Category: Windows Incident Response

LNK Metadata

I ran across this Ctrl-Alt-Intel blog post today, which discusses RustGate v2, and noticed that for all of what was addressed in the blog, there wasn’t a…

Burn Out, Or Fade Away

I didn’t start out in threat intel. I didn’t start my career in cybersecurity in DF/IR work. I started doing vulnerability assessments using commercial…

LNK Metadata

I ran across this Ctrl-Alt-Intel blog post today, which discusses RustGate v2, and noticed that for all of what was addressed in the blog, there wasn’t a…

True Lies

Many times within the industry, we hear things stated repeatedly, or with authority, or both, and simply accept them as fact, as being true. However, a…

Finding Initial Access

I recently ran across a comment from a SOC manager on social media that said, “Finding initial access is difficult.” I thought about it for a moment, and had to ask, “why is that?” For context, I transitioned from military…

Rigor in Threat Intel

I’m just going to say it. IOCs are not “threat intel”.  Lists of IP addresses and domain names, without context, are data points and information, not “intel”. Threat intel is based on patterns developed from the accumulation/aggregation of data. In…

LNK Files in CTI

There’s a good bit of file analysis that goes into CTI reports, including (but not limited to) malware analysis. But for some reason, not all files appear to be worthy of parsing and analysis. We also tend to see in-depth…

Consistency

I’ve worked a lot of places over the years, all for varying lengths of time. While this worked against me in the early days, with potential employers wondering why I didn’t stay longer at my previous employer, and wondering how…

Timelines

I like timelines, particularly when it comes to forensic investigations.  There I said it. The first step to addressing an issue is admitting that you have a problem. I’ve been creating timelines since about 2008-ish, or so. I have a…

Links

I’ve been saving some things up in this draft blog post, adding new things, removing some older stuff that, after a few days, didn’t quite hit the same as when I first read them. Most who know me know that…

LNK Files

I know what you’re thinking…”LNK files? Again? Dude, you are like a dog with a bone!” Yes. Yes, I am. But in this case, I’ll keep it short. I’ve posted a lot…a LOT…about LNK files, and there’s very likely more…

Devices

Something I learned very early on as a DF/IR consultant was that you’re likely never going to run into a perfect environment as an on-call responder. In fact, the best you can hope for is an environment with the default logging,…

Devices

Something I learned very early on as a DF/IR consultant was that you’re likely never going to run into a perfect environment as an on-call responder. In fact, the best you can hope for is an environment with the default logging,…

Views on AI & the Anthropic Report

There’s been a lot of chatter over the use of AI in various fields, and because it’s my professional focus, I’m most interested in how it’s used in cybersecurity. Now, that doesn’t mean that I’m not aware of how it’s…

Views on AI & the Anthropic Report

There’s been a lot of chatter over the use of AI in various fields, and because it’s my professional focus, I’m most interested in how it’s used in cybersecurity. Now, that doesn’t mean that I’m not aware of how it’s…

What’s on your clipboard?

One of the fascinating aspects of Windows systems, from a DF/IR perspective, for me has been the clipboard. Notice I said, “one of”, rather than “the”…that’s because there are a lot of fascinating aspects of Windows systems when it comes…

Questions I’ve Been Asked

Sometimes I’ll get questions via different routes…webinars or podcasts, via social media, DM, or even email. Getting questions is good, because it keeps me aware that I’m in somewhat of a bubble, given the work I do and the environment…

Grab Bag

This started out as a bit of an end-of-the-year grab bag of posts, but I don’t like simply linking to things, dropping links with no explanation as to why; instead, I’d rather share the why behind what I found interesting about the…

Windows Defender Support Logs

I ran across a LinkedIn post the other day that  mentioned using Windows Defender Support Logs (actually, I think the post referred to them as “diagnostic” logs). These logs are found in the following folder: C:\ProgramData\Microsoft\Windows Defender\Support\  …and follow the…