Digital Forensics is Really Easy

The mechanics of digital forensics (and its related cousin, incident response) are fairly easy. A computer…

On ransomware, my advice is different from that other guy’s advice.

For engagements where my clients ask for help in preparing for a ransomware attack, the most…

Don’t totally discount attribution in Incident Response work

I’m big on attribution in crimes. It is my personality and attitude, which you can probably…

What is this thing called “Patreon?”

Some have found a Patreon page that I created for the DFIR Training website (http://www.patreon.com/dfirtraining). Here…

#DFIR Traveling Isn’t

For those working in DFIR, there are some who don’t travel, some who travel a lot, and…

Patreon at DFIR Training

If you haven’t seen yet, I started a Patreon page for DFIR Training (www.dfir.training). I’ve done this…

101+ Tips & Tricks with X-Ways Forensics

Let me get something out of the way: X-Ways Forensics (XWF) is not the only forensic suite…

How to Start a Digital Forensic Lab in Your Police Department

So, you want to start a brand new, right-out-of-the-box, digital forensics lab in your police department? …

X-Ways Forensics Cheat Sheet and “Three Things”

I had the pleasure of talking to a group of high schoolers about digital forensics recently.…

Brett’s opinion on DFIR notes and note-taking

I’ve read some really good material on the importance of taking notes over the years and…

Low-Hanging Fruit Report

Low Hanging Fruit: Evidence Based Solutions to the Digital Evidence Challenge When I first saw the…

A skill you need in DFIR, but won’t find DFIR courses in it

Working in DFIR requires that you convey information to someone else. There is no way around…

Interconnected Devices Investigations

Reading through the paper“Forensic framework to identify local vs synced artefacts” from DFRWS 2018 Europe, I…

Old hat investigative work will always work

The Reality Winner case is good example where a basic investigative method still works regardless of…

In the #DFIR world, it seems like everyone is an expert….

…because everyone can be an expert. One thing about the DFIR field and all of its…

Why does Google think this is a good idea?

An incredible new Gmail feature, “Confidential E-mail Mode” by Google looks to be one of those…

Don’t become a hacker by hacking back a hacker that hacked you

Emotions run deep if you are victimized.  Initially, you want blood at any cost.  You also…

Zombie-Cases:  Did you ever have a case that just wouldn’t die?

I just finished up Case Study #8, with one of those types of cases that just…