Live Response Collection – Cedarpelta

Hello again readers and welcome back!! Today I would like to announce the public release of updates to the Live Response Collection (LRC), which is named “Cedarpelta”. This may come as a surprise to some as Bambiraptor was released over two years … Continue reading Live Response Collection – Cedarpelta

FileTSAR: Free digital forensic investigations toolkit for law enforcement

Purdue University cybersecurity experts have created FileTSAR, an all-in-one digital forensic investigations toolkit for law enforcement. About FileTSAR FileTSAR, which stands for Toolkit for Selective Analysis & Reconstruction of Files, combines … Continue reading FileTSAR: Free digital forensic investigations toolkit for law enforcement

Sly Guy Nabs Pi Spy

When one of [Christian Haschek’s] co-workers found this Raspberry Pi tucked into their network closet, he figured it was another employee’s experiment – you know how that goes. But, of course, they did the safe thing and unplugged it from the network right away. The ensuing investigation into what it was doing there is a tour de force in digital forensics and a profile of a bungling adversary.

A quick check of everyone with access to that area turned up nothing, so [Christian] shifted focus to the device itself. There were three components: a Raspberry Pi model B, a 16GB …read more

Continue reading Sly Guy Nabs Pi Spy

Veronica Schmitt, DFIRLABS – Paul’s Security Weekly #580

Veronica Schmitt is the Sr. Digital Forensic Scientist for DFIRLABS. Veronica explains what SRUM is in WIndows 10. She explains how SRUM can be a valuable tool in Digital Forensics. Full Show NotesFollow us on Twitter: https://www.twitter.com/securityw… Continue reading Veronica Schmitt, DFIRLABS – Paul’s Security Weekly #580

Incident Response Basics: Getting started with DFIR

The digital world has borrowed terminology and principals form the kinetic world for decades. We’ve all heard of an upcoming cyber war using cyber bullets spawned from the digital pearl harbor. We have gangs, as well as cyber-gangs, or criminals,… Continue reading Incident Response Basics: Getting started with DFIR

Data Source-level Focus in Large Cases

The 4.8.0 release of Autopsy is out and the major themes in the release are: Focus on data source-level review in large cases Keyword search accuracy improvements Tagging efficiencies Plus lots of other changes. This blog focuses on the data source-level changes that will make it easier for you to conduct investigations on a single […] Continue reading Data Source-level Focus in Large Cases

Live Response Collection Development Roadmap for 2018

Hello again readers and welcome back! It’s been a little while …OK, a long while… since I’ve made updates to the Live Response Collection. Rest assured for those of you who have used, and continue to use it, that I am still working on it, and tryin… Continue reading Live Response Collection Development Roadmap for 2018

Diffy: A triage tool for cloud-centric incident response

The Netflix Security Intelligence and Response Team (SIRT) has released Diffy, an open source triage tool that allows digital forensics and incident response teams to quickly pinpoint compromised hosts during a security incident on cloud architectures…. Continue reading Diffy: A triage tool for cloud-centric incident response