Investigation Challenges Allan Liska at ‘Ransomware Sommelier’LockBit Down! Jinghua Bai at APNICDeep dive into […]

View Details

Cado Security How to be IR Prepared in AWS How to be IR prepared in Azure DCSO CyTecOverview: Evidence Collection of Ivanti Connected Secure Appliances ForensafeInvestigating iOS TikTok PasswareFrom FileVault to T2: How to Deal with Native Apple Encryption Phill Moore, Zach Stanford and Ross Brittain at CyberCXNetScalers are under attack. Or… they were… Bill […]

View Details

Emi Polito at AmpedIntegrate Multiple Frames to Improve Visibility Andrew Skatoff at ‘DFIR TNT’RMM – Level.io: Forensic Artifacts and Evidence BelkasoftiOS WhatsApp Forensics with Belkasoft X Patterson Cake at Black Hills Information SecurityWrangling the M365 UAL with SOF-ELK and CSV Data (Part 3 of 3) Brian MaloneyWhat’s New in OneDriveExplorer DCSO CyTecMicrosoft Edge Forensics: Screenshot […]

View Details

Emi Polito at AmpedDeblur a Moving Car Joseph Moronwi at Digital InvestigatorLinux Web Server Forensics: Dr. Ali Hadi’s Web Server Case ForensafeInvestigating iOS Telegram Nik Alleyne at ‘Security Nik’ Packet Crafting – Tearing down a connection with TCP Reset Solving the CTF challenge – Network Forensics (packet and log analysis), USB Disk Forensics, Database Forensics, […]

View Details

Abhiram KumarDeep Dive Into Windows Diagnostic Data & Telemetry (EventTranscript.db) – PART 2 Ahmed Kamal ElmagrabyWindows Registry Analysis Cheat Sheet David Spreadborough at AmpedCCTV Acquisition Series Summary Andrew Skatoff at Andrew Skatoff at ‘DFIR TNT’RMM – Action1: Client Side Evidence Cado Security Why is CIRA all the Hype for Cloud Incident Response? Analyzing AWS Nitro […]

View Details

Abhiram KumarDeep Dive Into Windows Diagnostic Data & Telemetry (EventTranscript.db) – PART 1 David Spreadborough at AmpedViewing CCTV after Acquisition Bhargav Rathod at DFRWSDFRWS 2023 Challenge ForensafeInvestigating Android Skype Harlan Carvey at HuntressGone Phishing: An Analysis of a Targeted User Attack Joshua Hickman at ‘The Binary Hick’Android & AirTags (Part II) Justin De Luna at […]

View Details

ADF SolutionsHow to Scan a Mobile Device with Mobile Device Investigator BelkasoftHow to Analyze KnowledgeC.db with Belkasoft X CloudbrothersOther Entra ID / Azure AD SignIn errors ForensafeInvestigating Android Aqua Mail Justin De Luna at ‘The DFIR Spot’A LNK To The Past: Utilizing LNK Files For Your Investigations Lorena Carthy-WilmotVipps App — Forensics Lucid Truth TechnologiesForensic analysts can […]

View Details

David Spreadborough at AmpedThe Creation of Master and Working Copies after CCTV Acquisition Andrew Skatoff at ‘DFIR TNT’RMM – Xeox: Client Side Evidence AT&T CybersecurityRAM dump: Understanding its ­­­importance and the process CellebriteUnveiling the Modern Approach to Digital Investigations through Remote Collection of Androids and Workplace Apps Derek EiriDisk Toggling, Validating WinFE Geraldine Blay and […]

View Details

Amr Ashraf EventLog Analysis EDR Log Investigation Troy Wojewoda at Black Hills Information SecurityWelcome to Shark Week: A Guide for Getting Started with Wireshark and TShark Cado SecurityDecoding the NIST Cloud Computing Forensics Reference Architecture Oleg Afonin at ElcomsoftApple iCloud Acquisition: A Lifeline for Forensic Experts ForensafeInvestigating Android Twitter Salvation DATAWhat is DVR and How […]

View Details

Amped Acquisition from a Cloud-based Service Provider How to Use the Macroblocks Filter in Amped FIVE BelkasoftIns and Outs of Hashing and Hashset Analysis in Belkasoft X Manuel Winkel at DeydaChecklist for NetScaler (Citrix ADC) CVE-2023-3519 Elcomsoft iOS Forensic Toolkit Tips & Tricks iOS Device Acquisition: Installing the Extraction Agent Howard Oakley at ‘The Eclectic […]

View Details

Andrew Skatoff at ‘DFIR TNT’RMM – ScreenConnect: Client-Side Evidence Cado Security Macbooks and the Cloud Chain of Custody in the Cloud Cyber TriageLogon Session vs Local Session vs Cyber Triage Sessions. Oh My! Decrypting a DefenseMobile Surveillance, Body-worn Camera Audit Logs, Facial Rec. Source Code, & Threads Data Oleg Afonin at Elcomsoft Pushing the Boundaries: […]

View Details

David Spreadborough at AmpedRemote Acquisition Using a Mobile Device Felix Guyard at ForensicXlab🔦 Video Games Forensics : Steam ForensafeInvestigating Android Yandex Mail Jim Cole at CameraForensicsThe importance of closing the knowledge gap between software and law enforcement Ken Pryor at ‘No Pryor Knowledge’Forensics/Malware Courses and Tools Lorena Carthy-WilmotUses24HourClock: false Adam GossPython Threat Hunting Tools: Part […]

View Details

Marco Fontani at AmpedIntroducing Amped Engine: Our New Product to Integrate Video Conversion Everywhere Oleg Afonin at ElcomsoftLow-level Extraction for iOS 16 with iPhone 14/14 Pro Support Magnet ForensicsHow to Investigate Infostealer Malware  Salvation DATAWestern Digital USB Hard Disk Data Recovery Tips — Step by Step Megan Roddie at SANSGoogle Workspace Log Extraction Bill Stearns […]

