Autopsy - Autopsy 4.22.0: BitLocker Support, Cyber Triage Sidecar, Library Updates
Autopsy 4.22.0 includes BitLocker support, ability to run alongside Cyber Triage, and updates to lower-level libraries.
New Autopsy release is out! π
It's been a minute, but it's out. Notable features are BitLocker support and it can run side-by-side with Cyber Triage. Plus, a bunch of library updates.
Now Cyber Triage and Autopsy can be used on the same case at the same time!
www.autopsy.com/autopsy-4-22...
11.03.2025 20:36
π 19
π 10
π¬ 0
π 2
Elon Muskβs claim the X DDoS is from βIP addresses originating in the Ukraine areaβ is missing a key fact - it was actually IPs from worldwide, not just Ukraine.
Itβs a Mirai variant botnet, made of compromised cameras. They specifically targeted a Twitter ASN which had origin servers not behind CF
10.03.2025 22:30
π 439
π 166
π¬ 6
π 24
This is an important story.
The shitty part? I am Canadian, a court expert, I have offered my help to numerous Canadian orgs, lawyers and the Innocence Project.
Yet? I am only on dockets in Kansas, Oklahoma, and California through their indigent defense systems or NPOs.
Why? Wanna guess?
28.02.2025 11:51
π 2
π 1
π¬ 2
π 0
Kash Patel Took $25,000 From Russia-Linked Firm to Appear on an Anti-FBI TV Series
The documentary was produced by a filmmaker tied to Russian propaganda efforts.
SCOOP: Kash Patel took $25,000 from a production company with ties to Russia propaganda activity to appear in an anti-FBI docuseries. He did not respond to questions about this.
www.motherjones.com/politics/202...
07.02.2025 21:36
π 30205
π 13611
π¬ 1599
π 1038
From last month if you missed it - a gooder from @kennedycatherine.bsky.social
03.02.2025 20:21
π 5
π 1
π¬ 0
π 0
#DFIR π of the day: Our knowledge base is built on sharing - community contribution is critical.
With ever-evolving tech, no examiner knows all - we constantly learn new things. Shared knowledge is required- blog, script, peer review, etc - Please share! You have something to contribute!
13.12.2024 20:31
π 10
π 1
π¬ 1
π 1
A Reflection on Continual Growth in DFIR: An InvestigativeΒ Mindset
Derek reflects on continuous improvement of the investigative mindset.
I wrote a blog post reflecting on what I read from Brett Shavers' book, Placing the Suspect Behind the Keyboard: DFIR Investigative Mindset.
02.12.2024 12:38
π 14
π 6
π¬ 0
π 0
S2: DFIRmas Podcast: Alexis Brignoni
Instagram: @4n6_abrignoniYouTube: Alexis BrignoniBlueSky: @abrignoni.comPodcast: Digital Forensics Now (DFN)Resources: https://dfir.pubpub.orgThe Importance...
πArcPoint Forensics DFIRmas Podcast Season 2 Episode 1 is out!
βοΈTopic: Validation
π
Guest: Me!
βοΈSubscribe to the channel for more interviews.
πCheck it out at the link below:
https://buff.ly/4g4U6sk
#DFIR #DigitalForensics #MobileForensics
09.12.2024 18:16
π 7
π 5
π¬ 0
π 0
SentinelLab observed threat actor targeting service providers in Southern Europe abusing Visual Studio Code tunnels to maintain persistent remote access to compromised systems. www.bleepingcomputer.com/news/securit... KQL to detect such abuse.
10.12.2024 23:50
π 1
π 1
π¬ 0
π 0
#DFIR π of the day: Training should educate examiners on going beyond tool results.
Hereβs why:
1) Validate tool findings - particularly βsmoking gunβ.
2) Determine data meaning of results: how/why
3) Explain analysis results
4) Find unsupported artifacts
5) Adapt to change of supported artifacts
10.12.2024 11:46
π 10
π 3
π¬ 3
π 0
π¨ New file structure might contain email related data in BFU extractions!!! Also spotlight related data.
π¨ An iLEAPP artifact is available.
π Thanks to John Hyla for the research & parser.
π Check the post here: https://buff.ly/41Cv3Zp
#MobileForensics
04.12.2024 23:37
π 7
π 1
π¬ 0
π 1
From moi
04.12.2024 17:28
π 8
π 4
π¬ 1
π 0
Detecting AiTM Phishing and other ATO Attacks
Detecting AiTM Phishing and other Account Takeover Attacks
Detecting AiTM Phishing and other ATO Attacks
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering #Kusto #KQL #MicrosoftSentinel
23.11.2024 17:38
π 13
π 3
π¬ 0
π 0
You are threat hunting? You use KQL? Then read this post and follow @attackthesoc.com
20.11.2024 22:08
π 6
π 3
π¬ 1
π 0
WebScout
Online tool to collect domain/IP information:
- list of emails of domain (a very long list is given out upon free request)
- general domain info
- subdomains
- certificates
- similar domains
Partly free.
16.11.2024 07:30
π 22
π 3
π¬ 4
π 0
The SANS OSINT Summit listing for Justin Seitz and Chris Atha's presentation named: Kangaroo Court & The Evidence Carnival: How OSINT Can Save the Digital Forensics Plague. The registration URL is https://www.sans.org/cyber-security-training-events/sans-osint-summit-2025/#agenda
Hey hey #OSINT family! It will have been 5 years since we all gathered in Alexandria, Virginia - we get to do it again!
www.sans.org/cyber-securi...
16.11.2024 13:00
π 18
π 6
π¬ 3
π 0