Join us at #DFIRSummit when @DavidPany and @BSlay88 discuss how they plan attack diagrams and tools they have used so you can develop your first or next diagrams.
Register here: https://t.co/wdW6548mxp
#DFIR#IR#IncidentResponse
Is it weird that it’s a well known faux pas to roll your own crypto, but every website has been rolling their own identity with password policies, hashing, salting, storing, mfa, etc. for many years?
Recent advances in “log on with” providers must be relief for devs.
Anyone know if Sysmon EID 9 RawAccessRead can record the target file being accessed? I only see the process doing the access (less useful if injected) and the Device being accessed (how is that useful?). Not seeing answers in docs/blogs/etc.
#DFIR
Planning a New Year's resolution to get a new job at an awesome #DFIR company? Make it happen with:
Weekend shift IR: https://t.co/CyZPvaZij7
Engineering our in house world class toolset:
https://t.co/VIbeaqzEMh
https://t.co/uOaonScgUa
Questions? Let me know.
@inversecos Such a good artifact! In case you have the full image and haven't already tried this, point this usn jrnl record carver at the whole thing and parse the output with your preferred $J parser. It's amazing what has turned up in unallocated journal records: https://t.co/yHJgmFRUPg