, 6 tweets, 1 min read
My Authors
Read all threads
A #DFIR analysis series of thoughts:

Individual artifacts (a Registry key or value, a Windows Event Log record, etc.) may be a high fidelity indicator, but lack the context we usually find in artifact clusters. Artifact clusters, or "clusters of clusters", are
what we often refer to as "behaviors", particularly when they are a clear demonstration of "humanness".

During active IR, we have to be aware of artifact or evidence "oxidation", as the elements of the clusters begin to dissolve over time. (2/n)
Log entries and deleted files are overwritten, artifacts are updated, OS and application updates are applied, etc. All of this occurs due to the passage of time as the system continues to operate.

Not grasping the full scope of the artifact clusters, and understanding (3/n)
the issue of evidence oxidation can lead to incorrect or "off" findings, as unrealized gaps in analysis are plastered over with assumption and guesswork.

As responders/analysts, we have to remember that the finding we provide are very likely going to be used by someone (4/n)
to make critical business decisions regarding risk. Just as likely, those decisions may also determine other outcomes, such as fines, guilt or innocence, etc. (5/5)
Addendum: I posted these thoughts in hopes of generating meaningful, purposeful engagement.

If you "like" it, share why.
Missing some Tweet in this thread? You can try to force a refresh.

Enjoying this thread?

Keep Current with K:\eydet89

Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!