A Systematic Approach to Understanding MACB Timestamps on Unixlike Systems

Bruce Nikkel: Okay, thanks everyone. I hope you enjoyed the break. Welcome to the first session: session one, with the theme of file system forensics. We have two interesting papers in this session. The first one is a systematic … Read mor… Continue reading A Systematic Approach to Understanding MACB Timestamps on Unixlike Systems

A Systematic Approach to Understanding MACB Timestamps on Unixlike Systems

Bruce Nikkel: Okay, thanks everyone. I hope you enjoyed the break. Welcome to the first session: session one, with the theme of file system forensics. We have two interesting papers in this session. The first one is a systematic … Read mor… Continue reading A Systematic Approach to Understanding MACB Timestamps on Unixlike Systems

Enterprise Forensics: Traditions vs Reality in Modern DFIR

Hans: So our keynote for today. Actually, I ran into Emre (online, of course) Tinaztepe from Binalyze in December. It was an interesting online meeting. I had to understand their technology.

And I’m sure Emre’s going to tell us ab… Continue reading Enterprise Forensics: Traditions vs Reality in Modern DFIR

Global Incident Response: DFRWS-EU Keynote, 2022

Chris Hargreaves: Without further ado, we can start the formal program and I’ll hand over to Serge Droz – I did my best there – for the first keynote of the week. Thank you.

Serge: So, this technology … Read more The p… Continue reading Global Incident Response: DFRWS-EU Keynote, 2022

Register for Webinar: Uncovering Windows Registry Data and the Latest Mac Artifacts

As the need for computer forensics grows so does the ability for investigators to stay up to date on all the operating systems. 1 in 3 U.S. employees use their own computer to enable remote work, creating more data in … Read more The post Regist… Continue reading Register for Webinar: Uncovering Windows Registry Data and the Latest Mac Artifacts