<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DFIR on Matthew Green | DFIR, Threat Intelligence &amp; Research</title><link>https://dfir.au/areas/dfir/</link><description>Recent content in DFIR on Matthew Green | DFIR, Threat Intelligence &amp; Research</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Fri, 01 Nov 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://dfir.au/areas/dfir/index.xml" rel="self" type="application/rss+xml"/><item><title>Finding the LNK: Techniques and methodology for advanced analysis</title><link>https://dfir.au/posts/2024/finding_the_lnk/</link><pubDate>Fri, 01 Nov 2024 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2024/finding_the_lnk/</guid><description>Advanced LNK analysis with Velociraptor, covering shortcut structures, suspicious fields, and useful clustering points for DFIR and CTI workflows.</description></item><item><title>Windows IPSEC for endpoint quarantine</title><link>https://dfir.au/posts/2020/ipsec/</link><pubDate>Thu, 23 Jul 2020 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2020/ipsec/</guid><description>Build and deploy Windows IPsec policies for endpoint quarantine through Velociraptor, with containment requirements and policy removal considerations.</description></item><item><title>Local Live Response with Velociraptor ++</title><link>https://dfir.au/posts/2019/local_liveresponse_with_vr/</link><pubDate>Sun, 08 Dec 2019 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2019/local_liveresponse_with_vr/</guid><description>A historical walkthrough of bundling Velociraptor with WinPMem and Autoruns for local triage. This approach was superseded by the GUI collector builder.</description></item><item><title>Live response automation with Velociraptor</title><link>https://dfir.au/posts/2019/liveresponse_with_vr/</link><pubDate>Sun, 10 Nov 2019 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2019/liveresponse_with_vr/</guid><description>A historical walkthrough of automating Velociraptor collections and post-processing through its API. The examples predate the current API.</description></item><item><title>O365: Hidden InboxRules</title><link>https://dfir.au/posts/2019/o365_hiddenrules/</link><pubDate>Sun, 09 Jun 2019 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2019/o365_hiddenrules/</guid><description>Examine how Office 365 inbox rules can be hidden, how rule properties are modified, and methods for detecting the changes.</description></item><item><title>Live Response Script Builder</title><link>https://dfir.au/posts/2019/invoke-liveresponse_builder/</link><pubDate>Sun, 07 Apr 2019 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2019/invoke-liveresponse_builder/</guid><description>Build modular live response scripts with Invoke-LiveResponse, including custom collection logic and support for legacy PowerShell.</description></item><item><title>Sharing my BITS</title><link>https://dfir.au/posts/2018/sharing_my_bits/</link><pubDate>Sun, 18 Feb 2018 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2018/sharing_my_bits/</guid><description>Investigate Microsoft BITS job artefacts, collection methods and event logs to identify suspicious transfers and persistence.</description></item><item><title>Invoke-LiveResponse</title><link>https://dfir.au/posts/2018/invoke-liveresponse/</link><pubDate>Sun, 14 Jan 2018 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2018/invoke-liveresponse/</guid><description>Collect live response data and raw files over WinRM with Invoke-LiveResponse and PowerForensics. Covers setup, collection modes and forensic footprint.</description></item><item><title>PowerShell Remoting and Incident Response</title><link>https://dfir.au/posts/2017/powershell_remoting_ir/</link><pubDate>Thu, 12 Jan 2017 12:00:00 +1000</pubDate><guid>https://dfir.au/posts/2017/powershell_remoting_ir/</guid><description>Use PowerShell remoting and WinRM for incident response, with setup examples, collection options and operational considerations.</description></item></channel></rss>