DFIR
1 Nov 2024
Finding the LNK: Techniques and methodology for advanced analysis
Advanced LNK analysis with Velociraptor, covering shortcut structures, suspicious fields, and useful clustering points for DFIR and CTI workflows.
Published at Rapid7 (opens in a new tab)
23 Jul 2020
Windows IPSEC for endpoint quarantine
Build and deploy Windows IPsec policies for endpoint quarantine through Velociraptor, with containment requirements and policy removal considerations.
8 Dec 2019
Local Live Response with Velociraptor ++
A historical walkthrough of bundling Velociraptor with WinPMem and Autoruns for local triage. This approach was superseded by the GUI collector builder.
10 Nov 2019
Live response automation with Velociraptor
A historical walkthrough of automating Velociraptor collections and post-processing through its API. The examples predate the current API.
9 Jun 2019
Examine how Office 365 inbox rules can be hidden, how rule properties are modified, and methods for detecting the changes.
7 Apr 2019
Build modular live response scripts with Invoke-LiveResponse, including custom collection logic and support for legacy PowerShell.
18 Feb 2018
Investigate Microsoft BITS job artefacts, collection methods and event logs to identify suspicious transfers and persistence.
14 Jan 2018
Collect live response data and raw files over WinRM with Invoke-LiveResponse and PowerForensics. Covers setup, collection modes and forensic footprint.
12 Jan 2017
PowerShell Remoting and Incident Response
Use PowerShell remoting and WinRM for incident response, with setup examples, collection options and operational considerations.