<?xml version="1.0" encoding="UTF-8" ?> <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/"> <channel> <title>Sleuthifer</title><description>Notes on digital forensics, incident response, memory analysis and KQL for Sentinel.</description><link>https://sleuthifer.nz/</link><atom:link href="https://sleuthifer.nz/feed_rss_created.xml" rel="self" type="application/rss+xml" /> <language>en</language> <pubDate>Tue, 29 Sep 2026 10:56:43 -0000</pubDate> <lastBuildDate>Tue, 29 Sep 2026 10:56:43 -0000</lastBuildDate> <ttl>1440</ttl> <generator>MkDocs RSS plugin - v1.19.0</generator> <image> <url>https://sleuthifer.nz/assets/images/logo.png</url> <title>Sleuthifer</title> <link>https://sleuthifer.nz/</link> </image> <item> <title>Cipher (Anti-forensics)</title> <description>How Cipher.exe /w overwrites deleted data, tested on a USB drive and checked in FTK Imager.</description> <link>https://sleuthifer.nz/blog/cipher/</link> <pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate> <source url="https://sleuthifer.nz/feed_rss_created.xml">Sleuthifer</source><guid isPermaLink="true">https://sleuthifer.nz/blog/cipher/</guid> <enclosure url="https://sleuthifer.nz/assets/images/social/blog/cipher.png" type="image/png" length="53410" /> </item> <item> <title>File Carving</title> <description>File carving concepts (sectors, clusters, file size and fragmentation), then manually carving a deleted file from a FAT32 file system with FTK Imager.</description> <link>https://sleuthifer.nz/blog/file-carving/</link> <pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate> <source url="https://sleuthifer.nz/feed_rss_created.xml">Sleuthifer</source><guid isPermaLink="true">https://sleuthifer.nz/blog/file-carving/</guid> <enclosure url="https://sleuthifer.nz/assets/images/social/blog/file-carving.png" type="image/png" length="50484" /> </item> <item> <title>FTK Imager</title> <description>An intro to FTK Imager, then creating and verifying an E01 forensic image of a USB drive.</description> <link>https://sleuthifer.nz/blog/ftk-imager/</link> <pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate> <source url="https://sleuthifer.nz/feed_rss_created.xml">Sleuthifer</source><guid isPermaLink="true">https://sleuthifer.nz/blog/ftk-imager/</guid> <enclosure url="https://sleuthifer.nz/assets/images/social/blog/ftk-imager.png" type="image/png" length="44037" /> </item> <item> <title>Part 1: Memory and Volatility</title> <description>An introduction to examining RAM with volatility</description> <link>https://sleuthifer.nz/blog/part1-memory-and-volatility/</link> <pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate> <source url="https://sleuthifer.nz/feed_rss_created.xml">Sleuthifer</source><guid isPermaLink="true">https://sleuthifer.nz/blog/part1-memory-and-volatility/</guid> <enclosure url="https://sleuthifer.nz/assets/images/social/blog/part1-memory-and-volatility.png" type="image/png" length="50910" /> </item> <item> <title>PowerShell History</title> <description>Where to find the PowerShell history file.</description> <link>https://sleuthifer.nz/blog/powershell-history/</link> <pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate> <source url="https://sleuthifer.nz/feed_rss_created.xml">Sleuthifer</source><guid isPermaLink="true">https://sleuthifer.nz/blog/powershell-history/</guid> <enclosure url="https://sleuthifer.nz/assets/images/social/blog/powershell-history.png" type="image/png" length="43685" /> </item> <item> <title>Threat Intelligence &amp;amp; Intrusion Analysis</title> <description>Threat intelligence feeds, IoCs and IoAs, the Pyramid of Pain, the Cyber Kill Chain, MITRE ATT&amp;CK and the Diamond Model.</description> <link>https://sleuthifer.nz/blog/threat-intelligence/</link> <pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate> <source url="https://sleuthifer.nz/feed_rss_created.xml">Sleuthifer</source><guid isPermaLink="true">https://sleuthifer.nz/blog/threat-intelligence/</guid> <enclosure url="https://sleuthifer.nz/assets/images/social/blog/threat-intelligence.png" type="image/png" length="60000" /> </item> <item> <title>Wireshark</title> <description>An intro to Wireshark, then using Protocol Hierarchy and a DHCP filter to identify a laptop, and following a TCP stream to decode an SMTP login.</description> <link>https://sleuthifer.nz/blog/wireshark/</link> <pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate> <source url="https://sleuthifer.nz/feed_rss_created.xml">Sleuthifer</source><guid isPermaLink="true">https://sleuthifer.nz/blog/wireshark/</guid> <enclosure url="https://sleuthifer.nz/assets/images/social/blog/wireshark.png" type="image/png" length="49690" /> </item> <item> <title>You&#39;ve been hit, popped or breached?</title> <description>A quick and frank article on what should happen if you are unfortunate to be involved in a cyber security incident.</description> <link>https://sleuthifer.nz/blog/youve-been-hit-popped-or-breached/</link> <pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate> <source url="https://sleuthifer.nz/feed_rss_created.xml">Sleuthifer</source><guid isPermaLink="true">https://sleuthifer.nz/blog/youve-been-hit-popped-or-breached/</guid> <enclosure url="https://sleuthifer.nz/assets/images/social/blog/youve-been-hit-popped-or-breached.png" type="image/png" length="55663" /> </item> </channel> </rss>