's Avatar

@beercow.bsky.social

"Distrust and caution are the parents of security." - Benjamin Franklin https://malwaremaloney.blogspot.com

407 Followers  |  186 Following  |  49 Posts  |  Joined: 06.11.2024  |  1.4029

Latest posts by beercow.bsky.social on Bluesky

Post image

Updated OneDrive Evolution. You can now compare two versions of OneDrive and see what has changed. #DFIR

malwaremaloney.blogspot.com/p/onedrive-e...

07.08.2025 03:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Release v2025.05.30 Β· Beercow/OneDriveExplorer Β· GitHub Change Log Fixed ODL bug fix FileUsageSynce bug fix

Something you may not know. OneDriveExplorer also works for the OneDrive sync client for macOS.

github.com/Beercow/OneD...

25.06.2025 00:04 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Today we learned Fishrocket (the one with the doughnut) has cancer. It’s an aggressive form of mast cell tumors. Treatment usually involves removing them but there are too many. They prescribe prednisone because they itch. Has diabetes so can’t give him prednisone. Poor guy.

20.06.2025 00:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

1/ I successfully tested a LSASS dumping technique on a Windows 10 lab machine, which we encountered on a recent Incident Response engagement (no EDR, default Defender installed).

The "MiniDumpWriteDump" technique, as described here [1], was successful in writing the LSASS process to disk.

19.06.2025 08:33 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Post image

Another interesting forensic artifact in OneDrive. UXDatabase.db

18.06.2025 19:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
MALoney (It's in the name): Weekly Update 6/6/2025 OneDrive Evolution OneDrive Evolution has been updated to OneDrive versionΒ 25.106.0602.0001. Starting with versionΒ 25.102.0527.0001, there ...

Updates on the OneDrive sync client.

malwaremaloney.blogspot.com/2025/06/week...

06.06.2025 20:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

New folder and databases in the OneDrive sync client. Not sure what feature they are tied to yet. More to come. #DFIR

05.06.2025 02:02 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

New laptop, new stickes. 😜

03.06.2025 02:14 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Release v2025.05.30 Β· Beercow/OneDriveExplorer Β· GitHub Change Log Fixed ODL bug fix FileUsageSynce bug fix

Found a few bugs that would cause crashes in OneDriveExplorer around ODL and FileUsageSync. Update available.

github.com/Beercow/OneD...

30.05.2025 19:36 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
MALoney (It's in the name): OneDrive Evolution and Schema Updates OneDrive Evolution Updates OneDrive Evolution has been updated to v25.093.0514.0001 OneDrive Evolution SyncEngine Schema Updates Β Schemas 34...

Finally caught up. Updates to OneDrive Evolution and database schemas.

malwaremaloney.blogspot.com/2025/05/oned...

23.05.2025 19:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
MALoney (It's in the name): OneDriveExplorer now supports Microsoft.FileUsageSync.db Recently, I have been focused on adding support for Microsoft.FileUsageSync.db. See my previous post on Microsoft.FileUsag...

Been a little while. Was busy adding support for Microsoft.FileUsageSync.db to OneDriveExplorer. Update brings in data on files shared via email, Teams, SharePoint and more. Thank you Heather Barnhart for the bug report on search function issues. #DFIR

malwaremaloney.blogspot.com/2025/05/oned...

13.05.2025 11:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

15 strips would have at least been correct.

11.05.2025 20:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Original post: infosec.exchange/@13reak/1143...

15.04.2025 21:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Ah gotcha. I threw some on the stick table also. It was nice meeting you.

13.04.2025 15:20 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Did you snag them from CypherCon?

13.04.2025 03:36 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Hmmmm. What are we up to here? πŸ€”

11.03.2025 22:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Interesting thing with OneDrive Offline Mode for web. You can get the last two modification times of a file. Could come in handy. #DFIR

07.03.2025 20:16 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
MALoney (It's in the name): OneDrive Microsoft.FileUsageSync.db I recently started to look into the Microsoft.FileUsageSync.db . The database can be found in %localappdat...

