#forensics

Angus Marshall :2001: :linux:marshalla99@thx.gg
2025-12-16

I'm exploring how people find best practice for writing SOPs and what it looks like. You can help by completing the survey online at forms.gle/t26bsCqtBCwhq2YV9 or downloading a copy from drive.google.com/uc?export=dow

and emailing it back to me.

Input from ANY industry is useful - and more is probably better.

Responses are confidential and no detail of SOP asked for.

#forensics #SOPs #quality #ISO17025 #standards #DFIR #forensicScience

Please repost/boost for coverage.

📡 RightToPrivacy & Tech TipsRTP@fosstodon.org
2025-12-15

STORY: Man Arrested For Wiping Phone - covering how some rights depend where you live - understanding your rights is important, especially for the innocent.

(this case may have other info sealed - very possible there is more we don't know)

#humanrights #privacy #android #googlepixel #tech #AOSP #forensics #law #constitution #4thamendment #peertube

tube.tchncs.de/w/sA9DjpGbddTGr

Angus Marshall :2001: :linux:marshalla99@thx.gg
2025-12-13

I'm still trying to get to the bottom of how people find best practice for writing SOPs and what it looks like. You can help by completing the survey online at forms.gle/t26bsCqtBCwhq2YV9 or downloading a copy from drive.google.com/uc?export=dow

and emailing it back to me.

Input from ANY industry is useful - and more is probably better.

Responses are confidential and no detail of SOP asked for.

#forensics #SOPs #quality #ISO17025 #standards #DFIR

Please repost/boost for coverage.

Susan Villevillebooks
2025-12-12

📲 For five months, the Gaza Humanitarian Foundation was the main distributor of food in

Backed by the , more than 1,000 people were killed seeking aid at its sites

Video: Airwars reconstructed two aid sites, based on footage and interviews with Palestinian aid seekers and former GHF contractors

The short film shows how the design of the militarised aid system - from design to execution - made deaths and injuries inevitable

youtube.com/watch?v=drm5I4RFxQU

2025-12-11

Кибердетектив: по следам злоумышленника. Расследование инцидентов

И в мире ИБ есть свои детективы. Они исследуют, наблюдают, собирают информацию и занимаются профилактикой, как и коллеги из юридической сферы, только их деятельность направлена на безопасность информационную. Как они это делают? Как происходит расследование инцидентов? Что нужно знать, чтобы стать кибердетективом? В статье поговорим об этапах киберрасследования, анализе логов, дампов и не только, а также о том, где этому можно научиться.

habr.com/ru/companies/gaz-is/a

#газинформсервис #информационная_безопасность #ctf #forensics #computer_forensics #обучение

2025-12-09
2025-12-08

Recovering a Linux backdoor that is still running but was deleted off disk:

  • Check the /𝗽𝗿𝗼𝗰/𝗣𝗜𝗗 directory for the running process
  • If it has 𝐫𝐞𝐜𝐨𝐯𝐞𝐫𝐞𝐝_𝐞𝐱𝐞 in it, thats the reconstructed executable.

It may not always be there, but is great when it is!

#linux #forensics #dfir

Angus Marshall :2001: :linux:marshalla99@thx.gg
2025-12-08

I'm trying to get to the bottom of how people find best practice for writing SOPs and what it looks like. You can help by completing the survey online at forms.gle/t26bsCqtBCwhq2YV9 or downloading a copy from drive.google.com/uc?export=dow and emailing it back to me.

Input from ANY industry is useful - and more is probably better.

Responses are confidential and no detail of SOP asked for.

#forensics #SOPs #quality #ISO17025 #standards #DFIR

Please repost/boost for coverage.

2025-12-05

4n6images

Free database of 30+ verified images to practice and research. Filter by OS, creation date of file size.

4n6img.com/

By Husam Shbib

#dfir #forensics

2025 Year in Review: Open Source DFIR Tools and Malware Analysis Projects

As 2025 draws to a close, I’m taking a moment to reflect on what turned out to be one of my most productive years in code. From major releases to entirely new projects, this year saw significant evolution across my DFIR toolkit—driven by real-world incident response needs, classroom teaching experiences, and late-night tinkering sessions fueled by good bourbon and better puzzles.

What started as continuing work on CyberPipe evolved into a year of substantial innovation: creating MalChela for YARA and malware analysis, building a portable Raspberry Pi forensics platform, developing automated timeline generation workflows, and crafting specialized utilities that solve specific problems I encountered in the field. Each tool represents not just lines of code, but practical solutions to challenges that digital forensics and incident response professionals face daily.

Whether you’re a seasoned forensic analyst, an incident responder building your toolkit, or a student just getting started in DFIR, my hope is that these open-source projects make your work a little easier and a lot more efficient. All tools remain freely available on GitHub, because I believe the best way to advance our field is to share knowledge and capabilities openly.

