Your Logs Have a Gap. That Is Not Evidence Anybody Deleted Them.
A quiet hour in the logs has five ordinary causes before it has a suspicious one. Work them in order, and know a positive tell when you see it.
Read more →Blog › Incident Response
From first alert to a finding somebody else can check: scoping a compromise, preserving evidence before it expires, containment that does not destroy the case, and the words a report can defend.
8 articles
A quiet hour in the logs has five ordinary causes before it has a suspicious one. Work them in order, and know a positive tell when you see it.
Read more →A process can rewrite what ps reports about it in three lines of C. One field on the same host cannot be rewritten, and the contradiction is the detection.
Read more →The setting that decides whether you recover a SharePoint library is one any site owner can change. Detection in KQL, SPL and Sigma.
Read more →A managed Mac, a clean scanner result, and a notarized tool holding Full Disk Access. What to read on disk when nothing was ever technically malware.
Read more →GDPR, NIS2, DORA and the SEC start the notification clock at awareness or materiality, not at resolution. When each triggers, and why teams miss it.
Read more →You're on a compromised Windows host with no forensic tools installed. Capture volatile evidence, processes, and network state using only built-in commands.
Read more →VanGuard: open-source DFIR toolkit that replaces the 45-minute tooling scramble at incident start. 28 use cases, cross-platform.
Read more →The sign-in log tells you how they got in. The audit log tells you what they did. Here's the sequence that turns both into a containment decision.
Read more →Other topics