Shafik Punja's Avatar

Shafik Punja

@qubytelogic

DFIR worker bee/research monkey. Views are my own.🐧 And do not necessarily represent strategies, views or opinions of any employers: past, present or future.

44
Followers
95
Following
2
Posts
13.11.2024
Joined
Posts Following

Latest posts by Shafik Punja @qubytelogic

Preview
Autopsy - Autopsy 4.22.0: BitLocker Support, Cyber Triage Sidecar, Library Updates Autopsy 4.22.0 includes BitLocker support, ability to run alongside Cyber Triage, and updates to lower-level libraries.

New Autopsy release is out! πŸŽ‰

It's been a minute, but it's out. Notable features are BitLocker support and it can run side-by-side with Cyber Triage. Plus, a bunch of library updates.

Now Cyber Triage and Autopsy can be used on the same case at the same time!

www.autopsy.com/autopsy-4-22...

11.03.2025 20:36 πŸ‘ 19 πŸ” 10 πŸ’¬ 0 πŸ“Œ 2

Elon Musk’s claim the X DDoS is from β€œIP addresses originating in the Ukraine area” is missing a key fact - it was actually IPs from worldwide, not just Ukraine.

It’s a Mirai variant botnet, made of compromised cameras. They specifically targeted a Twitter ASN which had origin servers not behind CF

10.03.2025 22:30 πŸ‘ 439 πŸ” 166 πŸ’¬ 6 πŸ“Œ 24
Post image Post image Post image Post image

New Blog! Investigating Anonymous VPS services used by Ransomware Gangs

h/t to @drb_ra for lending me some of their C2 data! Made my life a lot easier 🫑

πŸ”— blog.bushidotoken.net/2025/02/inve...

Podcast version: www.youtube.com/watch?v=xX25...

15.02.2025 17:39 πŸ‘ 12 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0

This is an important story.

The shitty part? I am Canadian, a court expert, I have offered my help to numerous Canadian orgs, lawyers and the Innocence Project.

Yet? I am only on dockets in Kansas, Oklahoma, and California through their indigent defense systems or NPOs.

Why? Wanna guess?

28.02.2025 11:51 πŸ‘ 2 πŸ” 1 πŸ’¬ 2 πŸ“Œ 0
Preview
Kash Patel Took $25,000 From Russia-Linked Firm to Appear on an Anti-FBI TV Series The documentary was produced by a filmmaker tied to Russian propaganda efforts.

SCOOP: Kash Patel took $25,000 from a production company with ties to Russia propaganda activity to appear in an anti-FBI docuseries. He did not respond to questions about this.

www.motherjones.com/politics/202...

07.02.2025 21:36 πŸ‘ 30205 πŸ” 13611 πŸ’¬ 1599 πŸ“Œ 1038

From last month if you missed it - a gooder from @kennedycatherine.bsky.social

03.02.2025 20:21 πŸ‘ 5 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
The Human Element of DF/IR (YOU!) The clock is racing. A global breach is unraveling on one side of the room; millions siphoned in real-time, systems crashing, and reputations crumbling by the second. On the other, the unthinkable: a ...

'Tools don’t do forensics – you do. A tool should amplify your skill, not replace it.' - Brett Shavers brettshavers.com/brett-s-blog...

31.01.2025 21:53 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
The Human Element of DF/IR (YOU!) The clock is racing. A global breach is unraveling on one side of the room; millions siphoned in real-time, systems crashing, and reputations crumbling by the second. On the other, the unthinkable: a ...

'Technology will evolve. But your ability to think critically, prioritize, and follow evidence where it leads will always set you apart.' - Brett Shavers brettshavers.com/brett-s-blog...

31.01.2025 21:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Gideon's Garage An expert-curated wiki of digital evidence, junk science and public defense information.

substack.com/@justinseitz...

29.12.2024 18:19 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
This Fredericton man is using untested β€˜artificial intelligence’ to help convict people across the United States - Halifax Examiner By Tim Bousquet This item originally appeared as News #5 in Morning File, May 7, 2024 β€œLaw enforcement agencies and prosecutors from Colorado to New York have turned to a little-known artificial intel...

Woopsies!

www.halifaxexaminer.ca/this-frederi...

17.12.2024 16:31 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

#DFIR πŸ’­ of the day: Our knowledge base is built on sharing - community contribution is critical.