View Details

David Spreadborough at AmpedOpen-Box Acquisition Using the Internal Hard Disk Drive Kushalveer Singh Bachchas at AT&T CybersecurityDigital dumpster diving: Exploring the intricacies of recycle bin forensics blueteam0psdet-eng-samples ElcomsoftOpen-Sourcing Raspberry Pi Software for Firewall Functionality: Secure Sideloading of Extraction Agent ForensafeInvestigating Default Web Browser on Windows Kevin Pagano at Stark 4N6NahamCon CTF 2023 – Forensics Paritosh […]

View Details

BelkasoftKnowledgeC Database Forensics with Belkasoft X Blake ReganMount Up CloudyforensicsGoogle Cloud Forensics and Incident Response Dr. Neal Krawetz at ‘The Hacker Factor Blog’Indictment Documents Haider at HK_Dig4nsicsForensic Analysis of Windows Subsystem for Android (WSA) Maxime Chouquet at LexfoCVE-2023-27997 – Forensics short notice for XORtigate Md. Abdullah Al MamunEmail Incident Response NCC GroupNew Sources of Microsoft […]

View Details

David Spreadborough at AmpedCCTV Device Removal and Replacement BelkasoftAutomation with Belkasoft: Orchestrating Belkasoft X and Griffeye DI Pro Forensic Science International: Digital InvestigationVolume 45, June 2023 Mark Spencer at Arsenal ReconForensic Analysis of the NetWire Stack Jacob Torrey at Thinkst ThoughtsMeet “ZipPy”, a fast AI LLM text detector MoveIT Attack Graph Response to CISA Advisory […]

View Details

Ariel Szarf and Or Aspir at MitigaMitiga Security Advisory: Lack of Forensic Visibility with the Basic License in Google Drive ForensafeInvestigating qBittorrent MailxaminerOLK File Forensics – Examine OLK14 File and Export Evidence Plainbit(IR-CASE) 신용카드 결제 피싱 페이지 스크립트 삽입 사고 Arslan Sabir at System WeaknessWindows RDP Event Logs: Identification, Tracking and Investigation Part-1 Adam GossPython […]

View Details

David Spreadborough at AmpedClosed-Box CCTV Acquisition Using Network Access Cado Security Is Cloud Forensics just Log Analysis? Kind Of. Updates to Legion: A Cloud Credential Harvester and SMTP Hijacker Cyber TriageInbound Logon Artifact Deep Dive Series Data Forensics DD File Forensics and Analysis Using an Automated Software E01 Forensic Analysis Using a Tried & Tested […]

View Details

Lee Whitfield has announced the finalists for this years Forensic 4cast awards. Thanks for everyone that nominated this site for Resource of the Year.Forensic 4:cast Awards 2023 – Voting is now open! ThinkDFIRCPY JMP Brian Maloney at Malware MaloneyOneDrive Evolution ForensafeInvestigating Remote Desktop Connection Event Logs ForensicXlab📦 Volatility3 Windows Plugin : KeePass Invictus Incident ResponseImporting […]

View Details

Hexordia What’s brewing with IPAs – Working with IPA files for Forensic Examiners Cloud Storage & Digital Forensic Evidence David Spreadborough at AmpedClosed-Box CCTV Acquisition Using Storage Media Emre Caglar Hosgor at BelkasoftIncident Response with Belkasoft by Emre Caglar Hosgor, SOC Analyst—Specially for Belkasoft Blake Regancheckm8 to SSH Chuan-lun (Johnson) ChouFinding messages in Anonymous Chat […]

View Details

Chris Doman at Cado SecurityDFIR with KAPE and Cado Community Edition Darren LimForensic Analysis of Jami for Android, a Peer-to-Peer Messaging Application Decrypting a DefenseAI & Photography, NYC Council Hearing, Geofence Warrants, Search Warrant Returns, & More Michael Hamm at Digital CorporaCIRCL Forensics Exercises Haider at HK_Dig4nsicsiOS Shortcuts InfoSec Write-upsBlackEnergy Memory Forensic Ananlysis Invictus Incident […]

View Details

David Spreadborough at AmpedNavigating a CCTV Device and Reviewing Video BlackMambaBlackEnergy Memory Forensic Ananlysis ForensafeInvestigating Adobe Acrobat Reader HaircutfishTryHackMe Wireshark: The Basics — Task 1 Introduction & Task 2 Tool Overview Ian DBoggle-bytes in a Basic Data Partition Entry Markus Tuominen and Mehmet Mert Surmeli at WithSecureUnleashing the Power of Shimcache with Chainsaw N00b_H@ck3rCyberDefenders: AzurePot Phalgun Kulkarni and […]

View Details

Chris Doman at Cado SecurityThe Cado Platform Full Export for Forensic Data Lakes Digital Forensics MyanmarCHIP OFF ( Mobile FORENSIC) Domiziana FotiLetsDefend- SOC142 — Multiple HTTP 500 Response Oleg Afonin at ElcomsoftAnalyzing iPhone PINs Forensic Science International: Digital InvestigationVolume 44 JamfThreat advisory: Mobile spyware continues to evolve Mattia Epifani at Zena ForensicsiOS Forensics References: a curated list […]

View Details

Ahmed BelhadjadjiWindows Forensics: Event Logs Analysis David Spreadborough at AmpedPublic Submissions of CCTV and Video Evidence Elcomsoft Perfect Acquisition Part 4: The Practical Part Automating DFU Mode with Raspberry Pi Pico Automating Scrolling Screenshots with Raspberry Pi Pico Eric CapuanoCapturing & Parsing Forensic Triage Acquisitions for Investigation Timelining ForensafeInvestigating pCloud Invictus Incident ResponseRansomware in the […]

