LDLakshay Dhoundiyalinlakshaydhoundiyal.hashnode.dev·Jul 15 · 8 min readHow WhatsApp Stores, Deletes, and Protects Billions of Messages?Every day, billions of WhatsApp messages travel across the internet in just a few seconds. 📱 But have you ever wondered where WhatsApp messages are actually stored, whether WhatsApp saves every messa10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 12 · 5 min readBroncoCTF : Bundle WriteupSummary A .kra-adjacent artifact named Bundle_99 is handed off for analysis. It turns out to be a Krita resource bundle (.bundle) — a plain ZIP archive containing a brush preset (Brush 99.kpp). The .k00
SSansrinsansrsecurity.hashnode.dev·Jul 6 · 3 min readBreaking Down My First Network Forensics Investigation — The HawkEye CTF LabI recently completed the HawkEye Network Forensics lab on CyberDefenders, and I wanted to write up my process — partly for my own notes, partly because I wish more people shared their actual thinking 00
JJJeji Jamesinjeji-james.hashnode.dev·Jun 27 · 9 min readDigital Forensic Investigation Using Windows Security Event LogsIntroduction In cybersecurity, knowing how to investigate a compromised system is just as important as knowing how to defend one. Digital forensics is the process of collecting, preserving, and analys00
SESonny Enchillinsonnyenchill.hashnode.dev·Jun 25 · 5 min readThe Files Were Deleted. The Evidence Wasn't.The suspect had deleted the files. They had cleared the browser history. By the time the investigation started, the most obvious traces were gone. Digital forensics rarely begins with intact evidence.00
GGGiovanni Galarzaingiovannigalarza.hashnode.dev·May 28 · 5 min readThe Game PlanThe plan is simple really: learn enough DFIR to land a job in about a year. I also want to be able to make this as affordable as possible. This means the only thing I want to spend on are any certific00
JJebitokinsharonjebitok.com·May 8 · 35 min readAI Forensics (TryHackMe)Introduction The world of Digital Forensics is full of pieces needing to be connected, often under a time constraint. This can be a challenging task, but one that many forensics analysts have accompli00
Xx-originating-ipinx-originating-ip.hashnode.dev·Apr 30 · 8 min readBuilding 'nandtap': Dumping a Cisco Meraki Z1 NAND via Raspberry Pi GPIO Without Removing Chip from BoardTL;DR: https://github.com/x-originating-ip/nandtap As part of some personal upskilling, I wanted to get a better feel for what edge-device forensics actually looks like in practice. It’s one of those 10
Rrathsarainrr-dfir.hashnode.dev·Mar 22 · 14 min readCatching What Windows Hides: A Hands-On NTFS Forensics WalkthroughA hands-on walkthrough of MBR partition analysis, NTFS boot sector examination, Master File Table record inspection, and deleted file detection using hex editors and professional forensic tools. Unde00
Rrathsarainrr-dfir.hashnode.dev·Mar 22 · 8 min readData Hiding Techniques in GNU/Linux OSAn in-depth technical examination of data concealment methods within GNU/Linux covering ext3/4 file system internals, superblock and descriptor slack, inode-level deletion mechanics, and network-layer00