Masstin triage detection: KAPE, Velociraptor, Cortex XDR — and a per-source breakdown that finally makes sense
The problem with leaf-directory grouping
Read more →root@wia:~$ whoami
root@wia:~$ cat /etc/motd
Digital Forensics & Incident Response
We dissect digital evidence. We trace the untraceable.
0x0000: 57 65 20 49 6e 76 65 73 74 69 67 61 74 65 |We.Investigate|
0x000e: 41 6e 79 74 68 69 6e 67 |Anything........|
root@wia:~$ _
The problem with leaf-directory grouping
Read more →The problem with vendor-specific parsing
Read more →This is Part 9 of the AD DFIR Lab series. Part 8 gave us a noisy-ad-current snapshot packed with 2 years of realistic narrative. Part 9 pulls that snapshot o...
Read more →This is Part 8 of the AD DFIR Lab series. We turn a sterile clean-ad snapshot into noisy-ad-2years — a dataset that looks like a real company has been using ...
Read more →This is an interlude in the AD DFIR Lab series. A short operational post about keeping the lab running for years rather than months.
Read more →