DFIR - Automating End to End Acquisition and Processing
This post dives into automating end to end artifact collection and processing using Velociraptor and Timesketch all deployed using CloudFormation in AWS.
Certificate Transparency Logs
Exploring Certificate Transparency logs, deployment of elastic stack and showcase how they can be leveraged for some interesting use cases.
Velociraptor - Hunting for MOVEit IOCs
Showcasing Velociraptors capabilities as we hunt for MOVEit Indicators of Compromise off the back of CVE-2023-34362
Velociraptor - Platform Setup
Part 1: An intro to Velociraptor - Setup and client deployment
TeamSpy - MemProcFS
Exploration of memory analysis with MemProcFS. This post dives into an interesting CyberDefenders challenge, hunting for malicious processes, code executions, files and more.