I started exploring OneDrive’s FileUsageSync.bd. There is some useful information on files shared via email, Teams, etc… that may not be in the user’s OneDrive.

https://malwaremaloney.blogspot.com/2025/02/onedrive-microsoftfileusagesyncdb.html

21.02.2025 17:53 β€” πŸ‘ 0    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

I am OneDrive.

21.02.2025 13:39 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I just came across email information in one of the OneDrive databases. Sender, recipients, subject, mailbox, attachments, etc…
Pretty much everything except the body. More to come. πŸ€” #DFIR

19.02.2025 04:13 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
MALoney (It's in the name): OneDriveExplorer Offline Mode Edition Changes to OneDriveExplorer (ODE) With this release, there are a few things to be aware of that have chan...

OneDriveExplorer now supports and parses Offline Mode for web.

https://malwaremaloney.blogspot.com/2025/02/onedriveexplorer-offline-mode-edition.html

14.02.2025 21:22 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Working on adding this to ODE. πŸ™‚

07.02.2025 21:23 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Flaw in Microsoft's OneDrive Offline Mode Stores OCR Data Insecurely - WinBuzzer Cybersecurity experts warn that Microsoft’s OneDrive Offline Mode leaves sensitive OCR data vulnerable in unprotected local databases.

https://winbuzzer.com/2025/01/28/flaw-in-microsofts-onedrive-offline-mode-stores-ocr-data-insecurely-xcxwbn/

30.01.2025 03:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

https://www.msn.com/en-gb/money/technology/microsoft-onedrive-for-business-allegedly-keeps-ocr-ed-data-in-an-unprotected-format/ar-AA1xXUyl?ocid=entnewsntp&pc=LCTS&cvid=bfb3ccf8c62447bb85c4cbf855defaec&ei=35

29.01.2025 01:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
MALoney (It's in the name): OneDrive Offline Mode (Recallish vibes) Back in April 2024, Microsoft announced a new feature coming to OneDrive for Business called Offline Mode. The feature al...

There seemed to be enough interest so I decided to do a write up on what I have found about OneDrive Offline Mode. Hate to burn a forensic artifact but I’m concerned about what Microsoft feels is secure. #DFIR

https://malwaremaloney.blogspot.com/2025/01/onedrive-offline-mode-recallish-vibes.html

28.01.2025 02:41 β€” πŸ‘ 10    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0
Preview
MALoney (It's in the name): Running Autopsy Auto Ingest in Headless Mode In this post we are going to look at running auto ingest in a headless state. This will allow the auto ingest server to be...

Did you know you can run Autopsy Automated Ingest Nodes as a service. This eliminates human interaction and survives reboots.
https://malwaremaloney.blogspot.com/2025/01/running-autopsy-auto-ingest-in-headless.html

21.01.2025 20:43 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
MALoney (It's in the name): <UserCid>_import.dat Location %LOCALAPPDATA%\Microsoft\Onedrive\Settings\<Personal,Business1-9> Created when Save photos and videos from devices is on. Structure...

Added new artifact to All Things OnDrive. <UserCid>_import.dat is created when β€œSave photos and videos from device” is enabled. It records data on imported photos and videos.

https://malwaremaloney.blogspot.com/p/location-localappdatamicrosoftonedrives_16.html

16.01.2025 19:58 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Autopsy Hardening Guide: Part 2 This is part one of a two part series on hardening an Autopsy Multi-user Cluster. The Autopsy documentation states, "A mul...

Autopsy Hardening Guide: Part 2. This post covers encrypting passwords and securing the web-console of ActiveMQ.

malwaremaloney.blogspot.com/2025/01/auto...

13.01.2025 20:04 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
MALoney (It's in the name): <UserCid>_screenshot.dat Location %LOCALAPPDATA%\Microsoft\Onedrive\Settings\<Personal,Business1-9> Created when Save screenshots I capture to OneDrive is on. Struct...

Added new artifact to All Things OnDrive. <UserCid>_screenshot.dat is created when β€œSave screenshots I capture to OneDrive” is enabled. It records data on the last screenshot saved.

https://malwaremaloney.blogspot.com/p/location-localappdatamicrosoftonedrives.html

09.01.2025 19:19 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

I’m not that ambitious. lol

06.01.2025 20:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@beercow is following 19 prominent accounts