
DFSP # 483 Cooking up Forensics with Chef
In this week's episode, I delve into strategies for integrating CHEF into your security investigations, unlocking new avenues for proactive defense and effective incident response.
20 Mai 202514min

DFSP # 482 Unlocking Clues from Bash and Hidden Keys
This week, we're pulling back the curtain on SSH from a digital forensics perspective.
13 Mai 202520min

DFSP # 481 Triage outside the Core
In this week's episode, I dive into rapid triage techniques for non-core Windows executables to uncover signs of malicious activity.
6 Mai 202520min

DFSP # 480 Hidden risks of nested groups
This week, I'm talking about nested groups in Windows Active Directory and the security risks they pose. Active Directory allows administrators to attach one group to another—often called nesting. Whi...
29 Apr 202513min

DFSP # 479 Scan, Score, Secure
One of the essential skill sets for a DFIR analyst is the ability to understand the impact of vulnerabilities quickly. In many IR scenarios, you may find a newly discovered vulnerability or receive a ...
22 Apr 202515min

DFSP # 478 SRUM
This week, we're exploring the System Resource Usage Monitor (SRUM) – a powerful source of forensic data within Windows operating systems. First introduced...
15 Apr 202515min

DFSP # 477 SSH Triage
In this episode, our focus is on understanding how attackers achieve lateral movement and persistence through Secure Shell (SSH)—and more importantly, how to spot the forensic traces...
8 Apr 202518min

DFSP # 476 Service Host
In this episode, we'll take a focused look at how to triage one of the most commonly targeted Windows processes: svchost.exe. While the methods in this series generally apply to all Windows core proce...
1 Apr 202522min


