View Details

Andrew MalecIdentification, acquisition, and examination of iSCSI LUNs and VMFS datastores Monica Harris at CellebriteKey Takeaways and Highlights from Legalweek 2023 Chris at AskCleesImporting NSRL V3 hashsets into legacy tools Derek EiriGetting SMART(er) with Information Elcomsoft HomePod Forensics III: Analyzing the Keychain and File System Perfect Acquisition Part 3: Perfect HFS Acquisition ForensafeInvestigating Android Wi-Fi […]

View Details

Ahmed BelhadjadjiWindows Forensics: Examine Windows Files and Metadata David Spreadborough at Amped CCTV Recovery How to Use the Validation Tool in Amped FIVE Andrew Skatoff at ‘DFIR TNT’GoToForensics AvananThe Replier Attack Al Carchrie at Cado SecurityIPC YOU: How the Cado Platform Reveals Attacker Command Outputs  Dr. Ali Hadi at ‘Binary Zone’ Challenge #7 – SysInternals […]

View Details

Ahmed BelhadjadjiWindows Forensics Challenge Walkthrough (LETSDEFEND) Emma Sousa at Forgotten Nook CyberDefenders – Insider CyberDefenders – L’espion Eric Capuano Find Threats in Event Logs with Hayabusa A “Thank You” to Paid Subscribers So you want to be a SOC Analyst? Part 4 Forensafe Investigating Windows BitTorrent Investigating Windows Avira Antivirus Khris Tolbert at MaverisLabsHTB: CA2023 — Forensics […]

View Details

BelkasoftLagging for the Win: Querying for Negative Evidence in the sms.db David Spreadborough at AmpedCCTV Acquisition – Search and Trawl eForensics The Lockbit 3 Black Forensics Analysis: Memory Forensics Modern Approach (Part III) How to Better Prepare for a Memory Forensics Investigation Rooting Androids for Forensics iPhone Forensics Analyzing Malware Mobile Apps with VirusTotal Enterprise […]

View Details

Ahmed BelhadjadjiExamine the Cache, Cookies, and History Recorded in Web Browsers Belkasoft Walkthrough: Sigma Rules in Belkasoft X Basic but significant legal issues in the Casey Anthony Case Doug Metz at Baker Street ForensicsNSRL Query from the Command Line Eric CapuanoMounting E01 Forensic Images in Linux Foxton ForensicsAnalysing Safari browser history InfoSec Write-upsWindows Forensic 101: How […]

View Details

David Spreadborough at AmpedCCTV – The Beginners Guide Matt Danner at Cyber Social Hub3 Ways Programming Skills Can Help You Succeed In DFIR Dr. Tristan Jenkinson at ‘The eDiscovery Channel’The Importance of Data that Doesn’t Exist – Part Three (Missing Metadata – A Case Study) Forensafe Investigating Windows 1Password Investigating Windows Unigram Jerry ChangMason TCTF […]

View Details

Rushed last week and didn’t include Lee Whitfield’s post notifying the community that nominations for the 2023 Forensic 4Cast Awards is now open. Emi Polito at AmpedLearn How to Remove Sensitive Audio in Amped Replay: Ready, Steady, Redact! Amr AshrafRansomeWare Investigation Oleg Afonin at Elcomsoft Password Recovery and Data Decryption: Getting Around and About Right […]

View Details

David Spreadborough at AmpedIntroduction to CCTV Acquisition Dany at DigitellaExploitation Kit Network Traffic Investigation Forensafe Investigating Windows F-Secure Investigating Windows OpenVPN Magnet ForensicsUnderstanding Messages in Apple’s Cloud & Processing Warrant Returns Paolo Dal Checco at Studio d’Informatica ForenseManuale ENFSI per l’analisi dell’autenticità delle registrazioni digitali John Lukach at 4n6irNew Amazon Linux Triage Detection Adam Todd […]

View Details

Aditya PratapAcquisition & Analysis for Apple Devices Amanda Berlin at BlumiraWhat Are Event Logs and Why Do They Matter Cado Security and Invictus Incident ResponseCase Study Continued: Responding to an Attack in AWS Digital Forensics Myanmar eCDFP Module (5) File System Analysis (Part-12)  (NTFS File System Analysis) eCDFP Module (5) File System Analysis (Part-13)  (NTFS […]

View Details

Adam Cohen Hillel at Cado SecurityCado + GPT-3: Interactive Incident Response Digital Forensics Myanmar SQLite Database  Forensics (Note) eCDFP Module (5) File System Analysis (Part-11)  (NTFS File System Analysis) Doug Metz at Baker Street ForensicsKAPE batch mode, ARM Memory, updates to CSIRT-Collect, and all the things I learned along the way. Oleg Afonin at ElcomsoftForensically […]

View Details

Ali HadiAnit-Forensics Brian Carrier at Cyber TriageAnalyzing KAPE DFIR Artifacts in Cyber Triage Dany at DigitellaCyberDefenders HoneyBOT Challenge Write-up Derek EiriRetrieving Registry Values to Decrypt Files Protected with DDPE Dr. Neal Krawetz at ‘The Hacker Factor Blog’An Itty Midi Mystery Dr. Tristan Jenkinson at ‘The eDiscovery Channel’The Importance of Data that Doesn’t Exist – Part […]

View Details

Adam at HexacornExcelling at Excel, Part 3 Emi Polito at AmpedMeasuring in a Scene: What Filters to Use in Amped FIVE? Cado SecurityCase Study: Responding to an Attack in AWS Craig Ball at ‘Ball in your Court’Not So Fine Principle Nine Dany at DigitellaCyberDefenders PCAP Or It Didn’t Happen Challenge Write Up Domiziana FotiLetsDefend-SOC163 — Suspicious Certutil.exe […]

