Beercow :python: :verified:

"Distrust and caution are the parents of security." - Benjamin Franklin

Beercow :python: :verified:Beercow@infosec.exchange
2025-12-22

When you get a group text and fix the name and picture for them.

Beercow :python: :verified:Beercow@infosec.exchange
2025-12-07
Beercow :python: :verified:Beercow@infosec.exchange
2025-12-07

Fixed a bug in DeXRAY for Windows Defender files. 🙂

hexacorn.com/blog/2025/12/03/d

Beercow :python: :verified:Beercow@infosec.exchange
2025-12-03

Fixed a bug in DeXRAY for Windows Defender files. 🙂

hexacorn.com/blog/2025/12/03/d

Beercow :python: :verified:Beercow@infosec.exchange
2025-11-20

Not that kind of consent. The UAC kind of consent. Take a dive into how UAC works and some of the things it doesn’t tell you. Also a new utility to solve some of these issues.
malwaremaloney.blogspot.com/20

Beercow :python: :verified: boosted:
Beercow :python: :verified:Beercow@infosec.exchange
2025-11-20

When launching a program as admin, consent.exe runs with a parent process of svchost. If successful, consent.exe exits and the new process is launched with explorer as its parent. If not, we can’t always tell what was trying to be ran. Until now. github.com/Beercow/ConsentMoni

Beercow :python: :verified:Beercow@infosec.exchange
2025-11-20

When launching a program as admin, consent.exe runs with a parent process of svchost. If successful, consent.exe exits and the new process is launched with explorer as its parent. If not, we can’t always tell what was trying to be ran. Until now. github.com/Beercow/ConsentMoni

Beercow :python: :verified:Beercow@infosec.exchange
2025-11-19

Into the unknown and down rabbit holes we go.

Beercow :python: :verified: boosted:
Beercow :python: :verified:Beercow@infosec.exchange
2025-11-07

Weekly update. New features in OneDriveExplorer, Onedrive Evolution and schema updates. #DFIR
malwaremaloney.blogspot.com/20

Beercow :python: :verified:Beercow@infosec.exchange
2025-11-07

Weekly update. New features in OneDriveExplorer, Onedrive Evolution and schema updates. #DFIR
malwaremaloney.blogspot.com/20

Beercow :python: :verified:Beercow@infosec.exchange
2025-10-16

Adding a parser for Microsoft.FilesOnDemand.db to OneDriveExplorer. Yet another source to rebuild the user’s OnDrive. More to come. #DFIR

Beercow :python: :verified:Beercow@infosec.exchange
2025-10-16

Did a little digging in Microsoft.FileUsageSync.db. Found some information to piece together OneDrive Quick Access. #DFIR
malwaremaloney.blogspot.com/20

Beercow :python: :verified:Beercow@infosec.exchange
2025-10-08

Did a little digging in Microsoft.FileUsageSync.db. Found some information to piece together OneDrive Quick Access. #DFIR
malwaremaloney.blogspot.com/20

Beercow :python: :verified:Beercow@infosec.exchange
2025-09-30

In case you missed it. New release of OneDriveExplorer. It has a dedicated parser for MicrosoftListSync.db (offline mode). #DFIR

malwaremaloney.blogspot.com/20

Beercow :python: :verified:Beercow@infosec.exchange
2025-09-23

That time of year again when everybody starts abbreviating cybersecurity awareness month as CSAM. 21 pages deep of google searches for that term and not a single mention of cybersecurity awareness month. Go figure.

Beercow :python: :verified:Beercow@infosec.exchange
2025-08-22

OneDrive Evolution has been updated to v25.162.0820.0001. That’s 692 versions OneDriveExplorer now handles. SafeDelete.db has been updated to schema v9. Enjoy!

malwaremaloney.blogspot.com/p/

malwaremaloney.blogspot.com/p/

Beercow :python: :verified:Beercow@infosec.exchange
2025-08-11

Appears OneDrive snuck a new sync client in. Works with personal accounts at the moment. It’s WebView2. You can find data in the following locations:
AppData\Local\Microsoft\OneDrive\OD4
AppData\Local\Microsoft\OneDrive\Logs\OD4
Where are my browser forensics experts at? #DFIR

Beercow :python: :verified:Beercow@infosec.exchange
2025-08-07

Updated OneDrive Evolution. You can now compare two versions of OneDrive and see what has changed. #DFIR

malwaremaloney.blogspot.com/p/

Beercow :python: :verified:Beercow@infosec.exchange
2025-06-25

Something you may not know. OneDriveExplorer also works for the OneDrive sync client for macOS.

github.com/Beercow/OneDriveExp

Beercow :python: :verified:Beercow@infosec.exchange
2025-06-20

@FritzAdalis my daughter thought of it when she was little. We wanted to name the other one Mouse Missile but our son went a different direction. He’s 14 just wish there was something we could do for the itching. That doughnut comes off and he is licking and chewing at his skin.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst