Ryan Benson's Avatar

Ryan Benson

@hindsig.ht

144
Followers
336
Following
12
Posts
12.11.2024
Joined
Posts Following

Latest posts by Ryan Benson @hindsig.ht

Video thumbnail

Have a big number (or hex value) you found and think might be a timestamp? Drop it in `unfurl` in the terminal and see what comes out!

(add -d or --detailed if you want the type of timestamp, or run without it if you just want the value)

#DFIR #BF4SA #Unfurl 🌿

10.02.2026 15:15 👍 2 🔁 1 💬 0 📌 0
Preview
Hindsight v2026.01 Released! Hindsight v2026.01 brings new features, including parsing Sync Data, an updated terminal interface, improved output formats, and dozens of fixes and enhancements.

There's a new Hindsight release! v2026.01 brings new features, including:
🔄 Parsing Sync Data
⌨️ Updated terminal interface
📂 Improved output formats
⚙️ Many fixes and enhancements

Read more at dfir.blog/hindsight-v2... or download the new version from GitHub: github.com/obsidianfore...

05.02.2026 17:36 👍 1 🔁 0 💬 0 📌 0
Post image

A new Unfurl release (unfurl.link) is here! v2025.08 has:

🆔 Parsing more from TikTok IDs (millisecond timestamp, entity type (user account, device, live session, or video), and more). Thanks to Benjamin Steel for the paper arxiv.org/abs/2504.13279

📝 Full release notes: github.com/obsidianfore...

11.08.2025 15:16 👍 8 🔁 4 💬 0 📌 0
Post image

This story is absolutely insane. And we don't usually get a front-row seat to insider threat investigations

Spy got tricked by a honeypot and implicated the most senior leaders at the victim's biggest competitors.

I go through it all here: youtu.be/tDG1WfbSZFo

17.03.2025 19:31 👍 10 🔁 4 💬 1 📌 3
Preview
Unfurl 2025.03 Unfurl v2025.03 adds new features, including parsing Google Search's UDM parameter, support for Mastodon forks (like Truth Social), and a utility parser to "clean up" inputs.

Unfurl v2025.03 is live and adds new features, including:

🔎 Parsing #Google Search's UDM parameter
🐘 Recognizing #Mastodon usernames and parsing forks (like truthsocial[.]com and gab[.]com)
🧹 Utility parser to "clean up" inputs

Try it: unfurl.link
Blog post: dfir.blog/unfurl-parse...

#DFIR #OSINT

13.03.2025 14:12 👍 2 🔁 0 💬 0 📌 0
Preview
Hindsight v2025.03 Released! Hindsight v2025.03 focuses on Extensions - parsing more activity and state records, highlighting Extension permissions, and making it easier to examine Manifests.

There's a new Hindsight release!

Hindsight v2025.03 focuses on Extensions - parsing more activity and state records, highlighting Extension permissions, and making it easier to examine Manifests.

🌐 Blog: dfir.blog/hindsight-pa...
🛠️ Tool download: hindsig.ht/release

#DFIR #Chrome #Extensions

11.03.2025 17:08 👍 8 🔁 4 💬 0 📌 0
Preview
unfurl Extract and Visualized Data from URLs

A new Unfurl release is here! v2025.02 adds:

🌐 Parsing encoded/obfuscated IP addresses
🦋 Resolving #Bluesky handles to their identifiers (DIDs) and looking up their creation timestamps
🐛 Bug fixes & better bulk parsing

Blog: dfir.blog/unfurl-parse...
Code: github.com/obsidianfore...

#DFIR #OSINT

19.02.2025 14:46 👍 8 🔁 7 💬 0 📌 0
Preview
unfurl Extract and Visualized Data from URLs

Unfurl can do this as well - the timestamp is embedded in the ID in the URL, so no login/etc needed, just the URL.

Example: dfir.blog/unfurl/?url=...

18.02.2025 22:20 👍 2 🔁 0 💬 1 📌 0
Preview
unfurl Extract and Visualized Data from URLs

Want to break down what is in a URL? Try Unfurl from Ryan Benson and gain further insights! dfir.blog/unfurl/
#DFIR

10.02.2025 11:42 👍 16 🔁 8 💬 0 📌 0
A Google Search Results Page (SERP) from the Netflix movie Carry-On

A Google Search Results Page (SERP) from the Netflix movie Carry-On

Over the winter holiday, I was watching Netflix's Carry-On and got a bit nerd-sniped by a real Google Search URL on-screen... and then proceeded to "authenticate" it.

dfir.blog/authenticati...

#DFIR #OSINT #Unfurl #Netflix

13.01.2025 17:30 👍 3 🔁 0 💬 0 📌 0

The Raiders can’t even be good at being bad…

23.12.2024 00:52 👍 0 🔁 0 💬 0 📌 0
Preview
unfurl Extract and Visualized Data from URLs

Unless they fundamentally change how tweets work (which seems unlikely), the timestamp can be extracted from the URL (no API needed).

Taking your tweet about the timestamps as an example, a tool like Unfurl can show it was sent at 2024-12-04 21:13:20.296 UTC.

Example: dfir.blog/unfurl/?url=...

05.12.2024 05:11 👍 3 🔁 0 💬 0 📌 0

CTFs present challenges that you likely haven’t seen before. I’ve taken away new skills from every CTF I’ve ever participated in.

23.11.2024 13:23 👍 2 🔁 1 💬 1 📌 0
YouTube Share your videos with friends, family, and the world

A new episode is live now of @dfnpodcast.bsky.social www.youtube.com/live/4H9TLL8...

21.11.2024 23:05 👍 1 🔁 2 💬 0 📌 0
Post image

Since I'm trying out #Bluesky, I figured I should add in support for it in Unfurl!

The v2024.11.20 release has some minor updates, but the biggest feature is the ability to parse a timestamp from Bluesky post IDs (or atproto TIDs).

Example: dfir.blog/unfurl/?url=...

Give it a try at unfurl.link!

21.11.2024 04:19 👍 26 🔁 12 💬 0 📌 2

New Timesketch release is out. Two highlights:

- Unfurl [1] integration, get information from URLs directly in your timeline.

- DFIQ [2] support with context aware SearchHistory.

Changelog: timesketch.org/changelog/#v...

[1] dfiq.org
[2] dfir.blog/introducing-...

26.10.2023 19:15 👍 0 🔁 2 💬 0 📌 0

Oh hi everyone! I've missed what #DFIR Twitter used to be - here's to hoping we can get something similar going here!

14.11.2024 15:18 👍 11 🔁 1 💬 2 📌 1