With ever-evolving tech, no examiner knows all - we constantly learn new things. Shared knowledge is required- blog, script, peer review, etc - Please share! You have something to contribute!

13.12.2024 20:31 πŸ‘ 10 πŸ” 1 πŸ’¬ 1 πŸ“Œ 1
Preview
A Reflection on Continual Growth in DFIR: An InvestigativeΒ Mindset Derek reflects on continuous improvement of the investigative mindset.

I wrote a blog post reflecting on what I read from Brett Shavers' book, Placing the Suspect Behind the Keyboard: DFIR Investigative Mindset.

02.12.2024 12:38 πŸ‘ 14 πŸ” 6 πŸ’¬ 0 πŸ“Œ 0
Preview
S2: DFIRmas Podcast: Alexis Brignoni Instagram: @4n6_abrignoniYouTube: Alexis BrignoniBlueSky: @abrignoni.comPodcast: Digital Forensics Now (DFN)Resources: https://dfir.pubpub.orgThe Importance...

πŸŽ„ArcPoint Forensics DFIRmas Podcast Season 2 Episode 1 is out!
❄️Topic: Validation
πŸŽ…Guest: Me!
β˜ƒοΈSubscribe to the channel for more interviews.
🌟Check it out at the link below:
https://buff.ly/4g4U6sk

#DFIR #DigitalForensics #MobileForensics

09.12.2024 18:16 πŸ‘ 7 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Post image

SentinelLab observed threat actor targeting service providers in Southern Europe abusing Visual Studio Code tunnels to maintain persistent remote access to compromised systems. www.bleepingcomputer.com/news/securit... KQL to detect such abuse.

10.12.2024 23:50 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

#DFIR πŸ’­ of the day: Training should educate examiners on going beyond tool results.

Here’s why:
1) Validate tool findings - particularly β€œsmoking gun”.
2) Determine data meaning of results: how/why
3) Explain analysis results
4) Find unsupported artifacts
5) Adapt to change of supported artifacts

10.12.2024 11:46 πŸ‘ 10 πŸ” 3 πŸ’¬ 3 πŸ“Œ 0
Post image

🚨 New file structure might contain email related data in BFU extractions!!! Also spotlight related data.
🚨 An iLEAPP artifact is available.
πŸ™ Thanks to John Hyla for the research & parser.
πŸ”— Check the post here: https://buff.ly/41Cv3Zp

#MobileForensics

04.12.2024 23:37 πŸ‘ 7 πŸ” 1 πŸ’¬ 0 πŸ“Œ 1

From moi

04.12.2024 17:28 πŸ‘ 8 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0
Preview
Detecting AiTM Phishing and other ATO Attacks Detecting AiTM Phishing and other Account Takeover Attacks

Detecting AiTM Phishing and other ATO Attacks

academy.bluraven.io/blog/detecti...

#ThreatHunting #DetectionEngineering #Kusto #KQL #MicrosoftSentinel

23.11.2024 17:38 πŸ‘ 13 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

You are threat hunting? You use KQL? Then read this post and follow @attackthesoc.com

20.11.2024 22:08 πŸ‘ 6 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Post image

WebScout
Online tool to collect domain/IP information:
- list of emails of domain (a very long list is given out upon free request)
- general domain info
- subdomains
- certificates
- similar domains
Partly free.

16.11.2024 07:30 πŸ‘ 22 πŸ” 3 πŸ’¬ 4 πŸ“Œ 0
The SANS OSINT Summit listing for Justin Seitz and Chris Atha's presentation named: Kangaroo Court & The Evidence Carnival: How OSINT Can Save the Digital Forensics Plague. The registration URL is https://www.sans.org/cyber-security-training-events/sans-osint-summit-2025/#agenda

The SANS OSINT Summit listing for Justin Seitz and Chris Atha's presentation named: Kangaroo Court & The Evidence Carnival: How OSINT Can Save the Digital Forensics Plague. The registration URL is https://www.sans.org/cyber-security-training-events/sans-osint-summit-2025/#agenda

Hey hey #OSINT family! It will have been 5 years since we all gathered in Alexandria, Virginia - we get to do it again!

www.sans.org/cyber-securi...

16.11.2024 13:00 πŸ‘ 18 πŸ” 6 πŸ’¬ 3 πŸ“Œ 0