Advertisement · 728 × 90
#
Hashtag
#dfircon
Advertisement · 728 × 90
Post image

2 more days to get the early-bird discount for one of my all-time favorite conferences, #SANS #DFIRCON in Miami in Nov. There are a bunch of hands-on workshops on Sun, 16 Nov, lots of evening events during the week #FOR577 my last in 2025. Reg here: www.sans.org/cyber-securi...

2 2 0 1
Post image

🏆 Our #pentest and #dfir colleagues regularly attend conferences and trainings to connect with the community. Very proud that our #digitalforensic specialist and handler, Lukasz, rocked the SANS forensics #dfircon #ctf and saved the trophy for old Europe 😜 Congratz!!👏🏽

9 1 1 1
Post image Post image

It's the final countdown here at #DFIRCON Miami as #FOR577 comes to an end!

In a few minutes, the teams will present their evidence, and the best team will win the coveted lethal forensicator coin!

#dfir #cybersecurity

7 1 0 0
Post image

It's a gorgeous morning here in Miami as we get ready to start the last day of #FOR577 at #DFIRCON.

The good news is that I *think* we will be coming back here in 2025! If you have ideas for hands-on workshops or want to do awesome #infosec training, keep checking in with SANS for details.

12 0 0 0
Classroom photo taken 35 minutes before the start of class.

Classroom photo taken 35 minutes before the start of class.

Class starting to fill up early, ahead of Day 3 of #FOR577, here at #DFIRCON Miami.

Today starts with the FHS and how we can threat hunt it, then moves to the magic of logs and the journal.

#Linux #infosec ##cybersecurity #dfir

13 1 0 0
Post image

Ten minutes until the start of #FOR577, the Linux IR course, here in sunny Miami!

Super excited to get into the training week after a fantastic #DFIRCon yesterday.

#infosec #cybersecurity

24 1 1 0
Post image

SANS DFIRcon presenter's dinner picture.
Hanging out with Korstiaan Stam, Ian Whiffin, Brian Maloney and others.

I'm up at 1 PM leading a workshop on the LEAPPs framework. Hope to make a new Android Bluesky artifact parser with the class.

#DFIRCon #DigitalForensics #MobileForensics

10 0 3 0

ODE update. Centers around the ODL logs. Better parsing of v3 logs. Distinguishes which key was used to decrypt the log entries. This helps to identify the difference between vault and general logs. Last update before #DFIRCON

github.com/Beercow/OneDriveExplorer...

0 1 0 0