H. C:\arvey (@keydet89 )

H. C:\arvey

Bio Sr DFIR Advisor, Researcher, Practitioner. USMC vet. Author. Opinions = own. #IntrusionIntel
Location Planet Earth
Tweets 6,5K
Followers 3,4K
Following 36
Account created 29-06-2017 21:18:07
ID 880535878724009985

Twitter Web App : Lennaert "...overview of software..."

That could go on and on, without ever begin actually read.

I guess what I'm really asking is given everything that's already been written on this topic, what's missing?

Twitter Web App : First, this:

welivesecurity.com/2020/05/21/no-…

Then this:

Launching printprocessors v.20200710

ControlSet001\Control\Print\Environments\Windows x64\Print Processors\winprint
LastWrite time: 2018-09-15 07:34:18Z
Driver value = winprint.dll

#DFIR

Twitter Web App : Lennaert So...nothing?

What I'm trying to determine is what folks are looking for in this sort of content that hasn't already been covered/written about...

Twitter Web App : Mike Mullins Dr. Anton Chuvakin CrowdStrike What's really needed is for intel and IR teams to work closely together. Unfortunately, this is obviated by the utilization model used by IR teams, and most intel teams don't have someone with deep DFIR knowledge on board.

Twitter Web App : Good write-up:

welivesecurity.com/2020/07/09/mor…

Apparently, LNK files still don't warrant a "deep look"...

#DFIR #intrusionintel #threatintel