View Details

AbdulRhman Alfaifi at U0041Exploring Windows Artifacts : $Security Artifact Catie WalshSysInternals Case Write Up Dany at DigitellaUsing Powershell To Enumerate Information on Windows Defender and Firewalls Digital Forensics MyanmarBitLocker Decryption Methods Dr. Tristan Jenkinson at ‘The eDiscovery Channel’The Importance of Data that Doesn’t Exist – Part One (Timelines) Oleg Afonin at ElcomsoftiOS 15.5 Low-Level Keychain […]

View Details

Andrew Rathbun at AboutDFIR New Windows 11 Pro (22H2) Evidence of Execution Artifact! DFIR FYI: Security:4624 has been updated in Windows 11 Pro (22H2) Abdul ShareefDFIR-Resources Adam at HexacornExcelling at Excel, Part 1 Austin Songer at ‘Songer Tech’Evidence Gathering Recommendation: Adding TimeStamp To Screenshots BelkasoftNIST tested Belkasoft support for SQLite data recovery James McGee at […]

View Details

Welcome to 2023! I wrote a 2022 Wrap Up! Oleg Afonin at Elcomsoftcheckm8 for iOS 16.2 and Windows-based iOS Low-Level Extraction Joe T. Sylve, Ph.D. 2022 APFS Advent Challenge Day 18 – Decryption 2022 APFS Advent Challenge Day 20 – Snapshot Metadata 2022 APFS Advent Challenge Day 21 – Fusion Containers 2022 APFS Advent Challenge […]

View Details

And that’s a wrap for 2022! Things returned a lot more to normal down in Sydney, with pretty much all restrictions being lifted. We have seen a bit of an increase in COVID cases recently, and it seems almost everyone is getting it now (or again) – thankfully almost all the cases seem to be […]

View Details

CTF导航Cyberdefenders蓝队-恶意软件流量分析3 Dr. Neal Krawetz at ‘The Hacker Factor Blog’Weird Science ForensafeInvestigating Window Kaspersky Antivirus Howard Oakley at ‘The Eclectic Light Company’Rolling logs and anti-malware scans Jason Wilkins at ‘Noob to Pro Forensics’Drive Geometry, File Systems, and How Criminals Hide Data Joe T. Sylve, Ph.D. 2022 APFS Advent Challenge Day 13 – Data Streams 2022 APFS […]

View Details

Active CountermeasuresHunting Windows Event Logs Oleg Afonin at ElcomsoftWindows Account Passwords: Why and How to Break NTLM Credentials ForensafeInvestigating Window Google Drive Karthikeyan Nagaraj at InfoSec Write-ups Advent of Cyber 2022 [Day 11]-Memory Forensics-Not all gifts are nice Write up Advent of Cyber 2022 [Day 14]-Packet Analysis | Simply having a wonderful pcap time — Simple Write… […]

View Details

CyberJunnkiePhishing Email Challenge by LetsDefend Joseph Moronwi at Digital InvestigatorMalware Threat Hunting With Volatility ForensafeInvestigating Android Sygic Fallen sky at InfoSec Write-upsEmail analysis : avoid phishing attacks Joe T. Sylve, Ph.D. 2022 APFS Advent Challenge Day 3 – Containers 2022 APFS Advent Challenge Day 4 – NX Superblock Objects 2022 APFS Advent Challenge Day 5 – […]

View Details

Andrew Rathbun and Eric ZimmermanEZ Tools Manuals Digital Forensics Discord ServerThe Hitchhiker’s Guide to DFIR: Experiences From Beginners and Experts – v1.2 Bill Thompson at OpenTextGetting to know your tools Liu Zhixiangcheckm8提取速查表:iPhone、iPad Derek EiriPractical Linux Forensics & a Mini Linux Forensics CTF David Stenhouse at DS ForensicsMy Time With The Judge ForensafeInvestigating Windows Defender James […]

View Details

Ali Alwashali at ‘HackDefend Labs’Sysinternals case writeup Paul Lorentz at CellebriteSmart Flow – A super-charged single step for extractions in UFED 7.60 Domiziana FotiLetsDefend- SOC112 — Traffic to Blacklisted IP Doug Metz at Baker Street ForensicsGroup collections from O365 with PowerShell ForensafeInvestigating iOS FACEBOOK Messenger Haircutfish TryHackMe MITRE Room-Task 3 ATT&CK® Framework TryHackMe MITRE Room- Task 1 […]

View Details

Cado Security Enhancing Cado Community Edition with Velociraptor WatchDog Continues to Target East Asian CSPs The Ultimate Guide to Ransomware Incident Response & Forensics Dr. Ali HadiChallenge #7 – SysInternals Case Oleg Afonin at Elcomsoft Advanced Logical Extraction with iOS Forensic Toolkit 8: Cheat Sheet Cloud Forensics: Obtaining iCloud Backups, Media Files and Synchronized Data […]

View Details

Blake ReganHow to create a forensic image of a physical hard drive using FTK Imager Alan Flora at CellebriteUsing Pathfinder to Avoid Ethical Dilemmas in Digital Forensics CTF导航 inctf Forensic复现 | Memlabs(下) inctf Forensic复现 | Memlabs(上) 电子取证之NTFS基础 Digital Forensics Myanmar Browser Forensics (Firefox, Chrome, Edge, Opera, Brave) Clear Browsing Data  Forensics (Firefox, Chrome, Edge, Opera, […]

View Details

Cado SecurityAnalysing Docker Images in the Cado Platform CTF导航如何基于volatility2构建“新”版本内核的profile DFIR Review Wipeout! Detecting Android Factory Resets An Alternate Location for Deleted SMS/iMessage Data in Apple Devices iOS KnowledgeC.db Notifications Digital Forensics Myanmar Disk Scan (OR) Low Level Enumeration  (NTFS  File System) Zone.idnetifier  In Master File Table (MFT) Joseph Moronwi at Digital Investigator IP Geolocation: A […]

