Skip to content

Blog

Write-ups on digital forensics, incident response and memory analysis. Browse by topic with the categories in the sidebar, or subscribe via RSS to hear about new posts.

Cipher (Anti-forensics)

Something I came across recently in an incident response engagement was the potential use of "Cipher.exe". Let's take a look at how it works. The testing site is on an exFAT USB but in-depth analysis regarding the exFAT process of deleting files etc will not be discussed today but more so focussed on what Cipher.exe does to the file instead.

File Carving

File carving refers to a process used in Digital Forensics to recover data from a file system which has typically been deleted. File carving can be automated using software or done so manually. The sign of a good Digital Forensics practitioner is the ability to do this manually or at the minimum understand how this process is carried out when using forensic programs that can do it for you.

You've been hit, popped or breached?

It's only a matter of time before you are involved with a cybersecurity incident. That's not fear-mongering, that's the truth. Businesses and organisations that respect this will be at the forefront of planning to prevent it, but even the most prepared are fallible and adversaries are evolving on a day-to-day basis.