Michael

Digital Forensic Survival Podcast

Society EN ↓ 229 episodes

Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.

Author

Michael

Category

Society

Latest episode

Sep 9, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

DFSP # 349 - Registry Modification Events 25.10.2022

This week I talk about how to find evidence of malicious autoruns in the windows registry using Windows event codes.

DFSP # 348 - Root Cause 18.10.2022

This week I talk about strategies to determine root cause early during an investigation.

DFSP # 347 - Weblogs 11.10.2022

This week is a breakdown of HTTP log forensic triage.

DFSP # 346 - Masquerading 04.10.2022

This week I talk about finding evidence of Kernel file masquerading on Linux systems.

DFSP # 345 - AutoRuns 27.09.2022

This week I talk about how to find evidence of malicious autoruns in the windows registry.

DFSP # 344 - Mac Spotlight DB 20.09.2022

This week I talk about the forensic value of the Apple Spotlight DB.

DFSP # 343 - Registry aka The Dungeon Maze 13.09.2022

When you talk autoruns you must talk about the Windows registry. This artifact is very dense and it may be difficult to zero in on the elements that are important for compromise assessment. Given that, I am going to begin the series with a breakdown of the Windows Registry from a DFIR point of view. This is crucial in understanding ...

DFSP # 342 - FLUX It 06.09.2022

This week I talk about the attack methodology known as Fast Flux.

DFSP # 341 - Those other taskers 30.08.2022

This week’s focus is on other scheduled task events useful for DFIR triage.

DFSP # 340 - PSEXEC, ready or not 23.08.2022

This week I talk about a popular Windows utility attackers often exploit.

DFSP # 339 - That SUDO that you do 16.08.2022

This week I breakdown the SUDOERS file for forensic triage.

DFSP # 338 - Taskers 09.08.2022

This week’s focus is on new scheduled tasks, which are a common way of establishing longevity on system. I will have my breakdown of the artifact and how to interpret it for fast analysis coming up….

DFSP # 337 - ResponderCon 02.08.2022

The must-attend event for Cyber First Responders who must detect and deal with ransomware, zero-day events, and more!

DFSP # 336 - BAM! 26.07.2022

This week I talk about the Windows Background Activity Monitor, an artifact that may be used to find evidence of execution.

DFSP # 335 - CRON 19.07.2022

This week I breakdown CRON for the uninitiated.

DFSP # 334 - Service Changes 12.07.2022

This week is about persistence artifacts. Namely the records for when services fail to start, are either started or stopped, have crashed have had their start type changed. Since services are one of the common ways attackers achieve persistence, understanding how these events may be used for triage purposes is very important...

DFSP # 333 - Mac Autoruns 05.07.2022

This week I talk Mac autoruns.

DFSP # 332 - Bash Histories 28.06.2022

This week is about bash history forensics.

DFSP # 331 - New Services 21.06.2022

In the past I’ve talked about fast triage from a high-level, addressing the different artifacts and some interesting elements in each of those artifacts. I decided to start going a bit deeper and focus on one or a few artifacts at a time and really talk about the important details they may record for your investigation and how to interpret that information quickly. I’m going to start with the New...

DFSP # 330 - Certifications 14.06.2022

Every so often I like to revisit certifications. Everyone seems to have their own opinion as to the value of one certification over another, whether or not certifications should carry as much weight as they do, or preference of certain certifications over others, and so on. In this episode I’m sharing my thoughts on the topic as well as how I would approach certifications if I were new in the fiel...

DFSP # 329 - Shellbags 07.06.2022

This week is a back to basics episode where I cover Windows shell bags. This is a core Windows artifact that gets included in pretty much  every file use and knowledge investigation. Any investigation where you’re looking to tie a specific account to directory access activity. Like most Windows artifacts you must know how user interaction affects the artifact in order to properly interpreted as ev...

DFSP # 328 - Linux Executables 31.05.2022

If you are accustomed to Windows forensics you may find you have to shift your way of thinking about executables when you are dealing with a Linux system. Unlike Windows, in Linux there is no fixed file extension to designate an executable. Everything on a Linux system of the file and any file can be executable, so where do you even begin? In this episode I am going to address how to approach Linu...

DFSP # 327 - Persistence Part 1 24.05.2022

One of the first things attackers attempt to accomplish on a compromised system is to establish persistence. Unless you are dealing with a denial of service attack, most other attacker goals are centered on maintaining the degree of control over a compromise system in order to use system resources for things like cryptomining or to maintain a foothold to further an attack strategy. This week I am...

DFSP # 326 - MFT 17.05.2022

This week I’m covering the Master file table as a core forensic artifact for Windows investigations. This artifact has value is both a primary and secondary artifact and offers opportunity to decode evidence in a number of different situations. In this episode I’m covering the forensic basics, some use cases and tools you can use to bring the value of the artifact to its full potential.

DFSP # 325 - Malware Triage Part 2 10.05.2022

This week of talking malware fast triage. These are the techniques that are short of malware reverse engineering and allow analysts to identify malware and also get a sense of what it is does. This is a necessary skill set for all DFIR professionals as you typically deal with malware and you need a way to do some basic forensics on it for context to advance your investigation. This is going to be...

Listen to the Digital Forensic Survival Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.