As someone who works, lives and breathes in the world of Digital Forensics and Incident Response (DFIR), there is one skill that I think is often overlooked. Triage. It is a step we often forget since we want to jump straight into forensic analysis. However, skipping triage often means you have no idea where to … Continue reading Chaos to Clarity: Why Triage is Not Optional
Where does macOS fit into DFIR?
Isn’t Windows DFIR enough? If you work in Digital Forensics and Incident Response (DFIR) or even just read about it on the side, you know Windows DOMINATES the field. Windows is still king when it comes to organizational/business use. Therefore, more Windows systems are being targeted and hacked by these pesky adversaries. So, don’t get … Continue reading Where does macOS fit into DFIR?
Get Good at Documentation
PLAN IT Photo by Bich Tran on Pexels.com Figure out what you need to do Firstly, the idea of documenting something is far easier when you are actively trying something. Don’t wait until the task is finished, since you will forget a lot of what you've done. Another great way to start is to test … Continue reading Get Good at Documentation
What’s in my DFIR toolbox? | 2023
You know what they say sharing is caring. So, I recently got a new system and had to get my usual tools back on the system. I figured this would be a great time to share with you all the tools I default to and why I use them. If you work in DFIR, I … Continue reading What’s in my DFIR toolbox? | 2023
Investigation Framework | Part 7 – Reporting
Investigation Framework Incident Scoping Evidence Collection Analysis Correlation Timeline Analysis Intelligence Correlation Reporting Reporting We finally made it, we are at the bitter end. Speaking of bitter, we are going to talk about the most dreaded part of an investigation, the report. It could be argued that reporting is perhaps the most important part of … Continue reading Investigation Framework | Part 7 – Reporting
Investigation Framework | Part 6 – Intelligence Correlation
Investigation Framework Incident Scoping Evidence Collection Analysis Correlation Timeline Analysis Intelligence Correlation Reporting Intelligence Correlation There’s one last piece of “analysis” left to do with your evidence. It’s time to take what you know and look for any similarities to know intelligence. The best way to summarize this section is “Find out if anyone else … Continue reading Investigation Framework | Part 6 – Intelligence Correlation
Investigation Framework | Part 5 – Timeline Analysis
Investigation Framework Incident Scoping Evidence Collection Analysis Correlation Timeline Analysis Intelligence Correlation Reporting Timeline Analysis We’re past the halfway point! Even if you think you covered everything with your analysis and correlation, sometimes you need to put things to see the bigger picture. Here we will be covering creating potentially the most important aspect of … Continue reading Investigation Framework | Part 5 – Timeline Analysis
Investigation Framework | Part 4 – Correlation
Investigation Framework Incident Scoping Evidence Collection Analysis Correlation Timeline Analysis Intelligence Correlation Reporting Correlation Welcome back, hopefully you’ve had a chance to take a break and refill your caffeine of choice. Findings only provide half the answer when dealing with investigations. As an analyst, your job is not only to discover findings but to also … Continue reading Investigation Framework | Part 4 – Correlation
Investigation Framework | Part 3 – Analysis
Investigation Framework Incident Scoping Evidence Collection Analysis Correlation Timeline Analysis Intelligence Correlation Reporting Analysis Now we’re in the good stuff! We got an incident, we’ve scoped it perfectly and collected evidence to start our analysis. If you know the theme now, say it loud “DON’T JUST JUMP IN”. Part of analysis is also organizing your … Continue reading Investigation Framework | Part 3 – Analysis
Investigation Framework | Part 2 – Evidence Collection
Investigation Framework Incident Scoping Evidence Collection Analysis Correlation Timeline Analysis Intelligence Correlation Reporting Evidence Collection Firstly, we need to understand the goal. The goal is simple, we need to preserve and prepare evidence for analysis. DISCLAIMER: In some cases, you may need to preserve evidence for a legal investigation. I will go on the record … Continue reading Investigation Framework | Part 2 – Evidence Collection