Michael
Digital Forensic Survival Podcast
Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.
Author
Michael
Category
Podcast website
Latest episode
Sep 9, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
DFSP # 299 - Malicious Powershell with Blumira 09.11.2021 20:07
Amanda Berlin of Blumira speaks on malicious Powershell attacks and defense techniques.
DFSP # 298 - Mac Forensics with SUMURI 02.11.2021 32:20
This week SUMURI's Steve Whalen (a.k.a. 'MacBoy') talks Mac forensics.
DFSP # 297 - Nested Groups 26.10.2021 10:38
This week I’m talking about Nested Groups and the risk they pose for security. Built-in to the functionality of Active Directory is the ability to attach a group to another group. While this has advantages for account administration across an organization, it also offers attackers opportunity if certain precautions are not taken. This week I’ll break down Nested Groups in DFIR terms, talk about ho...
DFSP # 296 - Case Study Turla-Comrat 19.10.2021 19:30
This week is a case study where we look at an actual attack strategy and compared it against standard triage methods to see how well they hold up. The Turla group using ComRat malware is our case example, let’s see if standard triage techniques can save the day.
DFSP # 295 - Ransomware with Blumira 12.10.2021 32:21
Matt Warner, Blumira CTO and Co-Founder, talks ransomware investigations.
DFSP # 294 - CSA Cloud Threats 7 05.10.2021 10:14
This week is a continuation of the threats to cloud computing miniseries. We are stepping through the top 11 threats to cloud computing as identified by the Cloud Security alliance. When you are protecting cloud assets or investigating breaches of cloud assets, there is a lot to keep in mind. You must remember the standard security infrastructure, the new cloud infrastructure as well as any change...
DFSP # 293 - Case Study: Ransomware 28.09.2021 13:30
This week is a case study that demonstrates how fundamental DFIR triage methods can detect advanced attacks. Examiners, especially newer examiners, should find confidence in the fact that standard triage techniques have such a powerful impact on security investigations.
DFSP # 292 - Top Cloud Threats with Blumira 21.09.2021 23:26
This week Nato Riley from Blumira pays a visit to talk about the top threats to cloud computing.
DFSP # 291 - Lateral MM Fast Triage 3 14.09.2021 14:08
This week we continue with the Windows fast triage series and talk about lateral movement evidence that may be found in admin shares event records. Four different types of logs are covered, each containing different information for triage purposes.
DFSP # 290 - Mac Training with SUMURI 07.09.2021 20:44
This week SUMURI's Steve Whalen (a.k.a. 'MacBoy') and Dave Melvin talk about the latest in Mac training and certification. Learn the advantages of vendor neutral training and how to prioritize it in your own training regiment.
DFSP # 285 - Linux Malware Triage 03.08.2021 20:55
This week I wanted to take a break from Windows forensics and talk about Linux malware triage. The Linux platform offers forensic analysts the opportunity to do a very decent job performing malware triage. What I mean by this is that you do not need any special tools installed, all you essentially need is the knowledge of a handful of commands in the ability to make sense of the output. Armed with...
DFSP # 284 - Fast Triage case study: non-Windows core processes 27.07.2021 15:40
This week we’re going to take a look at how standard triage methodology can detect advanced attack techniques. Even as a newer examiners, if you learn the standard triage methods that I have covered in the fast triage series, you will find the skills provide ample opportunity to detect all sorts attack activity-even very advanced attack activity. This is because there are natural chokepoints in th...
DFSP # 264 - Golden SAML 09.03.2021 12:37
This week is about preparing for Golden SAML attacks for both Incident Response and Threat Hunting.
DFSP # 262 - Security Theatre 23.02.2021 17:51
This week is about theatrics in security and how to avoid the trap.
DFSP # 261 - Wincore Processes Revisited part 2 16.02.2021 15:12
This week I revisit Windows Core Processes and the triage methods to apply to them.
DFSP # 260 - Learn from the Red Team 09.02.2021 14:43
This week I talk about vulnhub, a free resource to practice ethical hacking skills and sharpen your DFIR skills.
DFSP # 259 - Wincore Processes Revisited part 1 02.02.2021 20:19
This week I revisit Windows Core Processes and the triage methods to apply to them.
DFSP # 258 - Network Triage Part 4 26.01.2021 15:00
This week is the fourth part of the Network-Fast-Triage mini-series. In this installation I cover triage techniques for Windows event logs that record blocked network activity.
DFSP # 257 - Supply Chain Attacks 19.01.2021 17:13
This week is about supply chain security posture from a DFIR point-of-view.
DFSP # 256 - Kernel Process Masquerading 12.01.2021 9:04
This week I go over a method to detect kernel process masquerading on Linux systems.
DFSP # 255 - The Worship of Intelligence in Tech 05.01.2021 25:49
This week I interview author Shawn Livermore about the myth of the "tech-genius."
DFSP # 253 - Network Triage Part 2 22.12.2020 15:01
This week is the second part of the Network-Fast-Triage mini-series. In this installation I cover triage techniques for Windows event logs that record network connections.
DFSP # 252 - Werfault 15.12.2020 14:42
This week I cover triage techniques for werfault.exe. The process does not have the best documentation which makes it a challenge to triage.
DFSP # 251 - The Rise of Crypto SIM Swapping 08.12.2020 32:14
This week I interview Haseeb Awan, CEO of EFANI, about the rise of SIM swapping attacks. Haseeb explains the attack, how attackers carry it out, and provides some mitigation strategies.
DFSP # 250 - Network Triage Part 1 01.12.2020 14:52
This week is the first part of the Network-Fast-Triage mini-series. The first installation is the network investigation primer.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.