View Details

CyberJunnkiePrintNightmare : Memory forensics and Network forensics challenge -> Letsdefend Derek EiriExploring AI Assisted Picture Categorization with Magnet Forensics AXIOM and X-Ways Forensics with Excire, Re: Weapons Digital Forensics MyanmarDisk Scan (OR) Low Level Enumeration  (FAT File System) Erik Hjelmvik at NetresecWhat is a PCAP file? ForensafeInvestigating VirtualBox Haircutfish TryHackMe Volatility — Task 2 Obtaining Memory Samples Secure […]

View Details

Krzysztof Gajewski at CyberDefNerdThe $MFT flag that you have never considered before – OneDrive not synchronized files. Mohamed Labib at DetectiveStringsMay svchosts guid you Domiziana FotiLetsDefend- SOC 175- PowerShell Found in Requested URL-Microsoft Exchange Server… ForensafeInvestigating FileZilla Fox-ITI’m in your hypervisor, collecting your evidence InfoSec Write-upsPylirt — Python Linux Incident Response Toolkit Md. Abdullah Al MamunMy Recent […]

View Details

John Lukach at 4n6irAmazon Linux Triage for Anyone and Everyone ArcPointGetting started with ALEAPP | ArcPoint Forensics Cyrill Brunschwiler at Compass SecurityTutorial on how to Approach Typical DFIR Cases with Velociraptor ForensafeInvestigating Ouick Access Harel Segev at ‘RAT In Mi Kitchen’The Forensic Value of the (Other) WSH Registry Key Lina Lau at InversecosHow to Investigate […]

View Details

Andre Maccarone and John Ailes at AonAmazon Web Services: Exploring the Cost of Exfil CERT-SE CTF2022CERT-SE CTF2022 CyberJunnkieIncident Response LetsDefend : Detecting Web App attack and detecting persistence Forensafe Investigating LogMeIN Investigating ExpressVPN Kathryn HedleyWindows 11 Time Rules Magnet ForensicsSRUM: Forensic Analysis of Windows System Resource Utilization Monitor Carl Purser at OpenTextApple property list parsing with […]

View Details

Chris Vance at ‘D20 Forensics’ iOS 16 Breaking Down the Biomes Part 2 – AppInstalls, AppLaunch, & AppIntents iOS 16 – Breaking Down the Biomes (Part 3) – Keeping up with CarPlay iOS 16 – Breaking Down the Biomes (Part 4) – Surfin’ with Safari iOS 16 – Breaking Down the Biomes Part 5 — […]

View Details

Chris Vance at ‘D20 Forensics’ iOS 16 – “Paul unsent a message.” … OR DID HE?! iOS 16 – Now You ‘C’ It, Now You Don’t — Breaking Down The Biomes Part 1 Krzysztof Gajewski at CyberDefNerdC:\ProgramData\Microsoft\Event Viewer\ExternalLogs – artifacts showing what Windows Event Logs were opened on the suspected device. Joseph Moronwi at Digital […]

View Details

Digital Forensics Myanmar Digital Forensics Myths & Reality DFIR Field Mistake How To Use Forensics Reader And Viewer Joseph Moronwi at Digital InvestigatorFile Signature And Hash Analysis Oleg Afonin at ElcomsoftEntering DFU: iPhone 8, 8 Plus, and iPhone X Forensafe Investigating WordPad Recent Files Investigating Windows Startup Programs Forensics [Insider]Basic Concepts in Mobile Device Forensics […]

View Details

Jessica Hyde at HexordiaPeer Review for Mobile Forensics Joseph Moronwi at Digital InvestigatorFile Carving In Windows Forensafe Investigating Microsoft Management Console (MMC) MRU Investigating WordPad Recent Files Lina Lau at InversecosForensic Detection of Files Deleted via SDelete Magnet ForensicsWhat is MRU (Most Recently Used)? Mattia Epifani at Zena ForensicsAndroid Forensics References: a curated list Muhammed […]

View Details

Alican KirazThreat Hunting for Windows Registry Blake ReganPicking the right gear for your DFIR write-blocker kit Derek EiriAssembling a Go-Bag, Re: Write Block Options? Joseph Moronwi at Digital InvestigatorUsing The Wayback Machine For OSINT Forensafe Investigating WinZip Investigating Swap File URL’s ForensiumFirmware extraction from BT headset 2 InfoSec Write-upsS3 Bucket: Cloud Trail Log Analysis Kevin […]

View Details

Cado SecurityAWS EC2 Incident Response CovertshellDFIR triage and Timeline Analysis Danus MinimusThe guide for a freeloader Threat Intelligence Analyst and Malware Researcher Digital Forensic ForestBlue Team Cheat Sheets Digital Forensics Myanmar NTFS Index Attributes B-Trees (NTFS) IOS Crash & Sysdiagnose Log – PDF Oleg Afonin at ElcomsoftLow-Level Extraction of iOS 15.2-15.3.1 Forensafe ArtiFast ShimCache Parser […]

View Details

BelkasoftSQLite Forensics with Belkasoft X Cyber TriageWhat is a Windows Recents Folder Artifact? Joshua I. James at DFIRScienceiLEAPP and RLEAPP updates and dev thoughts Elcomsoft Probing Linux Disk Encryption: LUKS2, Argon 2 and GPU Acceleration Breaking Windows Passwords: LM, NTLM, DCC and Windows Hello PIN Compared Erik Hjelmvik at NetresecWhat is PCAP over IP? ForensafeLast […]

View Details

Jessica Hyde at HexordiaCreating Synthetic Test Data Asger SGeolocating IP addresses in Velociraptor Gary Warner at CyberCrime & Doing TimeThree UK-based Nigerian BEC Scammers Used Construction Intelligence Service to Target Victims Joshua I. James at DFIRScienceModular artifact scripts coming to iLEAPP Muhammed AygünBAM/DAM Analizi N00b_H@ck3rLetsDefend: Memory Dumper Oxygen ForensicsExtract Data from OnlyFans App with Oxygen […]

View Details

AxelaratorCloud Recon BelkasoftBelkasoft CTF July 2022: Write-up Carlos at Carlos Cajigas at ‘Mash That Key’Velociraptor Playground 2022-08-02 CloudbrothersUpdate to the Hitchhiker’s Guide to Microsoft Defender for Endpoint exclusions Cyber TriageWhat is a Windows OpenSave MRU Artifact? Yogesh Khatri at DFRWSDFRWS APAC 2022 Call for participation Elcomsoft Windows Hello: No TPM No Security New in Elcomsoft […]

View Details

Andrew RathbunWindows 10 vs. Windows 11, What Has Changed? Cyber TriageWhat is a Microsoft Office Most Recently Used Artifact “MRU” Joseph Moronwi at Digital InvestigatorWindows Memory Dump Analysis With Volatility Doug Metz at Baker Street ForensicsMagnet 2022 CTF – iOS15 Vladimir Katalov at Elcomsoftcheckm8 Extraction: iPhone 7 Elizabeth McPherson at HexordiaJailbreaking iPhone XR with unc0ver […]

View Details

Andrew MalecSecurity Patch/KB Install Date Arsenal ReconCheck out Arsenal Recon’s post Krzysztof Gajewski at CyberDefNerdEasy way to prove that a file was downloaded by a web browser, having only $UsnJrnl logs. Digital Forensics Myanmar Unkown USB Stick  Analysis Smart Watch Forensics Joseph Moronwi at Digital InvestigatorImage OSINT Investigations Dr. Neal Krawetz at ‘The Hacker Factor […]

View Details

Heather Mahalik at CellebriteFinal CTF 2022 Round Up Scott Koenig at DFIR ReviewiOS Location Services and System Services are they ON or OFF Digital Forensics Myanmar eCDFP Module (5) File System Analysis (Part-9)  (NTFS File System Analysis) eCDFP Module (5) File System Analysis (Part-10)  (NTFS File System Analysis) Forensafe Investigating Windows Terminal Investigating Mapped NEtwork […]

View Details

Mark Spencer at Arsenal ReconMaximum Exploitation of Windows Registry Hive Bins Cellebrite Part 2: CTF 2022 Write Up – Heisenberg’s Android Part 3: CTF 2022 Write Up – Marsha’s iOS Device Part 4: CTF 2022 Write Up – Beth’s iOS Device Krzysztof Gajewski at CyberDefNerdStripped off ADS (Zone.Identifier) for files downloaded in the incognito/private mode. […]

View Details

A monthly wrap-up of the DFIR news for June 2022. Thank you to those Patreon donors for the last month. This project takes a lot of time, so it’s very much appreciated that people see enough value in it to contribute back 🙂 If you are a Patreon donor the show notes will be found here. Special […]

View Details

The voting for the 2022 Forensic 4Cast Awards has been opened. Thank you everyone that nominated this website, please make sure to cast your votes below!2022 Forensic 4:cast Awards – Voting is now OPEN BlackholdVolcado de memoria con LiME y análisis con Volatility Blake’s R&DA Begginers All Inclusive Guide to ETW DaddycocoamanDumping RSA Certificates with […]

View Details

Patrick Bennett at CrowdStrikeThe Call Is Coming from Inside the House: CrowdStrike Identifies Novel Exploit in VOIP Appliance Cyber Social HubHow To Use ExifTool To Look At Metadata Digital Forensics Myanmar eCDFP Module (5) File System Analysis (Part-6)  (NTFS File System Analysis) OSINT Critical Thinking For Social Media Elcomsoft checkm8 Extraction: the iPads, iPods, and […]

View Details

Lee Whitfield has opened the nominations for the Forensic 4cast awards for another week; get your last minute nominations in now!Forensic 4:cast Awards – Update Didier StevensDiscovering A Forensic Artifact Digital Forensics Myanmar How the Federal Government Buys Our Cell Phone Location Data By  BENNETT CYPHERS  (Myanmar Translation) Solid State Drive (SSD) Structure & Forensics […]

View Details

Asger SCreating Standalone Artifact Collector Belkasoft How to use Advanced Filters with Belkasoft X The importance of fully charged devices in your digital forensic investigation Digital Forensics Myanmar eCDFP Module (5) File System Analysis (Part-5) #DVR_NVR_Forensics Oleg Afonin at ElcomsoftFilling the Gaps: iOS 14 Full File System Extracted ForensafeInvestigating Windows LogFile Ian Whiffin at DoubleBlakiOS16iMessage […]

View Details

4DiscoveryCase Study: The Executive Stealing Company Data Cado SecurityTales From the Honeypot: WatchDog Evolves With a New Multi-Stage Cryptojacking Attack Dr. Brian Carrier at Cyber TriageCyber Triage Lite – Identifying OS Configuration Luca Ebach at cyber.wtfWindows Registry Analysis – Today’s Episode: Tasks Krzysztof Gajewski at CyberDefNerdHow long was the malicious PowerShell script active on the […]

View Details

Asger SDeadhost Investigation and Super Timeline Block MagnatesRikkei Finance Hack: Explained Cassie Doemel at AboutDFIRApp Timeline Provider – SRUM Database Chris at AskCleesDecrypting Mega Preferences (Part 2) Dr. Brian Carrier at Cyber TriageCyber Triage Lite – Identifying Malware Digital Forensics Myanmar Imaging Unlocated Space  & Install FTK Imager On USB What Is Call Details Record […]

View Details

Ahmed AliCouch to 5K Runner: A Mobile Forensics Investigation BelkasoftWhere in the world was John McAfee and An0nymous? A tell-tale sign from EXIF data Matt Muir at Cado SecurityLinux Attack Techniques: Dynamic Linker Hijacking with LD Preload Christopher KyriacouForensic Investigation of the Grubhub iOS App Joshua I. James at DFIRScience Tableau External Write Blocker Setup […]

