Hmmmm. What are we up to here? 🤔
11.3.2025 22:53Hmmmm. What are we up to here? 🤔Interesting thing with OneDrive Offline Mode for web. You can get the last two modification times of a file. Could come in handy. #DFIR
7.3.2025 20:16Interesting thing with OneDrive Offline Mode for web. You can get the last two modification times of a file. Could come in handy. #DFIRI started exploring OneDrive’s FileUsageSync.bd. There is some useful information on files shared via email, Teams, etc… that may not be in the user’s OneDrive.
https://malwaremaloney.blogspot.com/2025/02/onedrive-microsoftfileusagesyncdb.html
21.2.2025 17:53I started exploring OneDrive’s FileUsageSync.bd. There is some useful information on files shared via email, Teams, etc… that may not be...I am OneDrive.
21.2.2025 13:39I am OneDrive.I just came across email information in one of the OneDrive databases. Sender, recipients, subject, mailbox, attachments, etc…
Pretty much everything except the body. More to come. 🤔 #DFIR
OneDriveExplorer now supports and parses Offline Mode for web.
https://malwaremaloney.blogspot.com/2025/02/onedriveexplorer-offline-mode-edition.html
14.2.2025 21:22OneDriveExplorer now supports and parses Offline Mode for web....There seemed to be enough interest so I decided to do a write up on what I have found about OneDrive Offline Mode. Hate to burn a forensic artifact but I’m concerned about what Microsoft feels is secure. #DFIR
https://malwaremaloney.blogspot.com/2025/01/onedrive-offline-mode-recallish-vibes.html
28.1.2025 02:41There seemed to be enough interest so I decided to do a write up on what I have found about OneDrive Offline Mode. Hate to burn a forensic...Did you know you can run Autopsy Automated Ingest Nodes as a service. This eliminates human interaction and survives reboots.
https://malwaremaloney.blogspot.com/2025/01/running-autopsy-auto-ingest-in-headless.html
Added new artifact to All Things OnDrive. <UserCid>_import.dat is created when “Save photos and videos from device” is enabled. It records data on imported photos and videos.
https://malwaremaloney.blogspot.com/p/location-localappdatamicrosoftonedrives_16.html
16.1.2025 19:58Added new artifact to All Things OnDrive. <UserCid>_import.dat is created when “Save photos and videos from device” is enabled. It...Autopsy Hardening Guide: Part 2. This post covers encrypting passwords and securing the web-console of ActiveMQ.
https://malwaremaloney.blogspot.com/2025/01/autopsy-hardening-guide-part-2.html
13.1.2025 20:04Autopsy Hardening Guide: Part 2. This post covers encrypting passwords and securing the web-console of ActiveMQ....Added new artifact to All Things OnDrive. <UserCid>_screenshot.dat is created when “Save screenshots I capture to OneDrive” is enabled. It records data on the last screenshot saved.
https://malwaremaloney.blogspot.com/p/location-localappdatamicrosoftonedrives.html
9.1.2025 19:19Added new artifact to All Things OnDrive. <UserCid>_screenshot.dat is created when “Save screenshots I capture to OneDrive” is...Part 1 of the Autopsy hardening guid is up. This goes over points to make PostgreSQL and Solr more secure. #DFIR
https://malwaremaloney.blogspot.com/2025/01/autopsy-hardening-guide-part-1.html
6.1.2025 20:10Part 1 of the Autopsy hardening guid is up. This goes over points to make PostgreSQL and Solr more secure....Did a quick update to DFIR_Toolbar. Executable created. Now to work on the Readme.
https://github.com/Beercow/DFIR_Toolbar/releases
4.1.2025 18:35Did a quick update to DFIR_Toolbar. Executable created. Now to work on the Readme. https://github.com/Beercow/DFIR_Toolbar/releasesThought I’d do something fun. Presenting the DFIR_Toolbar. Basically a toolbar that can be anything you want it to be.
https://malwaremaloney.blogspot.com/2025/01/dfirtoolbar.html
3.1.2025 01:15Thought I’d do something fun. Presenting the DFIR_Toolbar. Basically a toolbar that can be anything you want it to be....Python tool that converts Microsoft Defender Antivirus Signatures (VDM) into YARA rules.
https://github.com/t-tani/defender2yara
14.12.2024 04:38Python tool that converts Microsoft Defender Antivirus Signatures (VDM) into YARA rules.https://github.com/t-tani/defender2yaraJust a heads up. M$ is OCRing all your images in OneDrive for business in an unsecured database on your desktop/laptop. Happy Friday. #DFIR
6.12.2024 21:39Just a heads up. M$ is OCRing all your images in OneDrive for business in an unsecured database on your desktop/laptop. Happy Friday. #DFIROut of necessity, today I wrote and compiled my first extension for SQLite. And it worked!
6.12.2024 16:23Out of necessity, today I wrote and compiled my first extension for SQLite. And it worked!Getting a little concerned now about OneDrive. Looks like the Recall no one’s talking about.
5.12.2024 13:48Getting a little concerned now about OneDrive. Looks like the Recall no one’s talking about.