Kat Hedley's Avatar

Kat Hedley

@4enzikat0r

DFIR, SANS author & certified instructor GSP & all the FOR GIACs khyrenz.com github.com/khyrenz

170
Followers
132
Following
17
Posts
17.11.2024
Joined
Posts Following

Latest posts by Kat Hedley @4enzikat0r

Post image

My goal for the holiday period was to finish @nintendouki.bsky.social #MarioVsDonkeyKong

Goal accomplished on New Years Day 😎

06.01.2025 21:28 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Enjoy Apple TV+ for free the first weekend of 2025 Apple TV+ is ringing in the New Year by offering an all-access pass to customers all around the world.

Best news ever!

Free #AppleTV this weekend

That’s my weekend sorted πŸ‘

www.apple.com/tv-pr/news/2...

04.01.2025 11:38 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Kudos to you for that; I took one look outside & went β€˜nope!’

01.01.2025 12:32 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Me: i’m going to start the year as I mean to go on, with a 2km #DFIRFit run on the treadmill πŸ’ͺ

My treadmill 2mins into the warm up…

Anyone know how to fix a dead @nordictrack.bsky.social S20 (UK)? πŸ€¦β€β™€οΈ

It’s not the fuse & I yes I already tried turning it off & on again!

01.01.2025 11:47 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
GitHub - khyrenz/parseusbs: Parses USB connection artifacts from offline Registry hives Parses USB connection artifacts from offline Registry hives - khyrenz/parseusbs

Version 1.6 of #DFIR #parseUSBs is out…

I was interested to see if I could fill in any gaps in assigned drive letters for previous USB connections using LNK data, so this version does exactly that (matching on VSN)

As always, feedback very welcome

github.com/khyrenz/pars...

11.12.2024 10:54 πŸ‘ 8 πŸ” 4 πŸ’¬ 1 πŸ“Œ 1

I felt that pain!

10.12.2024 09:36 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

I got as far as I could on the badge challenges on day1 of @SANSInstitute #CyberThreat24 … tripped up by a micro USB cable πŸ€¦β€β™€οΈπŸ€£

10.12.2024 09:11 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

It’s all kicking off in style at @SANSInstitute #CyberThreat

09.12.2024 09:52 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Congratulations & very well done; you aced the capstone πŸ’ͺ

04.12.2024 18:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Gritter tracker | Traffic Scotland Traffic Scotland gives you the real-time information you need about Scotland’s trunk road network

Very important development… the @trafficscotland gritter tracker now has a beta 3D map! Best names ever, every year

Go Icesweeper Willie, go!

Though I still think the best name so far is… Itsy Bitsy Teenie Weenie Yellow Anti-Slip Machiney

www.traffic.gov.scot/gritter-trac...

01.12.2024 10:23 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Code found online exploits LogoFAIL to install Bootkitty Linux backdoor Unearthed sample likely works against Linux devices from Acer, HP, Fujitsu, and Lenovo.
29.11.2024 21:37 πŸ‘ 73 πŸ” 20 πŸ’¬ 2 πŸ“Œ 3

Possibly yes, but I ran out of characters in the post… right now I have:

X: 2.7k
Mastodon: 231
Bluesky: 105
LinkedIn: 1.4k connections

I think that makes the Bluesky figures more interesting

27.11.2024 08:31 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

How do #InfoSec social media apps compare? Stats on my last #DFIR post after 24hrs…

X:
- 5 reposts
- 26 likes
- 2 new followers

Mastodon:
- 2 boosts
- 3 favourites
- 2 followers

Bluesky:
- 6 reposts
- 16 likes
- 7 followers

LinkedIn:
- 13 reposts
- 79 reactions
- 7 followers
- 25 conn requests

26.11.2024 22:00 πŸ‘ 13 πŸ” 0 πŸ’¬ 4 πŸ“Œ 0
Preview
GitHub - khyrenz/parseusbs: Parses USB connection artifacts from offline Registry hives Parses USB connection artifacts from offline Registry hives - khyrenz/parseusbs

🚨 #DFIR Tool update 🚨

I’ve updated parseUSBs (again!):
- Now supports mounted #KAPE images
- Improved deduplication of events within secs of each other
- Added extraction of partition style (MBR/GPT) & Filesystem
- Parses alternate S/Ns
- Parses WPDBUSENUM key

github.com/khyrenz/pars...

25.11.2024 22:19 πŸ‘ 28 πŸ” 10 πŸ’¬ 1 πŸ“Œ 0

There’s wifi you have to pay for?!

20.11.2024 07:01 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Is Bluesky Billionaire-Proof? Questions and answers about the new social media network Bluesky that you don’t need an invite to see. First, Jack Dorsey is not an owner.

Who owns Bluesky? What’s the role of former Twitter CEO Jack Dorsey? What’s Bluesky’s business model? And what prevents another Elon Musk from buying and destroying it?Β 

@micahflee.com answers your Bluesky questions.

01.06.2023 19:58 πŸ‘ 17 πŸ” 8 πŸ’¬ 2 πŸ“Œ 0
Preview
Understanding the security impacts of iOS 18’s inactivity reboot - Magnet Forensics Learn about iOS 18's inactivity reboot feature, its security impact, and implications for forensic investigations.

Ha! You of all people doubt connectivity in the modern world 😜

It’s a great article. I also read @cScottVance’s blog on this last week: www.magnetforensics.com/blog/underst...

…& I think the key takeaway is still to acquire a device ASAP after seizure. Cool to see how the forced reboot is logged πŸ‘

19.11.2024 21:38 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Reverse Engineering iOS 18 Inactivity Reboot Wireless and firmware hacking, PhD life, Technology

Interesting and potentially problematic from a LE viewpoint - @tazwake.bsky.social did you know about this?

naehrdine.blogspot.com/2024/11/reve...

19.11.2024 16:15 πŸ‘ 3 πŸ” 3 πŸ’¬ 3 πŸ“Œ 0
Post image
18.11.2024 17:53 πŸ‘ 83 πŸ” 11 πŸ’¬ 1 πŸ“Œ 1
GitHub - khyrenz/parseusbs: Parses USB connection artifacts from offline Registry hives Parses USB connection artifacts from offline Registry hives - khyrenz/parseusbs

My #parseusbs #DFIR tool got another small update this week to fix an issue on Linux - now tested on Windows cmd/powershell, WSL (the best shell!), and Ubuntu

Parse USB connection artifacts from a Windows volume, including registry & event log data (or offline hives)

github.com/khyrenz/pars...

18.11.2024 12:57 πŸ‘ 11 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Post image

Join me in Lisbon next week for lots of @sansforensics #FOR500 Windows forensics fun. I’ve discovered some fun new things about USB connection artifacts that I’ll be sharing first at this event, so you’ll want to be around for all that!

Sign up here: sans.org/u/1yrB

18.11.2024 12:12 πŸ‘ 7 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - stuhli/awesome-event-ids: Collection of Event ID ressources useful for Digital Forensics and Incident Response Collection of Event ID ressources useful for Digital Forensics and Incident Response - stuhli/awesome-event-ids

This git is full of resources for event logs/auditing. Covers everything from tool configs to audit cheatsheets to event attack chains and data samples. In #DFIR visibility is key. This is a solid resource for those responding to an incident or trying to prevent one. #grc

github.com/stuhli/aweso...

17.11.2024 22:27 πŸ‘ 11 πŸ” 6 πŸ’¬ 0 πŸ“Œ 0