Crack up read from the WATCHTOWR team, highly recommend for an educational giggle.
labs.watchtowr.com/more-governm...
@sleuthifer.bsky.social
// Digging through ya artifacts - DFIR // Running out of “It is what it is” // Dumpster Firefighter -> Preventer of Dumpster Fires @ Internal SecOps
Crack up read from the WATCHTOWR team, highly recommend for an educational giggle.
labs.watchtowr.com/more-governm...
😂
06.01.2025 20:44 — 👍 0 🔁 0 💬 0 📌 0Happy New Year! 🎉🥳 The first 13Cubed episode of 2025 is here! Let's explore some groundbreaking research from CyberCX on “rewinding the NTFS USN Journal.” www.youtube.com/watch?v=GDc8... #DFIR
06.01.2025 12:36 — 👍 11 🔁 3 💬 0 📌 1I made a windows #DFIR artifacts collection MindMap, it's tough to fit everything into a readable overview (might change later)
04.01.2025 23:50 — 👍 24 🔁 12 💬 1 📌 0Agreed 😄 please refer to the “actually interesting to read content” part of that sentence.
04.01.2025 22:36 — 👍 0 🔁 0 💬 1 📌 0Hey Harlan, are you using flat files for timelines or host analysis?
03.01.2025 23:22 — 👍 0 🔁 0 💬 1 📌 0How do you track DFIR timelines and findings? There doesn't seem to be a one size fits all solution in the industry.
Most commonly used are still spreadsheets, where Crowdstrike actually released a pretty nice IR Tracker template a while ago: www.crowdstrike.com/en-us/blog/c...
OneNote or Microsoft Loop for triage and deeper dive host analysis 🕵️♂️
03.01.2025 20:59 — 👍 0 🔁 0 💬 0 📌 0A slightly modified version of the CrowdStrike Excel Sheet. Aurora IR is an option but I prefer the excel imo
03.01.2025 20:56 — 👍 1 🔁 0 💬 1 📌 0I jest 😂
03.01.2025 15:51 — 👍 0 🔁 0 💬 0 📌 0Where about was this? Planning a surf trip 🌊 I’ve had penguins and seals in NZ but no dolphins… yet
30.12.2024 23:42 — 👍 2 🔁 0 💬 1 📌 0So, the other day I started to whisper and my wife asked why I was whispering? I told her I didn't want Mark Zuckerberg to hear us.
I laughed.
My wife laughed.
Alexa laughed.
Siri laughed.
Can’t beat a good ankle nut
29.12.2024 00:03 — 👍 1 🔁 0 💬 0 📌 0What’s the suggested alternative in your opinion? Agreed Google sucks
28.12.2024 23:43 — 👍 0 🔁 0 💬 0 📌 0Godspeed brave man 🙏
28.12.2024 23:39 — 👍 1 🔁 0 💬 0 📌 0iykyk… 👀
20.12.2024 23:49 — 👍 0 🔁 0 💬 0 📌 0Image of a variety of knives all labeled with a different type of material they are designed for cutting like Ham, Bread, Cheese, etc. At the bottom of the image is a light saber labeled "For people that don't use UTC for logging"
#DFIR #DFIRHumor
16.12.2024 21:58 — 👍 60 🔁 7 💬 0 📌 1Getting injected 💉
11.12.2024 22:31 — 👍 0 🔁 0 💬 0 📌 0Sir please! Some respect.
10.12.2024 13:16 — 👍 0 🔁 0 💬 0 📌 0open.spotify.com/track/25Ozqe...
Getting through ya Monday floating on a cloud listening to this 🌌
Pretty much 🍤
06.12.2024 18:26 — 👍 0 🔁 0 💬 0 📌 0“Genshin Impact” has entered the chat…
27.11.2024 18:03 — 👍 1 🔁 0 💬 0 📌 0That little countdown on 2FA apps stresses the shit out of me. I feel like I'm diffusing a bomb.
If it gets into the red, I just wait. I can't handle the stress.
Tbh screw starter packs… this is the way
23.11.2024 20:34 — 👍 1 🔁 0 💬 0 📌 0