Updated OneDrive Evolution. You can now compare two versions of OneDrive and see what has changed. #DFIR
malwaremaloney.blogspot.com/p/onedrive-e...
@beercow.bsky.social
"Distrust and caution are the parents of security." - Benjamin Franklin https://malwaremaloney.blogspot.com
Updated OneDrive Evolution. You can now compare two versions of OneDrive and see what has changed. #DFIR
malwaremaloney.blogspot.com/p/onedrive-e...
Something you may not know. OneDriveExplorer also works for the OneDrive sync client for macOS.
github.com/Beercow/OneD...
Today we learned Fishrocket (the one with the doughnut) has cancer. Itβs an aggressive form of mast cell tumors. Treatment usually involves removing them but there are too many. They prescribe prednisone because they itch. Has diabetes so canβt give him prednisone. Poor guy.
20.06.2025 00:19 β π 0 π 0 π¬ 0 π 01/ I successfully tested a LSASS dumping technique on a Windows 10 lab machine, which we encountered on a recent Incident Response engagement (no EDR, default Defender installed).
The "MiniDumpWriteDump" technique, as described here [1], was successful in writing the LSASS process to disk.
Another interesting forensic artifact in OneDrive. UXDatabase.db
18.06.2025 19:30 β π 0 π 0 π¬ 0 π 0Updates on the OneDrive sync client.
malwaremaloney.blogspot.com/2025/06/week...
New folder and databases in the OneDrive sync client. Not sure what feature they are tied to yet. More to come. #DFIR
05.06.2025 02:02 β π 1 π 0 π¬ 0 π 0New laptop, new stickes. π
03.06.2025 02:14 β π 0 π 0 π¬ 0 π 0Found a few bugs that would cause crashes in OneDriveExplorer around ODL and FileUsageSync. Update available.
github.com/Beercow/OneD...
Finally caught up. Updates to OneDrive Evolution and database schemas.
malwaremaloney.blogspot.com/2025/05/oned...
Been a little while. Was busy adding support for Microsoft.FileUsageSync.db to OneDriveExplorer. Update brings in data on files shared via email, Teams, SharePoint and more. Thank you Heather Barnhart for the bug report on search function issues. #DFIR
malwaremaloney.blogspot.com/2025/05/oned...
15 strips would have at least been correct.
11.05.2025 20:01 β π 0 π 0 π¬ 0 π 0Original post: infosec.exchange/@13reak/1143...
15.04.2025 21:17 β π 0 π 0 π¬ 0 π 0Ah gotcha. I threw some on the stick table also. It was nice meeting you.
13.04.2025 15:20 β π 1 π 0 π¬ 1 π 0Did you snag them from CypherCon?
13.04.2025 03:36 β π 1 π 0 π¬ 1 π 0Hmmmm. What are we up to here? π€
11.03.2025 22:53 β π 0 π 0 π¬ 0 π 0Interesting thing with OneDrive Offline Mode for web. You can get the last two modification times of a file. Could come in handy. #DFIR
07.03.2025 20:16 β π 1 π 0 π¬ 0 π 0I started exploring OneDriveβs FileUsageSync.bd. There is some useful information on files shared via email, Teams, etcβ¦ that may not be in the userβs OneDrive.
https://malwaremaloney.blogspot.com/2025/02/onedrive-microsoftfileusagesyncdb.html
I am OneDrive.
21.02.2025 13:39 β π 0 π 0 π¬ 0 π 0I just came across email information in one of the OneDrive databases. Sender, recipients, subject, mailbox, attachments, etcβ¦
Pretty much everything except the body. More to come. π€ #DFIR
OneDriveExplorer now supports and parses Offline Mode for web.
https://malwaremaloney.blogspot.com/2025/02/onedriveexplorer-offline-mode-edition.html
Working on adding this to ODE. π
07.02.2025 21:23 β π 0 π 0 π¬ 0 π 0https://www.msn.com/en-gb/money/technology/microsoft-onedrive-for-business-allegedly-keeps-ocr-ed-data-in-an-unprotected-format/ar-AA1xXUyl?ocid=entnewsntp&pc=LCTS&cvid=bfb3ccf8c62447bb85c4cbf855defaec&ei=35
There seemed to be enough interest so I decided to do a write up on what I have found about OneDrive Offline Mode. Hate to burn a forensic artifact but Iβm concerned about what Microsoft feels is secure. #DFIR
https://malwaremaloney.blogspot.com/2025/01/onedrive-offline-mode-recallish-vibes.html
Did you know you can run Autopsy Automated Ingest Nodes as a service. This eliminates human interaction and survives reboots.
https://malwaremaloney.blogspot.com/2025/01/running-autopsy-auto-ingest-in-headless.html
Added new artifact to All Things OnDrive. <UserCid>_import.dat is created when βSave photos and videos from deviceβ is enabled. It records data on imported photos and videos.
https://malwaremaloney.blogspot.com/p/location-localappdatamicrosoftonedrives_16.html
Autopsy Hardening Guide: Part 2. This post covers encrypting passwords and securing the web-console of ActiveMQ.
malwaremaloney.blogspot.com/2025/01/auto...
Added new artifact to All Things OnDrive. <UserCid>_screenshot.dat is created when βSave screenshots I capture to OneDriveβ is enabled. It records data on the last screenshot saved.
https://malwaremaloney.blogspot.com/p/location-localappdatamicrosoftonedrives.html
Iβm not that ambitious. lol
06.01.2025 20:22 β π 0 π 0 π¬ 0 π 0