Combining Fuji Cartridge and WinFE into a single setup that can handle forensic imaging for both macOS and Windows systems. #DFIR
malwaremaloney.blogspot.com/2026/04/last...
Posts by
Coming soon. How to build a combined Fuji recovery and WinFE drive. #DFIR
Coming soon. How to build a combined Fuji recovery and WinFE drive. #DFIR
Available Hashes:
MD5, SHA1, AmCache SHA1, SHA256, CRC32, SHA512, SHA3-256, SHA3-512, BLAKE2b, IMPHASH, QuickXorHash, SSDEEP, MD4, ED2K
SmackThatHash features AmCache SHA1 variant and QuickXorHash (OneDrive). Run against a single file or entire folder recursively. Pick from preset hashes or roll your own. Console and csv output. #DFIR
github.com/Beercow/Smac...
Made an update to XstReader. It was unusable with larger ost files. It now loads large ost files in seconds making it usable again. Have a pull request in but not counting on it being accepted due to inactivity. Let me know what you think. #DFIR
github.com/Beercow/XstR...
When you get a group text and fix the name and picture for them.
Fixed a bug in DeXRAY for Windows Defender files. 🙂
www.hexacorn.com/blog/2025/12...
Fixed a bug in DeXRAY for Windows Defender files. 🙂
www.hexacorn.com/blog/2025/12...
13Cubed XPlat Bundle and T-Shirt giveaway.
📢 I partnered with @13cubed.bsky.social for another giveaway! 🎁
🏆 1 winner will receive a 13Cubed Investigator T-Shirt + the XPlat Bundle Complete
👕 5 winners will receive 13Cubed Investigator T-Shirts
To Enter: Like, Comment, and Repost
#DFIR #DigitalForensics #IncidentResponse
Woot!
Not that kind of consent. The UAC kind of consent. Take a dive into how UAC works and some of the things it doesn’t tell you. Also a new utility to solve some of these issues.
malwaremaloney.blogspot.com/2025/11/lets...
When launching a program as admin, consent.exe runs with a parent process of svchost. If successful, consent.exe exits and the new process is launched with explorer as its parent. If not, we can’t always tell what was trying to be ran. Until now. github.com/Beercow/Cons...
When launching a program as admin, consent.exe runs with a parent process of svchost. If successful, consent.exe exits and the new process is launched with explorer as its parent. If not, we can’t always tell what was trying to be ran. Until now. github.com/Beercow/Cons...
Into the unknown and down rabbit holes we go.
Weekly update. New features in OneDriveExplorer, Onedrive Evolution and schema updates. #DFIR
malwaremaloney.blogspot.com/2025/11/oned...
Weekly update. New features in OneDriveExplorer, Onedrive Evolution and schema updates. #DFIR
malwaremaloney.blogspot.com/2025/11/oned...
Adding a parser for Microsoft.FilesOnDemand.db to OneDriveExplorer. Yet another source to rebuild the user’s OnDrive. More to come. #DFIR
Did a little digging in Microsoft.FileUsageSync.db. Found some information to piece together OneDrive Quick Access. #DFIR
malwaremaloney.blogspot.com/2025/10/oned...
Did a little digging in Microsoft.FileUsageSync.db. Found some information to piece together OneDrive Quick Access. #DFIR
malwaremaloney.blogspot.com/2025/10/oned...
*but
Correct me if I’m wrong bit what you described is Xbox from day one.
In case you missed it. New release of OneDriveExplorer. It has a dedicated parser for MicrosoftListSync.db (offline mode). #DFIR
malwaremaloney.blogspot.com/2025/09/oned...
That time of year again when everybody starts abbreviating cybersecurity awareness month as CSAM. 21 pages deep of google searches for that term and not a single mention of cybersecurity awareness month. Go figure.
OneDrive Evolution has been updated to v25.162.0820.0001. That’s 692 versions OneDriveExplorer now handles. SafeDelete.db has been updated to schema v9. Enjoy!
malwaremaloney.blogspot.com/p/onedrive-e...
malwaremaloney.blogspot.com/p/safedelete...
Appears OneDrive snuck a new sync client in. Works with personal accounts at the moment. It’s WebView2. You can find data in the following locations:
AppData\Local\Microsoft\OneDrive\OD4
AppData\Local\Microsoft\OneDrive\Logs\OD4
Where are my browser forensics experts at? #DFIR
Updated OneDrive Evolution. You can now compare two versions of OneDrive and see what has changed. #DFIR
malwaremaloney.blogspot.com/p/onedrive-e...
Something you may not know. OneDriveExplorer also works for the OneDrive sync client for macOS.
github.com/Beercow/OneD...
Today we learned Fishrocket (the one with the doughnut) has cancer. It’s an aggressive form of mast cell tumors. Treatment usually involves removing them but there are too many. They prescribe prednisone because they itch. Has diabetes so can’t give him prednisone. Poor guy.