There is a hymn that we sing at church. The first line of the song alone is a message unto itself. “Because I have been given much, I too must give.” This is a message that I try to live up to. I know I’m not able to help everyone, but I can always do […]
On Friday July 17, 2020 the annual Forensic 4:cast Awards took place at the SANS DFIR Virtual Summit. The video for the awards can be found below.
Last week I had the privilege of addressing the attendees of the 2020 SANS DFIR Summit. I spoke about the need to reach out and help those not as fortunate as ourselves. Please take 25 minutes to watch the presentation and then do something about it.
Yesterday I came to you with a request to buy and read my father’s book. It was 100% for charity and for your own edification. Today’s request is somewhat less altruistic. COVID-19 screwed up a lot of people’s plans. SANS moved from live, in-person classes to the “Live Online” format very quickly. So quickly and […]
I’ve been a digital forensic investigator for several years, I’ve been nominated to act as an expert witness as occasion permits. I’ve testified in court and stood up to some particularly rigorous questioning at times. This, I’m sure you’ve all heard before. What you may not know is that expert witness work is in my […]
Greeting all, what an interesting 2020 we’ve had so far. I trust that you and your family are well and safe. The nominees have been counted and I’m very proud to announce the voting for the 2020 Forensic 4:cast Awards is now open. Please take the time to post your votes for your favorites. Also, […]
Is it really that time of year again already? Yes! The nominations for the 2020 Forensic 4:cast Awards are open! I’ve added one new category. Please either watch the video or read below for the category descriptions. Note that awards will be announced at the SANS DFIR Summit in Austin, TX on July 16. Winners […]
For those of you that know me personally, I try very hard to not minimize other people’s work and accomplishments. In fact, I revel in others’ joy when they achieve things. So, this post will be somewhat out of character for me. I’ve been conducting forensic investigations for around fourteen years. During that time I’ve […]
Hello everyone. It’s that magical time of the year once more. The nominations have been counted and the final, privileged few have made it to the voting round. Few of things I need to address: I dropped a category. Very few nominations were cast in the Threat Intel category, so I decided to let that […]
I’ve been revisiting things in Windows 10 recently. We’ve seen a few things change that we have taken for granted in previous versions so I’ve been investigating things. In my most recent efforts, I’ve come to the RecentDocs key in the Windows registry. For those that are unaware, this key lies in each user’s NTUSER.DAT […]