Here’s what kept me busy in 2025:

MalChela – YARA & Malware Analysis Toolkit (Rust)

My flagship project that evolved significantly throughout 2025:

  • March: Initial release – Combined 10 programs into one Rust workspace for YARA and malware analysis
  • May: v2.1 – Added smoother workflows, better third-party tool integration, and enhanced argument handling
  • May: v2.2 “REMnux Release” – Native support for REMnux, integrations with Volatility3, Tshark, YARA-X
  • June: v3.0 – Major update introducing Case Management system, FileMiner (replacing MismatchMiner), and tool suggestion capabilities based on file characteristics
  • July: v3.0.1 – Refinements to mStrings, improved MITRE mappings, “Select All” functionality, optimizations for running on Toby
  • August: v3.0.2 – Enhanced threat hunting with MITRE ATT&CK technique lookup

MalChela at a Glance

  • Rust-based malware analysis toolkit combining YARA scanning, file analysis, hash generation, string extraction with MITRE ATT&CK mapping, and automated malware sample extraction from password-protected archives 
  • Multiple specialized utilities including mzhash/xmzhash for corpus generation, file type mismatch detection, entropy analysis, PE structure examination, and fuzzy hashing capabilities 
  • Integrated threat intelligence with VirusTotal and Malware Bazaar API support, NSRL database queries for known-good file filtering, and Sigma rule application for IOC identification 
  • Case management system (v3.0) featuring unified tracking of files, tools, and notes in case.yaml format with auto-saved outputs, tagging, search functionality, and VS Code integration 
  • Extensible architecture supporting custom tool integration via tools.yamlconfiguration, enhanced support for Volatility 3, TShark, and YARA-X, with both GUI and CLI modes (WSL2-compatible on Windows)
  • Complete documentation embedded as PDF or online

https://bakerstreetforensics.com/2025/06/20/malchela-v3-0-case-management-fileminer-and-smarter-triage/

https://github.com/dwmetz/MalChela

CyberPipe – Incident Response Collection Tool (PowerShell)

Continued evolution of the enterprise digital evidence collection script:

  • May: v5.1 – Streamlined profiles with better flexibility, customizable collection profiles
  • October: v5.2 – Improved collection methods with dual disk space validation, SHA-256 hashing of artifacts, single-file reporting, network collection simplification
  • November: v5.3 – Critical PowerShell 5.1 compatibility fixes, dual validation logic, enhanced reliability across all PowerShell environments

https://bakerstreetforensics.com/2025/11/04/cyberpipe-v5-3-enhanced-powershell-compatibility-and-reliability/

https://github.com/dwmetz/CyberPipe

CyberPipe-Timeliner ✱New✱ (PowerShell)

  • NovemberCyberPipe-Timeliner – New companion project to CyberPipe that automates the workflow from Magnet Response collections to unified forensic timelines using Eric Zimmerman’s EZ Tools and ForensicTimeliner

https://bakerstreetforensics.com/2025/11/05/cyberpipe-timeliner-from-collection-to-timeline-in-one-script/

https://github.com/dwmetz/CyberPipe-Timeliner

Toby – Portable Raspberry Pi Forensics Toolkit

  • July: Released Toby – A compact forensics toolkit built on Raspberry Pi Zero 2 W running customized Kali Linux, designed for headless operation via SSH/VNC, perfect for field analysis and malware triage

https://bakerstreetforensics.com/2025/07/20/portable-forensics-with-toby-a-raspberry-pi-toolkit/

Toby-Find

  • JulyToby-Find – Terminal-based command-line helper tool for discovering CLI forensics tools in KALI and REMnux environments, created initially for university teaching

https://bakerstreetforensics.com/2025/07/29/toby-find-simplifying-command-line-forensics-tools/

https://github.com/dwmetz/Toby

Crabwise – USB Device Benchmark Utility (Rust)

  • August: Released Crabwise – A lightweight USB benchmarking tool that measures true read/write speeds of USB devices for forensic workflows. Tests write throughput with pseudo-random data and read performance under uncached conditions. Includes logging functionality to track performance across different cables, hubs, and connection paths, helping forensic investigators optimize their hardware setups.

https://bakerstreetforensics.com/2025/08/27/is-your-usb-device-slowing-down-your-forensic-investigation/

https://github.com/dwmetz/Crabwise

Toolbox Utilities – Specialized Python and Bash Scripts

Standalone tools maintained in the Toolbox repository:

  • OctoberCoreBreaker.py – Breaks large yara-rules-core files into smaller .yar files for tool ingestion
  • OctoberEtTu.py – Caesar cipher brute force decoder (created for Murdle puzzle solving); After all, All work and no play makes Jack a dull boy.
  • Novembercloudtrail_timeline.py – Parses AWS CloudTrail JSON logs and outputs CSV format for Timeline Explorer
  • Novembermac_triage_timeline.sh – Processes Mac-Triage ZIP files and generates timeline for Timeline Explorer
  • Novemberuac_timeline.sh – Processes UAC tar.gz files and generates timeline for Timeline Explorer (Linux/macOS)

https://github.com/dwmetz/Toolbox

All projects are available on my GitHub at github.com/dwmetz, with detailed documentation on bakerstreetforensics.com. My goal is making DFIR and malware analysis more accessible, automated, and efficient for incident responders and forensic analysts.

