Good news everyone!! A minor update to the Live Response Collection has been published. It ensures the "Secure" options properly securely delete the collected data after the zip file creation, because of an update to the executable #DFIR https://t.co/JYJTvxM7L4
What are you gonna be doing at the beginning of October?
@tmesick1 and I, along with many others, will be speaking at the #ThreatHuntingSummit in New Orleans. Come join us!
https://t.co/przjibDOEL
@eric_capuano@EricRZimmerman@blueteamerAU @jamdunnDFW The CLI version works great for scripting disk image collection, but I would never, ever recommend using FTK Imager to collect memory (fails far too often*) or mount any image (so many better options available)
*Based on my own usage, experiences, as well as feedback from others
Good news everyone!! As long as the order arrives on time, there will be a brand new batch of BriMor Labs stickers that will be available to anyone who wants one at the SANS #DFIRSummit in Austin next week!
Good news everyone!! A new blog post, covering utilizing Photoshop to help automate part of RDP bitmap reconstruction, is now up! https://t.co/gPvzl40SeG #DFIR
Good news everyone!! A new blog post is up, which details the newest version of the Live Response Collection, Cedarpelta! https://t.co/WHnNoxOO4n #DFIR
Working on updates and enhancements for a new version of the Live Response Collection. This release is MacOS heavy, any features that you'd like to see?
Good news everyone!! A new blog post, covering some interesting details regarding Skype and older versions of Android, is up! https://t.co/YBmWVyhViS #DFIR
@jamesejr7@iamevltwin I've thought about doing that for quite some time, and I'm still debating the pros and cons of doing that. Also looking at other code hosting options as well.
TBH it can be tough to find the time to get updates done, let alone migrate it to a code sharing platform :)
Good news everyone!! A new blog post, detailing my 2018 roadmap for the Live Response Collection (with an extra special shout out to @iamevltwin ) is up! https://t.co/fClSNYsb3N #DFIR
Good news everyone!! A new blog post "Let's Talk About Kext" is up! I'd love to hear any ideas on how you are (reliably) dumping memory from a MacOS system with SIP enabled!
https://t.co/ZF0xHW5Yxj #DFIR#mac4n6
Pro Tip: If you are going to have a "Cybersecurity Association" of any kind, especially one that is associated with local, county, or state government, make sure that you have good cyber security procedures and policies in place #ThatThereIsWhatWeCallAPhishyAttachment
Good news everyone!! A new blog post, "Who's down with PTP?" is up, covering ways to work through acquisition of a mobile device when nothing seems to work right!
#DFIR
https://t.co/ZJYFUmjfCa
Good news everyone!! A new blog post, covering "fishing for work" (which is different than phishing) is up!! Also talk about IOC sharing, responsible disclosures, etc! #DFIR https://t.co/MIeebWU5Zu
I am going to talk about what led up to this awesome article in a blog post that will be out shortly. Great work by the folks at @arbornetworks
https://t.co/pTjNv4NS8P
#DFIR
All 30 free cybersecurity and cybercrime investigations trainings are now posted! Locations are throughout the state of Ohio. The Secret Service and FBI cyber unit will be joining us for the LE trainings. https://t.co/goLIckGLpk