Michael
Digital Forensic Survival Podcast
Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.
Author
Michael
Category
Podcast website
Latest episode
Sep 9, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
DFSP # 324 - Malware Triage Part 1 03.05.2022 16:09
This week of talking malware fast triage. These are the techniques that are short of malware reverse engineering and allow analysts to identify malware and also get a sense of what it is does. This is a necessary skill set for all DFIR professionals as you typically deal with malware and you need a way to do some basic forensics on it for context to advance your investigation. This is going to be...
DFSP # 323 - SRUM 26.04.2022 13:11
This week I’m talking about SRUM, a Windows artifact that you don’t hear that much about. It has a lot of great potential as evidence and it is something worth the time to check it out and see how it fits into your daily DFIR work.
DFSP # 322 - Live evidence integrity 19.04.2022 17:30
This week is some thoughts on live evidence integrity. Years ago evidence validation was fairly standard with few exceptions. Nowadays it’s more of a challenge when considering live evidence collections either on scene, remotely or even in lab environments where physical level access to your evidence is becoming more the exception. It is something that needs to be part of your collection process a...
DFSP # 321 - URL Leaks 12.04.2022 16:30
This week I will talk about investigating data spill cases involving exposed URLs. This is a typical privacy investigation many incident response teams handle and I thought it would be useful to go over some standard guidelines for handling such cases. To be effective with these investigations you need to know how to determine liability and responsibility, a little Google foo, and a number of odds...
DFSP # 320 - Lateral MM and Event Logs 05.04.2022 13:11
This week I’m going to cover detecting lateral movement using Windows event logs. This is not the Windows fast triage method I covered in previous episodes. This is more in-depth and focuses on specific attack tools and strategies seen in actual cases. Going into this level of detail is beyond the scope of a typical episode, however there is some research that has very granular details on the tool...
DFSP # 319 - Shellbags 29.03.2022 15:07
This week is a back to basics episode where I am going to cover Windows shellbags. This is a core Windows artifact that gets included in pretty much most every file use and knowledge investigation or any investigation where you’re looking to tie a specific account to directory access activity. Like most Windows artifacts you must know how user interaction affects the artifact in order to properly...
DFSP # 318 - Rust and Chainsaw 22.03.2022 15:38
This week I am talking about a program language called rust and the advantages it has for DFIR analyst. I’m also covering Chainsaw, a toolset that you can use for Windows event log analysis.
DFSP # 317 - UserAssist 15.03.2022 17:36
This week it’s back to basics with a Windows artifact for tracking program execution. I’m covering the user assist key which is a mainstay for both live triage and dead box forensics. This artifact is useful for profiling system usage, identifying malware, and general file use and knowledge applications. There are some caveats you need to be aware of and in this episode I’m covering five differen...
DFSP # 316 - Cloud Traffic Security 08.03.2022 12:55
This week I am covering how different common protocols are secured in the cloud. Part of your effectiveness as a security analyst is your knowledge and understanding of how environments work in a typical scenario. I know that all environments are different but there is some foundational knowledge that you can learn that will be useful no matter what environment you’re working. My goal with this ep...
DFSP # 315 - ARTHIR 01.03.2022 12:35
This we can talk about Arthir, an open source platform for windows incident response and threat hunting.
DFSP # 314 - Future of Cyber Security 22.02.2022 44:16
This week Max Lamothe-Brassard talks about the future of cyber security.
DFSP # 313 - Shimcache and Amcache 15.02.2022 18:28
This week is a back to basic episode featuring Shimcache and Amcache. Learn what they are, why they are important to many investigations and the pitfalls to avoid.
DFSP # 312 - Cloud Network Security Services 08.02.2022 15:56
This week is about Cloud Network Security Services.
DFSP # 311 - Data Spoliation Fast Triage 01.02.2022 13:08
This week we continue with the Windows fast triage series and talk about data spoliation detection.
DFSP # 310 - Cloud Network Segmentation 25.01.2022 13:11
This week is about cloud network segmentation. Network segmentation has security advantages, and that’s regardless of whether or not security is the intention. There are some big differences between traditional on-prem network segmentation and cloud infrastructure segmentation. As a DFIR practitioner, knowing the difference is vital for your incident response preparedness. This week I will break i...
DFSP # 309 - Insider Threats 18.01.2022 21:42
This week I cover insider threat, which is sort of a gray area between traditional investigations and DFIR investigations.
DFSP # 308 - Cloud Access Controls 11.01.2022 16:45
This week I’m talking about identity access controls commonly encountered in cloud environments. These come up during DFIR investigations and high-level awareness, at the least, is necessary for analysts in order to be effective during investigations. These are the things that may be part of root cause, part of the attack escalation, or part of mitigation will remediation. This week all cover the...
DFSP # 307 - Career Strategy Checkup 04.01.2022 30:21
This week is my advice for conducting a career critique as well as to plan for the future - or at least for 2022. I do this episode every year at this time with the intention of helping newer analysts maximize their efforts to achieve the desired career goals in both the short term and long term.
DFSP # 306 - Lateral MM Fast Triage 5 28.12.2021 11:21
This week we continue with the Windows fast triage series and talk about lateral movement evidence that may be found in DC records.
DFSP # 305 - CSA Cloud Threats 8 21.12.2021 10:13
This week is a continuation of the threats to cloud computing miniseries. We are stepping through the top 11 threats to cloud computing as identified by the Cloud Security alliance. When you are protecting cloud assets or investigating breaches of cloud assets, there is a lot to keep in mind. You must remember the standard security infrastructure, the new cloud infrastructure as well as any change...
DFSP # 304 - Detecting File Poisoning on Linux 14.12.2021 14:28
This week I review a great method to detect file poisoning on Linux using all native commands.
DFSP # 303 - Mac Artifacts with SUMURI 07.12.2021 35:45
This week SUMURI's Steve Whalen (a.k.a. 'MacBoy') talks Mac artifacts
DFSP # 302 - Lateral MM Fast Triage 4 30.11.2021 15:46
This week we continue with the Windows fast triage series and talk about lateral movement evidence that may be found in logon event records.
DFSP # 301 - OSDFCON 2021 23.11.2021 22:21
This week Brian Carrier of Basis Technology joins me to talk about OSDFCon. The DFIR community relies on open source tools and the conference is a great way to get exposure to new tools and to learn how to use them. There's a great lineup this year with something for everyone. Registration is free for everyone.
DFSP # 300 - Case Study Ocean Lotus 16.11.2021 20:37
This week is a case study where we look at an actual attack strategy and compared it against standard triage methods to see how well they hold up. In this episode I break down some attack methods attributed to APT32, also known as Ocean Lotus, and we’ll see how standard triage techniques hold up against the attack chain.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.