Made a quick #TIL (thing I learned, things I liked) post for SANS #DFIRSummit 2024 (online last Th & Fri). Thanks to all of the speakers, the SANS summit team, and the organizers for another great conference! https://www.dfirnotes.net/til_dfirsummit_2024/
TIL DFIR Summit 2024 online

TIL DFIR Summit 2024 online

Up next in our #FTSCon speaker lineup: Greg Lesnewich will present “Holding a GRUdge: Phishing Campaigns Outside the Warzone” in the HUNTER track!
 
Register for From The Source, hosted by @volatility, here: https://events.humanitix.com/from-the-source-hosted-by-the-volatility-foundation
 
Stay tuned for more speaker announcements!
 
#dfirsummit
From The Source - Hosted by The Volatility Foundation

From The Source - Hosted by the Volatility Foundation

Theres no better feeling than watching one of your students kill it on stage at a @sansforensics #DFIRSummit!

Dan gave a really cool & interesting talk about drone #DFIR analysis - questions to ask, what data they collect, how to acquire, & deep dived into a DJI Mavic Air 3 & the DJI Fly app 🤘

@sansforensics #DFIRSummit keynote by @robtlee highlighted the rise of #AI and the key to #DFIR moving forwards in the future will be the ability of people to learn & adapt

He gave a list of useful resources to get started & get ahead. Go check them out: https://thegrai.com/wp-content/uploads/2024/08/AI-Resource-Checklist-2.pdf

Super interesting talk by Josh Hickman on artifacts left by Android’s Find My Device feature & paired trackers at @sansforensics #DFIRSummit. I’m frantically scribbling notes of all the files that store data!

Prize bags are ready & waiting for any #GettingStartedInDFIR workshop winners at @sansforensics #DFIRSummit. Come find me at the back of the room 🥳

#DFIR

Working through review of #FOR508 today and getting excited for #DFIRSummit . Logs, sure, great if you have them, but I'm eager to crack into the memory images ( might have already taken a peek 😺)

Just 3hrs to go til the last free workshop in my #GettingStartedInDFIR @sansforensics series! This one’s all about #base64: what it is & how to encode & decode data

Remember, all 5 previous #DFIR workshops are also available at the same time, so you have from 13:00 EDT today til midnight Aug 21st to complete the set; join today’s workshop to get the new event codes - I’ll hand them all out at the start

Also a reminder that if you get the workshop themes and the link between them, find me at either the #DFIRSummit next week or #DFIRSummitEurope in September to get a small prize 🪙

https://www.sans.org/blog/unraveling-the-mysteries-of-digital-forensics-a-blog-on-the-secret-life-of-devices-workshop-series/

Unraveling the Mysteries of Digital Forensics: A Blog on the "Secret Life of Devices" Workshop Series

A blog showcasing a six-part workshop series on unraveling the mysteries of digital forensics

Due to popular demand… I will be re-running Ranges events for ALL of my previous @sansforensics #GettingStartedinDFIR workshops in the run up to the #DFIRSummit

Join the last #DFIR workshop on encoding & decoding Base64 live 13:00-15:00 EDT on Aug 13th. Or you can watch the recording & play along on Ranges.io until midnight on Aug 21st

Sign up here:
https://www.sans.org/webcasts/demystifying-base64-beginners-guide-encoding-decoding/

All of my previous workshops (1-5) will be re-run on Ranges at exactly the same time so you can watch those recordings & play along too.

13:00 EDT August 13th to midnight EDT August 21st 2024

I’ll give out the Ranges event codes at the start of workshop 6 on August 13th

Also, a quick reminder that if you correctly identify the theme for each workshop (excluding workshop 4 on timestamps) as well as the common link between the themes, and come along to either the #DFIRSummit in Salt Lake City in August or the #DFIREuropeSummit in Prague in September, find me for a small prize bag

Demystifying Base64: A Detailed Beginner's Guide to Encoding and Decoding | SANS Institute

Demystifying Base64: A Detailed Beginner's Guide to Encoding and Decoding

When you can't make the #DFIRsummit the only alternative is to organize your own mini version.