LNK Files, Again

 I ran across SharpWebServer via Twitter recently…the first line of the readme.md file states, “A Red Team oriented simple HTTP & WebDAV server written in C# with functionality to capture Net-NTLM hashes.” I thought this was fascinating beca… Continue reading LNK Files, Again

Posted in Uncategorized

On #DFIR Analysis

I wanted to take the opportunity to discuss DFIR analysis; when discussing #DFIR analysis, we have to ask the question, “what _is_ “analysis”?”In most cases, what we call analysis is really just parsing some data source (or sources) and either viewing … Continue reading On #DFIR Analysis

Posted in Uncategorized