Research, workflow writeups, and DFIR methodology
Practical research, investigative workflows, technical analysis, and lessons learned from building investigator-focused DFIR tools.
Practical research, investigative workflows, technical analysis, and lessons learned from building investigator-focused DFIR tools.
Scenario with tool walkthrough
Interactive vs Non-Interactive Sign-in Logs: Their value in investigating BEC's and Account Takeovers.
Session Hijacking in the Cloud: How modern phishing steals tokens and bypasses traditional MFA.
A practical look at how OAuth abuse occurs, why it can be difficult to detect, and which authentication, audit, and activity logs matter during an investigation.
A practical look at why interactive sign-in logs matter, what they represent, and how authentication telemetry helps investigators reconstruct modern cloud and identity-based attacks.
A perspective on why DFIR is not simply looking at logs, but reconstructing adversary behavior through distributed forensic telemetry, identity evidence, and investigative context.
New articles will focus on Microsoft 365 investigations, authentication evidence, incident reconstruction, investigative workflows, and the development of practical DFIR tools.