#dfir #forensics #github #malware #malwareanalysis #opensource #powershell #rust #yara

2025-12-05

Bộ Chính trị đã ban hành Chỉ thị số 54, nhấn mạnh việc tăng cường sự lãnh đạo của Đảng đối với công tác giám định tư pháp và định giá tài sản.

Chỉ thị yêu cầu phải kiên quyết sàng lọc, thay thế những cán bộ yếu kém về năng lực, phẩm chất, có biểu hiện tiêu cực, vụ lợi trong lĩnh vực quan trọng này.

#ViệtNam #ChínhTrị #BộChínhTrị #GiámĐịnhTưPháp #ChốngThamNhũng #TinTức
#Vietnam #Politics #VietnamPolitics #AntiCorruption #Forensics #VietnamNews

vietnamnet.vn/bo-chinh-tri-kie

2025-12-04

I'm co-teaching two #digital #forensics courses for #archivists via SAA in Jan. 2025. Early cutoff for registration is Jan. 4.

Fundamentals: mysaa.archivists.org/nc__event

Advanced: mysaa.archivists.org/nc__event

I'm also revising these courses, so if you have taken them and have feedback on how you'd like to see them change, please reach out!

Athanasiaamelia13
2025-12-04

🧪 Plubeck’s Forensic Medicine & Criminal Investigations illuminates the dark junction of crime and science — real cases, forensic evidence, and investigations that challenge what we think we know. True crime with depth.

🔗 plubeck.com/category/forensic-

2025-12-03

Jimmie Duncan spent 27 years on death row, convicted in part based on evidence experts now consider to be junk science.

But even after the overturning of his murder conviction and his release on bail, Louisiana still wants to execute him.
propublica.org/article/jimmie-

#News #Louisiana #CriminalJustice #Law #Crime #Forensics

Angus Marshall :2001: :linux:marshalla99@thx.gg
2025-12-03

Today's reminder :

I'm trying to get to the bottom of how people find best practice for writing SOPs and what it looks like. You can help by completing the survey online at forms.gle/t26bsCqtBCwhq2YV9 or downloading a copy from drive.google.com/uc?export=dow and emailing it back to me.

Input from ANY industry is useful - and more is probably better.

Responses are confidential and no detail of SOP asked for.

#forensics #SOPs #quality #ISO17025 #standards #DFIR

Please repost/boost for coverage.

Angus Marshall :2001: :linux:marshalla99@thx.gg
2025-12-02

Today's reminder :

I'm trying to get to the bottom of how people find best practice for writing SOPs and what it looks like. You can help by completing the survey online at forms.gle/t26bsCqtBCwhq2YV9 or downloading a copy from drive.google.com/uc?export=dow and emailing it back to me.

Input from ANY industry is useful - and more is probably better.

Responses are confidential and no detail of SOP asked for.

#forensics #SOPs #quality #ISO17025 #standards #DFIR

Please repost/boost for coverage.

2025-12-02

Community Spotlight: Internship Search

We're excited to share that Muhammed Waseem Villan, a talented Master's student in Cybersecurity and Cyber Defence at the University of Luxembourg and co-organizer of BSidesLux 2026, is actively seeking an internship opportunity within our community!

About Waseem:

Currently pursuing Master's in Cybersecurity and Cyber Defence

Top 2% performer on TryHackMe

CEH v12 Certified and IBM Cyber Security Advanced Certificate holder

Background in Digital Forensics, Threat Intelligence Analysis, and Campus Ambassador roles (trained 1800+ students)

What He Brings:

Penetration Testing and Vulnerability Assessment

Digital Forensics and Incident Response

Threat Intelligence and Security Frameworks (NIST RMF, ISO 27001)

Strong technical foundation with excellent communication skills

Availability:

February 2025 – June/July 2025 (3-6 months duration)

Based in Luxembourg originally from India

If you have internship opportunities or know of relevant positions, please reach out to Muhammed directly or bsides page. Let's support one of our own!

#CyberSecurity #Internship #Luxembourg #Forensics #ThreatIntelligence #BSidesLuxembourg2026

2025-12-01

🇦🇺 A WA man, 44, has been sentenced in ⚖️ Perth District Court (districtcourt.wa.gov.au) to seven (7) years & four (4) months’ imprisonment. #australia #justice #wireless #technologies #forensics [ afp.gov.au/news-centre/media-r ] #informatique

The 👮 AFP commenced an investigation in April, 2024, after an airline reported that its employees had identified a suspicious WiFi network – which mimicked a legitimate AP – during a domestic flight.

Angus Marshall :2001: :linux:marshalla99@thx.gg
2025-12-01

Daily reminder - I'm trying to get to the bottom of how people find best practice for writing SOPs and what it looks like. You can help by completing the survey online at forms.gle/t26bsCqtBCwhq2YV9 or downloading a copy from drive.google.com/uc?export=dow and emailing it back to me.

Input from ANY industry is useful - and more is probably better.

Responses are confidential and no detail of SOP asked for.

#forensics #SOPs #quality #ISO17025 #standards #DFIR

Please repost/boost for coverage.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst