Main Takeaways Useful Note-taking and reporting requires explicit planning and goals. Organizing information is just as important as the content. Tips have been collected into the DFIR Notetaking Cheatsheet on Github. Introduction Since I've been working in DFIR full-time, I've been on a mission. I want to answer a question, a key question, I'm sure … Continue reading DFIR Note-Taking and Report Guide
writing
Presenting the ADAPT framework: Investigation and Analysis without Paralysis
Purpose: A way for technical investigators to systematically organize their thoughts for effective analysis while maintaining perfect notes that can easily be transitioned into a report or debrief. Audience: Anyone performing technical investigations (i.e. incident response, responding to cybersecurity alerts, identifying compromise). Additional Note: Keep in mind I am heavily biased towards incident response (IR) … Continue reading Presenting the ADAPT framework: Investigation and Analysis without Paralysis
Get Good at Documentation
PLAN IT Photo by Bich Tran on Pexels.com Figure out what you need to do Firstly, the idea of documenting something is far easier when you are actively trying something. Don’t wait until the task is finished, since you will forget a lot of what you've done. Another great way to start is to test … Continue reading Get Good at Documentation