Advertisement Β· 728 Γ— 90

Posts by Ryan Benson

Video

Have a big number (or hex value) you found and think might be a timestamp? Drop it in `unfurl` in the terminal and see what comes out!

(add -d or --detailed if you want the type of timestamp, or run without it if you just want the value)

#DFIR #BF4SA #Unfurl 🌿

2 months ago 3 1 0 0
Preview
Hindsight v2026.01 Released! Hindsight v2026.01 brings new features, including parsing Sync Data, an updated terminal interface, improved output formats, and dozens of fixes and enhancements.

There's a new Hindsight release! v2026.01 brings new features, including:
πŸ”„ Parsing Sync Data
⌨️ Updated terminal interface
πŸ“‚ Improved output formats
βš™οΈ Many fixes and enhancements

Read more at dfir.blog/hindsight-v2... or download the new version from GitHub: github.com/obsidianfore...

2 months ago 1 0 0 0
Post image

A new Unfurl release (unfurl.link) is here! v2025.08 has:

πŸ†” Parsing more from TikTok IDs (millisecond timestamp, entity type (user account, device, live session, or video), and more). Thanks to Benjamin Steel for the paper arxiv.org/abs/2504.13279

πŸ“ Full release notes: github.com/obsidianfore...

8 months ago 8 4 0 0
Post image

This story is absolutely insane. And we don't usually get a front-row seat to insider threat investigations

Spy got tricked by a honeypot and implicated the most senior leaders at the victim's biggest competitors.

I go through it all here: youtu.be/tDG1WfbSZFo

1 year ago 10 4 1 3
Preview
Unfurl 2025.03 Unfurl v2025.03 adds new features, including parsing Google Search's UDM parameter, support for Mastodon forks (like Truth Social), and a utility parser to "clean up" inputs.

Unfurl v2025.03 is live and adds new features, including:

πŸ”Ž Parsing #Google Search's UDM parameter
🐘 Recognizing #Mastodon usernames and parsing forks (like truthsocial[.]com and gab[.]com)
🧹 Utility parser to "clean up" inputs

Try it: unfurl.link
Blog post: dfir.blog/unfurl-parse...

#DFIR #OSINT

1 year ago 2 0 0 0
Preview
Hindsight v2025.03 Released! Hindsight v2025.03 focuses on Extensions - parsing more activity and state records, highlighting Extension permissions, and making it easier to examine Manifests.

There's a new Hindsight release!

Hindsight v2025.03 focuses on Extensions - parsing more activity and state records, highlighting Extension permissions, and making it easier to examine Manifests.

🌐 Blog: dfir.blog/hindsight-pa...
πŸ› οΈ Tool download: hindsig.ht/release

#DFIR #Chrome #Extensions

1 year ago 8 4 0 0
Preview
unfurl Extract and Visualized Data from URLs

A new Unfurl release is here! v2025.02 adds:

🌐 Parsing encoded/obfuscated IP addresses
πŸ¦‹ Resolving #Bluesky handles to their identifiers (DIDs) and looking up their creation timestamps
πŸ› Bug fixes & better bulk parsing

Blog: dfir.blog/unfurl-parse...
Code: github.com/obsidianfore...

#DFIR #OSINT

1 year ago 8 7 0 0
Preview
unfurl Extract and Visualized Data from URLs

Unfurl can do this as well - the timestamp is embedded in the ID in the URL, so no login/etc needed, just the URL.

Example: dfir.blog/unfurl/?url=...

1 year ago 2 0 1 0
Preview
unfurl Extract and Visualized Data from URLs

Want to break down what is in a URL? Try Unfurl from Ryan Benson and gain further insights! dfir.blog/unfurl/
#DFIR

1 year ago 16 8 0 0
A Google Search Results Page (SERP) from the Netflix movie Carry-On

A Google Search Results Page (SERP) from the Netflix movie Carry-On

Over the winter holiday, I was watching Netflix's Carry-On and got a bit nerd-sniped by a real Google Search URL on-screen... and then proceeded to "authenticate" it.

dfir.blog/authenticati...

#DFIR #OSINT #Unfurl #Netflix

1 year ago 3 0 0 0
Advertisement

The Raiders can’t even be good at being bad…

1 year ago 0 0 0 0
Preview
unfurl Extract and Visualized Data from URLs

Unless they fundamentally change how tweets work (which seems unlikely), the timestamp can be extracted from the URL (no API needed).

Taking your tweet about the timestamps as an example, a tool like Unfurl can show it was sent at 2024-12-04 21:13:20.296 UTC.

Example: dfir.blog/unfurl/?url=...

1 year ago 3 0 0 0

CTFs present challenges that you likely haven’t seen before. I’ve taken away new skills from every CTF I’ve ever participated in.

1 year ago 2 1 1 0
YouTube Share your videos with friends, family, and the world

A new episode is live now of @dfnpodcast.bsky.social www.youtube.com/live/4H9TLL8...

1 year ago 1 2 0 0
Post image

Since I'm trying out #Bluesky, I figured I should add in support for it in Unfurl!

The v2024.11.20 release has some minor updates, but the biggest feature is the ability to parse a timestamp from Bluesky post IDs (or atproto TIDs).

Example: dfir.blog/unfurl/?url=...

Give it a try at unfurl.link!

1 year ago 26 12 0 2

New Timesketch release is out. Two highlights:

- Unfurl [1] integration, get information from URLs directly in your timeline.

- DFIQ [2] support with context aware SearchHistory.

Changelog: timesketch.org/changelog/#v...

[1] dfiq.org
[2] dfir.blog/introducing-...

2 years ago 0 2 0 0

Oh hi everyone! I've missed what #DFIR Twitter used to be - here's to hoping we can get something similar going here!

1 year ago 11 1 2 1
Advertisement