View Details

Aditya PratapWindows Triaging with Powershell — Part 2: Artifacts Collection Heather Mahalik at CellebriteCellebrite Capture the Flag – May 2022 Chris at AskCleesDecrypting Mega’s megaprefences Sqlite Database Digital Forensics MyanmareCDFP Module (5) File System Analysis (Part-3) Elcomsoftcheckm8: Unlocking and Imaging the iPhone 4s ForensafeInvestigating UserAssist Kevin Pagano at Stark 4N6 Magnet Virtual Summit 2022 CTF – Egg […]

View Details

4DiscoveryThe Forged PDF ADEO Cyber Security ServicesChupacabra Digital Forensic Training Set 2022 by ADEO DFIR Team Angry-Bender’s blog house Cobalt Strike Decoding Handy DFIR Excel Formulas Yulia Samoteykina at AtolaRAID imaging made easy with Atola TaskForce  CellebriteThe Small Agency Guide to Modernizing Investigations Dan Maunz at CiscoCisco StarOS Forensic Guide Published ForensafeInvestigating Timezone Information Kevin […]

View Details

BelkasoftDealing with encryption within digital forensic and cyber incident response investigations Krzysztof Gajewski at CyberDefNerdArtifacts that you have never analyzed before… namely ETL files. Digital Forensics Myanmar eCDFP Module (5) File System Analysis (Part-1) eCDFP Module (5) File System Analysis (Part-2) Michael Karsyan at Event Log Explorer blogWorking with disk images in Forensic Edition ForensafeInvestigating […]

View Details

Jessica Hyde at Magnet ForensicsAndroid Motion Photos in Magnet AXIOM Aditya PratapWindows Triaging with Powershell — Part 1: Parsing Event Logs Blake’s R&DExtracting Cobalt Strike from Windows Error Reporting Cyber Social HubUnderstanding Tox Chat Dr. Neal Krawetz at ‘The Hacker Factor Blog’Where’s My Stuff? Jess Garcia at DS4N6[BLOG]  ODSC East 2022 – “Data Science for Digital Forensics […]

View Details

Cado SecurityInvestigating AWS ECS with Cado Response Chris Vance at ‘D20 Forensics’[Air]Tag You’re It! DFIR Review Ain’t That a Kik in the Head: Kik Messenger iOS Analysis Case Study: Forensic Analysis of TikTok on iOS Oleg Afonin at ElcomsoftDecrypting Password-Protected DOC and XLS Files in Minutes ForensafeInvestigating Foxit Reader Erik Schamper at NCC GroupA brief […]

View Details

Joshua James at DFIRScience Getting started in DFIR: Conferences and Workshops Oculus Quest 2 First Impressions and Research Notes DiabloHornFirewall analysis: A portable graph based approach Didier Stevens.ISO Files With Office Maldocs & Protected View in Office 2019 and 2021 Oleg Afonin at ElcomsoftUnlock WordPerfect and Lotus Documents with Advanced Office Password Recovery Brian Bahtiarian, […]

View Details

Christopher Romano and Vaishnav Murthy at CrowdStrikeCloudy with a Chance of Unclear Mailbox Sync: CrowdStrike Services Identifies Logging Inconsistencies in Microsoft 365 Krzysztof Gajewski at CyberDefNerdWhy do the battery use and the battery level matter during the investigation? Oleg Afonin at ElcomsoftWindows 11 TPM Protection, Passwordless Sign-In and What You Can Do About Them ForensafeInvestigating […]

View Details

Ahmed MusaadAnalyse Large Log Files Using ELK Andrew MalecAnyDesk Remote Access Benjamin Bruppacher at Compass SecurityVPN Appliance Forensics Dr Brian Carrier at Cyber TriageCyber Triage Lite – Analyzing User Activity Oleg Afonin at ElcomsoftSimplifying Digital Triage with Bootable Forensic Tools ForensafeInvestigating Page File URL’s Forensic-Research[논문리뷰] 이메일 원격지 압수·수색의 적법성에 관한 소고 – 대법원 2017.11.29. 선고 […]

View Details

Andy SmithForensic Analysis of Citymapper for Android Belkasoft BelkaCTF “Kidnapper Case” write-up The case of a missing girl and the power of a memory dump ForensafeInvestigating Logon Banner Geri at ‘4n6 Ninja’(Air)Dropping some Knowledge: Using  RLEAPP to Identify the Phone Number Used in an AirDrop Transfer Google Workspace UpdatesView more information on email delegate activity […]

View Details

Amber Schroader at Cyber Social HubExpectations of Facebook Data Dr. Brian Carrier at Cyber TriageCyber Triage Lite – Network, Disk Image, and Memory Inputs Krzysztof Gajewski at CyberDefNerd Battery charge level and its importance in forensics investigations. Quick analysis of the Internet Download Manager history using RegRipper plugins. Digital Forensics MyanmarFTK Imager ကိုဘာလို့နမူနာထားပြတာလဲ ForensafeInvestigating Windows […]

View Details

Kevin Ripa at SANSThe Truth About USB Device Serial Numbers – (and the lies your tools tell) Kibaffo33Decoding Vaulty Dr. Neal Krawetz at ‘The Hacker Factor Blog’Information Warfare ForensafeInvestigating ThumbCache Forensic-ResearchVirtualBox 가상머신의 메모리 덤프 추출 Magnet Forensics Analysis of Hikvision Date/Time DFIR in Zero-Trust Environments: Utilizing AXIOM Cyber for Remote Collection with Zscaler Data Recovery […]

View Details

A monthly wrap-up of the DFIR news for February 2022. Thank you to those Patreon donors for the last month. This project takes a lot of time, so it’s very much appreciated that people see enough value in it to contribute back 🙂 If you are a Patreon donor the show notes will be found here. Special […]

