As EDRs advance, red teams must evolve to keep up with real-world threats.
@StrozDFIR, a LevelBlue company, introduced SharpParty—a C# version of the PoolParty process injection technique that gives red teamers more payload options.
Learn more👇
https://t.co/gmX5R4tw7D
Threat actors don’t just break in—they stick around. Learn how they persist in #Microsoft365.
Catch Federico Cedolini at the @SansInstitute#DFIRSummit:
🎤 Backdoors & Breadcrumbs
🕥 July 24, 2025, 10:35 AM – 11:10 AM MDT | 12:35 PM –1:10 PM ET
🆓 Register: https://t.co/lZygBBtNhy
#StrozFriedberg #DFIR #IncidentResponse
Incomplete or unreliable log data is a common challenge in #DFIR.
Join Colin Meek at the @SANSInstitute#DFIRSummit for a look at forensic log extraction techniques—plus a demo of LAVA, a new open-source log anomaly analysis tool.
🕒 July 24, 2025, 3:25–4:00 PM MDT | 5:25–6:00 PM ET
🔗 https://t.co/7fogQH6P9h
🆓 Register: https://t.co/lZygBBtfs0
#StrozFriedberg #IncidentResponse #LogAnalysis
We are excited to announce that @StrozDFIR is set to join @LevelBlueCyber as part of a definitive agreement to acquire Aon’s Cybersecurity and Intellectual Property (IP) Litigation consulting groups. This marks a new chapter for us, enhancing our offerings and allowing us to continue delivering exceptional services to our clients.
We are grateful for your support and look forward to the opportunities this acquisition will bring.
Stroz Friedberg has released Quick ESXi Log Parser (QELP), an open-source tool to swiftly parse ESXi logs and identify suspicious activities. Learn more about how QELP can enhance your DFIR investigations.
Read more: https://t.co/QWrb21hp1W
GitHub: https://t.co/MNEcrO9Z0m
#Aon #StrozFriedberg #DFIR #IncidentResponse #ESXi #opensource #ransomware
Join Chapin Bryce from our Solutions Development team at #Shmoocon in DC on January 11 for his talk with Brittney Argirakis on the importance of tracking cloud instances within your environment and their open-source tool to support those efforts.
Learn more: https://t.co/I6V46V2FuR
#StrozFriedberg #Aon #Shmoocon #SoftwareDevelopment #DFIR #IncidentResponse
Stroz Friedberg has released a Python script that processes Jenkins job and plugin configurations, extracting key attributes into a CSV file to help identify suspicious activity.
Read more here: https://t.co/uqX0DfOin6
GitHub link: https://t.co/sWFAUf8aQf
#Aon#StrozFriedberg #DFIR #IncidentResponse #Jenkins #opensource
In our latest blog, 'Mounted Guest EDR Bypass,' we explore a technique used by a ransomware group to bypass Endpoint Detection and Response (EDR) protections.
Read more here: https://t.co/zG6q8CG9pH
#DFIR#IncidentResponse#StrozFriedberg#Aon#Ransomware
🚀 Exciting Internship Opportunity in #Cybersecurity🚀
Kickstart your cybersecurity career with Aon through our Cyber Summer Associate Program! Whether you're interested in Digital Forensics and Incident Response (DFIR), Security Testing, or Security Advisory, this is your chance to gain hands-on experience and make an impact. Our 10-week summer internship begins in June 2025 and offers exposure to real-world #cybersecurity consulting. You’ll have the opportunity to work in one of our cutting-edge forensic labs in NYC or DC, where you’ll collaborate on live cyber investigations and solve complex challenges alongside industry experts.
📅 Important Dates:
- Applications Open: Sept 24, 2024
- Application Deadline: Oct 15, 2024
- Program Start Date: June 2025
Don’t miss this opportunity to jumpstart your career in the fast-growing world of cybersecurity. Join us and be part of the future of cybersecurity!
Apply now and learn more about this exciting program: https://t.co/0mm3Za79K2
#StrozFriedberg #DFIRjobs #Aon #DigitalForensics #IncidentResponse #Internship #CyberCareers
In our latest blog, 'Bypassing EDR through Retrosigned Drivers and System Time Manipulation,' we explore a new variation of a technique used by ransomware groups to bypass EDR and obscure malicious activities by leveraging expired code signing certificates to load malicious kernel drivers.
Read more here: https://t.co/I63BGDIXyQ
#StrozFriedberg #Aon #DFIR #IncidentResponse
🚀 Exciting Early Careers Opportunity in #DFIR! 🚀
Love solving puzzles? Want to be on the front lines of investigating cyber investigations? Kickstart your career with our Stroz Friedberg Digital Forensics and Incident Response practice! Our Cyber Associate Program is a full-time role starting in August 2025, offering hands-on experience in #cybersecurity consulting. Work in one of our forensic labs in NYC, Chicago, DC, or Boston, and collaborate on real-world cyber investigations.
📅 Important Dates:
- Applications Open: Sept 3, 2024
- Deadline: Sept 17, 2024
- Program Begins: August 2025
Join us and be part of the future of cybersecurity!
Apply and learn more here: https://t.co/rJ7X1Az3WN
#StrozFriedberg #DFIRjobs #Aon #DigitalForensics #IncidentResponse
Stroz Friedberg identified a stealthy #malware, dubbed “#sedexp,” utilizing Linux udev rules to achieve persistence and evade detection. This advanced threat, active since 2022, hides in plain sight while providing attackers with reverse shell capabilities and advanced concealment tactics.
Read More: https://t.co/kkE4Cn5Aiq
#DFIR #IncidentResponse #Aon #StrozFriedberg
Rachel Kang will be speaking at #BSides Pittsburgh on July 12 about "The New Generation of #Phishing: Beyond the Mailbox". Her session will cover recent techniques in phishing and #BEC.
Learn more: https://t.co/RRgIrzeck1
#StrozFriedberg#DFIR#IncidentResponse#Aon
Join the Stroz Friedberg DFIR team during our three #RSAC2024 presentations on Thursday, May 9, 2024.
Links:
1. Beyond Cookies: The Unseen Privacy Risks of Web Analytics - https://t.co/xiljFTWFgN
2. What A Cloud Bill Can Reveal - https://t.co/hA0echQWuJ
3. Learn to Forensicate: Testing the Waters of DFIR - https://t.co/dgWE1r7jRz
Learn more about web privacy from Heidi Wachs and Mitch Green at our #RSAC2024 presentation, "Beyond Cookies: The Unseen Privacy Risks of Web Analytics" on May 9 at 9:40am PT.
To view details on the session and reserve a seat visit https://t.co/h8YD0PJ1c8
#StrozFriedberg#DFIR #IncidentResponse #Aon #RSAC
If you're in San Francisco for #RSAC2024 tomorrow, check out Stroz Friedberg's talk "What A Cloud Bill Can Reveal" by Andre Maccarone at 10:50am PT.
To view details on the session and reserve a seat visit https://t.co/Wh5MJEbGt2.
#StrozFriedberg#DFIR#IncidentResponse#Aon #RSAC
Join our DFIR directors Partha Alwar and Carly Battaile for a forensic-focused Learning Lab at #RSAC2024 in San Francisco on May 9 at 8:30am PT.
To view details on the session and reserve a seat visit https://t.co/EKu34XiKbB
#StrozFriedberg#DFIR#IncidentResponse#Aon#RSAC