Digital triage can do more than save you time. It may save a life. Dec 13, 2022

 Scenario (yes, this really happened):

Parents reported their daughter missing. They gave the assigned detective a laptop that their daughter was using prior to being lured from home.

The assigned detective conducted his own “triage” of the laptop by turning the laptop on poking...

Continue Reading...
DFIR Training Survey with a Book Giveaway as a Bonus Dec 06, 2022

Short version:

  • Complete a DFIR tools & training survey .
  • Get one (or more chances if you share the survey) to win a free book.
  • Winner will be chosen on January 6, 2023.

Go to the survey here:  https://survey.zohopublic.com/zs/oOCzKw

Then enter the giveaway here: ...

Continue Reading...
Attribution or bust. Nov 29, 2022

To be the best at this thing we call “DFIR”, you need to be singularly focused on the primary objectives of a digital forensic examination.  These (broadly) are:

  • locate EVIDENCE of the crime/incident,
  • identify the SUSPECT(s),
  • convey findings in COURT.

Locating digital EVIDENCE...

Continue Reading...
DFIR Book Challenge Sep 26, 2022

The winner of this month's DFIR Book Challenge was Madi (https://twitter.com/brum_below) and a signed copy of the X-Ways Forensics Practitioner's Guide/2E is being shipped.

I have another book in hand for the next giveaway.  But I have to connect with more authors for more books! ...

Continue Reading...
 
Rule #1 to Get into Cybersecurity Sep 22, 2022

Start asking the right questions to get the answers that you need. In any forensic analysis, a dive into data needs a “why” before even looking at the bits and bytes. Without a “why”, you will never get the “who-what-where-when-how”.  You will get...

Continue Reading...
It is not the tool, but the examiner that does the forensics. Sep 20, 2022

 I made a meme.

I tweeted a simple meme and it created good discussion in which I gained more than expected by reading the perspectives of so many. The civility in the thread was awesome, which I attribute to cool people in this cool DFIR field.

 

Continue Reading...
The DFIR world is your oyster because... Sep 01, 2022

Every job skill requires some level of training. Some jobs require education in the form of degrees or certifications. None of these guarantee competence in any skill. It also doesn’t indicate that learning occurred. I look at training or education documentation as proof that time was spent...

Continue Reading...
Networking is way more than connecting computers together Aug 12, 2022

It is time for you to talk to another DFIR human in real life

One of the very few things that I will miss from the past two years is the wealth of online training and videoconferences that were available. It was such an amazing time of resources where every vendor, every expert, and every...

Continue Reading...
Drowning in an ocean of DFIR resources Jul 31, 2022

It was much easier to learn digital forensics decades ago. This is not because systems were less complex or that datasets were smaller. It was easier because there just wasn’t that much to learn. On top of that, there were few resources to draw upon. No college degree programs, only a...

Continue Reading...
If you come from less, you must do more to make it in DFIR Jul 16, 2022

One certainty is that life certainly is not fair. If you want the solution to this problem, skip to the last paragraph, but you’ll miss a lot of good points.

Life is unfair!

A positive reaction to this life fact is to accept it and move forward. A negative reaction would be to nothing but...

Continue Reading...
 
June 14, ,2022 Updates! Jun 14, 2022

Some updates!

Do you want to be a book contributor?

X-Ways Guide course updates!

WinFE!

And more!

PS!!  Don't forget to leave an Amazon review if you liked the XWF Guide :)  

https://amzn.to/3QlATWG

Continue Reading...
 
Surviving and Thriving in DFIR Feb 05, 2022

Magnet Summit presentation

Continue Reading...
1 2