Renzon Profile picture
IR/Forensics @Unit42_Intel | Co-Founder @guidemtraining | Contributor/Analyst @TheDFIRReport | CTF member @_hackstreetboys
Nov 23, 2021 8 tweets 4 min read
1\ #dfirtips #dfir #infosec

Windows Event Logs can be daunting especially if it's a lot. No one can actually sit in front of their computer to check each of those logs one by one thru a manual approach. Here are some of the newest EVTX tools that can really save our lives as IR 2\ #Zircolite can be very useful where you can use your favorite sigma rules to detect bad stuff

github.com/wagga40/Zircol…
Nov 20, 2021 4 tweets 2 min read
Dealing with a bunch of memory #forensics lately so I just dump fairly new tools that are useful to all #dfir #incidentresponse out there:
MemProcFS - convenient and easy to use
BulkExtractor - extracts everything into a text file and grep it
SuperMem - CS tool for quick triage MemProcFS - github.com/ufrisk/MemProc…