View Details

Kevin RipaThe Truth About USB Device Serial Numbers – (and the lies your tools tell) BelkasoftWhy RAM dumping is so important and what tool to use? CellebriteIsolating Devices to Preserve Evidence Cheeky4n6MonkeyMonkey Attempts To Digest Some Google Takeout (DetectedActivitys) Digital Forensics MyanmarCHFI-V10-Dark Web-Note ForensafeInvestigating Windows Recycle Bin Herbie Zimmerman at “Lost in Security”2022-02-26 Quick Post […]

View Details

Abdallah Elnoty2019 Defcon DFIR CTF Write-up (Memory Forensics) Camille LoreParsing Google Voice Search CellebriteCellebrite Announces Fourth Quarter and Full Year 2021 Results Dr. Neal Krawetz at ‘The Hacker Factor Blog’Three Minute Forgeries Elcomsoft Dude, Where Are My Messages? GPU Acceleration On The Cheap: Using Affordable Video Cards to Break Passwords Faster ForensafeInvestigating PowerShell InfoSec Write-ups […]

View Details

ThinkDFIRTracking screenshots with LNK files Adam at HexacornAnalysing NSRL data set for fun and because… curious, Part 2 Awake SecurityForensic Investigation of the MEGAcmd Client Cellebrite Crime and Terrorism Have Changed: Today’s Investigators Rely on Digital Evidence How Digital Analysts Manage the Impact of Malware Nandeesha B at NII ConsultingThreat actor groups are targeting VMware […]

View Details

Digital Forensics MyanmarWindow Forensics With EZ-Tools (Part 1+2) diyinfosecWhy learning a Forensic Artifact matters? Elcomsoft checkm8 Extraction of iPhone 8, 8 Plus and iPhone X iPhone X, DFU mode and checkm8 Simon Wong at ExpelAttack trend alert: AWS-themed credential phishing technique ForensafeInvestigating User Accounts Lee Whitfield at Forensic 4castMac Randomization in Windows Forensic-Research [ART100] Digital […]

View Details

A monthly wrap-up of the DFIR news for January 2022. Thank you to those Patreon donors for the last month. This project takes a lot of time, so it’s very much appreciated that people see enough value in it to contribute back 🙂 If you are a Patreon donor the show notes will be found here. Special […]

View Details

Marco Fontani at AmpedHow To Check Video Integrity By Detecting Double Encoding With VPF Analysis   CCL SolutionsUPDATE – Relativity Processing vs. Nuix Workstation   Dr. Brian Carrier at Cyber TriageGeneral Purpose vs Specialized Digital Forensics Tools   ForensafeInvestigating Cortana   “Forensics – One Byte at a Time”Decrypting ‘Secret Calculator Photo Vault’   Febi Mudiyanto […]

View Details

Appalachian4n6AirTags within iOS File Systems BelkasoftWhere did this chat come from? The ‘Origin path’ concept in Belkasoft X Blake’s R&DMachine Learning and ETW Cado SecurityTechnical Indicators of Ukrainian Website Defacements James Lovato at CrowdStrikeMind the MPLog: Leveraging Microsoft Protection Logging for Forensic Investigations Krzysztof Gajewski at CyberDefNerdCan Windows Update fool you during the investigation? Digital […]

View Details

Bart Butler at ProtonMailA breakdown of a DKIM replay attack James Merritt at CCL SolutionsRelativity Processing vs. Nuix Workstation Roman Ferdigg at CertitudeRansomware Actor May Have Leaked Their Previous Victims Craig Ball at ‘Ball in your Court’Electronic Evidence Workbook 2022 Paul Pratley and Mark Goudie at CrowdStrikeCrowdStrike Services Offers Incident Response Tracker for the DFIR […]

View Details

David Cowen at the ‘Hacking Exposed Computer Forensics’ blogDaily Blog #703: Looking back at AWS EBS Direct Block access API ThinkDFIRI can see and hear you seeing and hearing me! Alex Caithness at CCL SolutionsAndroid ABX – Binary XML Cheeky4n6Monkey and Michael LacombeMike & the Monkey Dumpster Dive Into Samsung Gallery3d App Trash Doug Metz […]

View Details

DFIR ReviewValidation of X-Ways Forensics Evidence File Containers Kibaffo33At the roundabout, take the second exit… Daniela Elmi Best of Digital Forensics Cheatsheet Security Logs Dr. Neal Krawetz at ‘The Hacker Factor Blog’Sharing Research Elcomsoft Breaking BestCrypt Volume Encryption 5 Digital Evidence in Encrypted Backups Forensafe Investigating Task Scheduler Investigating Remote Desktop Connection MRU Hal Pomeranz […]

View Details

And that’s a wrap for 2021! Was it better than 2020? Maybe a little? Down in Sydney we spent a bit longer in lock-down here – 3-4 months I think it was this time around, but otherwise life was “COVID normal”. I can empathise with those that were hit hardest by this all, and thankfully […]

View Details

Alexis Brignoni at ‘Initialization Vectors’Android Tor Browser Thumbnails. What? Adam at Hexacorn Mapping Chrome extension IDs to their names Putting .inf files and NSRL database to a better use AhnLabCase of Ransomware Infection in a Company Using Local Administrator Accounts Set with Same Password Blake’s R&DMonitoring File mods through ETW and Velociraptor Matt Muir at […]

View Details

Brandon Lee at 4sysopsRecover deleted emails in Microsoft 365 Ahmed MusaadGoogle Workspace Security Investigation Tool BelkasoftiCloud acquisition and analysis with Belkasoft X Doug Metz at Baker Street Forensics Adding RAM collections to KAPE Triage CSIRT-Collect USB Dr. Neal Krawetz at ‘The Hacker Factor Blog’Apple and Fraud Elcomsoft More on checkm8 and USB Hubs, Upcoming iPhone […]