Blog

Research, workflow writeups, and DFIR methodology

Practical research, investigative workflows, technical analysis, and lessons learned from building investigator-focused DFIR tools.

Screenshot representing the newest River City Digital Forensics blog post
AUGUST 2026

Coming soon 

Scenario with tool walkthrough 

Screenshot representing a River City Digital Forensics blog post
JuLY 2026

Coming soon 

Interactive vs Non-Interactive Sign-in Logs: Their value in investigating BEC's and Account Takeovers.      

Screenshot representing a River City Digital Forensics technical article
June 2026

Session Hijacking Token Theft

Session Hijacking in the Cloud: How modern phishing steals tokens and bypasses traditional MFA. 

Interactive Sign-In Analyzer screenshot
May 2026

OAuth Abuse in Practice

A practical look at how OAuth abuse occurs, why it can be difficult to detect, and which authentication, audit, and activity logs matter during an investigation.

Interactive Sign-In Analyzer screenshot
April 2026

Interactive Sign-In Logs — One of the Most Important Artifacts in Modern DFIR

A practical look at why interactive sign-in logs matter, what they represent, and how authentication telemetry helps investigators reconstruct modern cloud and identity-based attacks.

Interactive Sign-In Analyzer screenshot
March 2026

DFIR Isn’t “Just Logs” — It’s Forensic Reconstruction at Scale

A perspective on why DFIR is not simply looking at logs, but reconstructing adversary behavior through distributed forensic telemetry, identity evidence, and investigative context.

Upcoming Content

Planned Research and Writeups

  • Why Microsoft 365 sign-in logs matter in business email compromise and account takeover investigations
  • How to interpret high-value authentication and sign-in artifacts
  • Release-note articles for major River City Digital Forensics tool updates
  • Lessons learned from building investigator-focused DFIR interfaces
River City Digital Forensics

Practical DFIR Research

New articles will focus on Microsoft 365 investigations, authentication evidence, incident reconstruction, investigative workflows, and the development of practical DFIR tools.