🎁 GIVEAWAY! 🎁
I've partnered with DFIR expert Robert Fried who is generously giving 12 FREE registrations to his online course to the DFIR community!
The course, "Data Forensics Class: Data Collections" is packed with 1.5 hours of content - including what you need to know and the questions you need to ask when encountering electronic evidence in a litigation matter or an investigation. Topics include:
- Electronically Stored Information (ESI)
- Computers
- Email
- Network File Shares
- Mobile Devices
- Databases
- Cloud Storage
- Social Media
- Remote Data Collections
- Data Collection Considerations
(Supplemental material is included)
To enter the giveaway: Like, Repost, and Leave a Comment
On August 25th, 2024: 6 winners will be chosen from LinkedIn and 6 winners will be chosen from Twitter(X).
But that's not all! Everyone can get 50% off the course until 9/30/2024 using code: DFIRDIVA50
Link to the course: https://t.co/aXWpG9erW5
#DFIR #DigitalForensics
I hacked the @SAP AI platform by changing my UID to 1337.
…Yeah, really.
This led to admin permissions on several SAP systems, but also access to customers’ secrets and private AI files 👀
This is the story of #SAPwned 🧵⬇️
Reverse Engineering Malware, Part 3: IDA Pro Introduction
This course is designed for those of you who want to ascend to the pinnacle of Digital Forensics and Cyber Security.
https://t.co/7P8GjpoZc8
@three_cube#hacking#malware#ida
SIEM users I beg of you. Please stop enabling all default rules. Many of these defaults include tools or services you aren't using. You're slowing down a SIEM for no reason at all.
Want faster queries? tune your SIEM. (or hire someone who can!)
In Microsoft Sentinel you can join Microsoft Entra ID sign in events to Microsoft Defender for Cloud App activities (for some actions & workloads) via the UniqueTokenIdentifier. This is a useful way to see what 'happened' during a sign in
I added some maturity models and stuff to the framework section of my awesome detection list a while back (https://t.co/D21K9bOpvo), thinking they'd come in handy one day. today, after needing something similar and spending hours on a d&r maturity model, I revisited my list and
FREE Challenge: Winrar 0-Day
⚡ Investigate Winrar Zero-day (CVE-2023-38831) in the compromised system.
📝 Examine the memory dump and find some evidence
🙌 Hands-on lab