DFIR

All articles

1 Nov 2024

Finding the LNK: Techniques and methodology for advanced analysis

Advanced LNK analysis with Velociraptor, covering shortcut structures, suspicious fields, and useful clustering points for DFIR and CTI workflows.

Published at Rapid7 (opens in a new tab)

23 Jul 2020

Windows IPSEC for endpoint quarantine

Build and deploy Windows IPsec policies for endpoint quarantine through Velociraptor, with containment requirements and policy removal considerations.

8 Dec 2019

Local Live Response with Velociraptor ++

A historical walkthrough of bundling Velociraptor with WinPMem and Autoruns for local triage. This approach was superseded by the GUI collector builder.

10 Nov 2019

Live response automation with Velociraptor

A historical walkthrough of automating Velociraptor collections and post-processing through its API. The examples predate the current API.

9 Jun 2019

O365: Hidden InboxRules

Examine how Office 365 inbox rules can be hidden, how rule properties are modified, and methods for detecting the changes.

7 Apr 2019

Live Response Script Builder

Build modular live response scripts with Invoke-LiveResponse, including custom collection logic and support for legacy PowerShell.

18 Feb 2018

Sharing my BITS

Investigate Microsoft BITS job artefacts, collection methods and event logs to identify suspicious transfers and persistence.

14 Jan 2018

Invoke-LiveResponse

Collect live response data and raw files over WinRM with Invoke-LiveResponse and PowerForensics. Covers setup, collection modes and forensic footprint.

12 Jan 2017

PowerShell Remoting and Incident Response

Use PowerShell remoting and WinRM for incident response, with setup examples, collection options and operational considerations.