Michael
Digital Forensic Survival Podcast
Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.
Author
Michael
Category
Podcast website
Latest episode
Sep 9, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
DFSP # 399 - Lateral Movement Failed Logon Events 10.10.2023 13:04
Finding and analyzing failed logons sometimes is just as important as finding suspicious, actual logon activity. Like anything, context is important. Old logon records offer an opportunity to identify not only suspicious activity, but perhaps attempted activity by an attacker. A standard move in the attack chain is to compromise an account and use it to move within the breached environment. Howeve...
DFSP # 398 - OODA & JOHARI 03.10.2023 16:06
This week I will discuss the use of the OODA loop and JOHARI window in security incident response investigations. These two frameworks are designed to help organizations quickly and effectively respond to security incidents, and can be used in combination to enhance incident response capabilities....
DFSP # 397 - Linux Home Directory Files for DFIR 26.09.2023 20:49
This week I'm talking about the linux file system from the point of view of a forensic analyst. In general, it's a good idea to have a solid working knowledge of the linux file system so you understand what directories hold what artifacts… Or if you're looking for a specific category of artifact, you at least have an idea of where you may find it. I will cover the home directory this week and brea...
DFSP # 396 - URL Leak 19.09.2023 18:47
This week I will talk about investigating data spill cases involving exposed URLs. This is a typical privacy investigation many incident response teams handle and I thought it would be useful to go over some standard guidelines for handling such cases. To be effective with these investigations you need to know how to determine liability and responsibility, a little Google foo, and a number of odds...
DFSP # 395 - Lateral Movement and Admin Logons 12.09.2023 18:38
This week is on lateral movement detection techniques. Inspecting Domain Admin account logons is a key component to lateral movement triage. Admin accounts are sought after by attackers for their elevated privileges. Evidence is often left behind both on the targeted system and on the domain controller. Both these factors provide protection opportunity through Windows event log analysis. I’ll brea...
DFSP # 394 - Functional Documentation 05.09.2023 15:49
This week I want to talk about the value of having functional documentation for your organization, or, at least for your team. Functional documentation means you have thoughtful and up-to-date incident run books, and play books that provide utility and usefulness for a responder. Without such documentation, you are always in danger of some dangerous pitfalls, some of which I'll discuss. This episo...
DFSP # 393 - Linux Subsystems for Windows 29.08.2023 24:38
The linux subsystem for windows, create both opportunity and challenges for forensic analysts. It makes Windows an excellent platform for multi platform forensic analysis tasks, allowing it to take it vantage of the many many Linux tools available. The challenges are foreseeable, you have Linux artifacts, now commingled on a Windows platform, which makes forensic analysis that much more difficult...
DFSP # 392 - Simulation Training 22.08.2023 20:52
This week I'm going to talk about tabletop exercises as part of a security training program. I feel that there is too much focus on technical skill training and not enough focus on actual incident management training in the industry. There are plenty of highly skilled professionals that can do DFIR work… However, a roadblock, many organizations and practitioners encounter is in the struggle of how...
DFSP # 391 - Investigation Lifecycle 15.08.2023 26:26
This week I'm talking about The NIST (National Institute of Standards and Technology) investigation lifecycle. The NIST investigation lifecycle encompasses a series of well-defined steps, starting from problem identification and scoping, through data collection and analysis, to the formulation of conclusions and recommendations. This comprehensive framework ensures that investigations conducted by...
DFSP # 390 - SSH Triage 08.08.2023 17:26
This week I'm talking about linux forensic triage strategy. In particular, I'm covering SSH. SSH traffic comes up in many different types of investigations. For that reason, it is a common and standard artifact every examiner should be familiar with. I will provide you the artifact background and the triage strategy…..
DFSP # 389 - $Usnrl 01.08.2023 15:16
The USN Journal, also known as the Update Sequence Number Journal, is a feature of the Windows operating system that serves as a record of changes made to files and directories on a disk volume. It provides valuable information and insights into file system activities, which can aid investigators in reconstructing events, understanding system behavior, and uncovering evidence. This week I break do...
DFSP # 388 - Web 3.0 Talk with SUMURI 25.07.2023 38:00
This week Jason Roslewicz from SUMURI returns for some web 3.0 and virtual reality talk.
DFSP # 387 - Network Share Modifications 18.07.2023 20:25
This week I talk about adding, modifying, and removing network shares through the lens of detecting lateral movement.
DFSP # 386- The Three Task Hosts 11.07.2023 12:07
This week I break down the three Windows task hosts from a DFIR point of view.
DFSP # 385 - Network Share Access 04.07.2023 19:06
This week I talk about network share access events and lateral movement detection.
DFSP # 384 - Cloud Talk with SUMURI 27.06.2023 1:16:22
This week Jason Roslewicz from SUMURI returns for some cloud talk.
DFSP # 383 - WMI Exploitation 20.06.2023 20:23
This week I talk about the exploitation of the Windows Management Instrumentation application.
DFSP # 382 - Protocol Buffers 13.06.2023 40:30
This week Chris Currier and I talk about mobile forensics and protocol buffers.
DFSP # 381 - Spoliation 06.06.2023 16:02
This week I cover Windows events commonly associated with data spoliation and insider threats.
DFSP # 380 - Ransomware Talk with SUMURI 30.05.2023 58:27
This week Jason Roslewicz from SUMURI returns for some ransomware talk.
DFSP # 379 - New Process Creation 23.05.2023 18:10
This week I Cover my all-time favorite Windows event, security event 4688: new process creation. If you do windows, incident, response, forensics, this is a must-know know artifact.
DFSP # 378 - SVCHOST Revisited 16.05.2023 18:05
This week I talk about SVCHOST; how it fits into the Windows operating system, and how to think about it from a DFIR point of view.
DFSP # 377 - Interview with Yugal Pathak 09.05.2023 39:49
This week I talk with Interview with Yugal Pathak about organizational forensic readiness.
DFSP # 376 - Zero-Day and DFIR 02.05.2023 25:15
This week I talk about the role and typical responsibilities DFIR professionals may be called up to take to assist with a zero-day response.
DFSP # 375 - More AI with SUMURI 25.04.2023 30:00
This week Jason Roslewicz from SUMURI returns to talk more about AI issues.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.