Sinopsis
Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.
Episodios
-
-
-
-
-
-
-
-
-
-
-
DFSP # 485 BAM! Packing Punch
27/05/2025 Duración: 10minThis week, I delve into the Windows BAM artifact, unraveling its forensic significance and exploring how it can unlock critical insights in digital investigations.
-
DFSP # 483 Cooking up Forensics with Chef
20/05/2025 Duración: 14minIn this week’s episode, I delve into strategies for integrating CHEF into your security investigations, unlocking new avenues for proactive defense and effective incident response.
-
DFSP # 482 Unlocking Clues from Bash and Hidden Keys
13/05/2025 Duración: 20minThis week, we’re pulling back the curtain on SSH from a digital forensics perspective.
-
DFSP # 481 Triage outside the Core
06/05/2025 Duración: 20minIn this week’s episode, I dive into rapid triage techniques for non-core Windows executables to uncover signs of malicious activity.
-
DFSP # 480 Hidden risks of nested groups
29/04/2025 Duración: 13minThis week, I’m talking about nested groups in Windows Active Directory and the security risks they pose. Active Directory allows administrators to attach one group to another—often called nesting. While nesting can simplify account administration and permission management, it can also create real opportunities for attackers if...
-
DFSP # 479 Scan, Score, Secure
22/04/2025 Duración: 15minOne of the essential skill sets for a DFIR analyst is the ability to understand the impact of vulnerabilities quickly. In many IR scenarios, you may find a newly discovered vulnerability or receive a scan that flags multiple potential weaknesses. To stay efficient, you must...
-
DFSP # 478 SRUM
15/04/2025 Duración: 15minThis week, we’re exploring the System Resource Usage Monitor (SRUM) – a powerful source of forensic data within Windows operating systems. First introduced...
-
DFSP # 477 SSH Triage
08/04/2025 Duración: 18minIn this episode, our focus is on understanding how attackers achieve lateral movement and persistence through Secure Shell (SSH)—and more importantly, how to spot the forensic traces...
-
DFSP # 476 Service Host
01/04/2025 Duración: 22minIn this episode, we’ll take a focused look at how to triage one of the most commonly targeted Windows processes: svchost.exe. While the methods in this series generally apply to all Windows core processes, svchost is an especially important case because attackers...
-
DFSP # 475 - Set the tone
25/03/2025 Duración: 20minRansomware attacks move quickly, making your initial response crucial in minimizing impact. This episode outlines critical first steps, from isolating infected machines to gathering key information and initiating containment. Whether you’re a SOC analyst, incident responder, or the first to notice an attack, this framework is designed to help you regain control. Follow these guidelines to effectively mitigate the damage from the very start.