100 episodes

The Forensic Lunch!

The one hour, mostly, live digital forensics and incident response focused video cast and podcast.

The Forensic Lunch with David Cowen and Matthew Seyer David Cowen

    • Technology
    • 5.0, 4 Ratings

The Forensic Lunch!

The one hour, mostly, live digital forensics and incident response focused video cast and podcast.

    Forensic Lunch 5/8/20 - Jack Farley, Josh Brunty, Kevin Pagano, Tom Pace, Jim Arnold

    Forensic Lunch 5/8/20 - Jack Farley, Josh Brunty, Kevin Pagano, Tom Pace, Jim Arnold

    This week on the Forensic Lunch we had:
    Josh Brunty, @joshbrunty,  talking about his DFIR program at Marshall   https://www.marshall.edu/cyber/ Tom Pace of Blackberry Cyclance and Jim Arnold of KPMG talking about recent ransomware trends.  Kevin Pagano, @kevpagano3,  talking about his Sunday Funday and the Magnet Virtual CTF  Jack Farley, @jackfarley248,  talking about MEAT and the Magnet Virtual CTF  https://github.com/jfarley248/MEAT  
     
    You can watch it here:
    https://youtu.be/fPzSm-hofA0

    • 1 hr 17 min
    Forensic Lunch 5/1/20 - Oleg Skulkin (FeatureUsage), Brian Marks (Office 365) , Lee Whitfield 4CAST

    Forensic Lunch 5/1/20 - Oleg Skulkin (FeatureUsage), Brian Marks (Office 365) , Lee Whitfield 4CAST

          This week the Forensic Lunch went into Overtime! We went a full 25 minutes over the usual hour because we had so much to talk about. On this weeks show:
     
    Matt Seyer (@forensic_matt) talked all about the etl parser and monitor he's working on in Rust! https://github.com/forensicmatt/RsWindowsThingies Oleg Skulkin (@oskulkin) talked about how he approaches Sunday Funday's (he's won 3!) and about his new blog post about the Windows FeatureUsage artifact.  https://www.group-ib.com/blog/featureusage Brian Marks (@briandfir) talked about how the Office365 UAL MailboxItemsAccessed Audit event works and what the entry details mean   Lee Whitfield (@lee_whitfield ) talked through the Forensic 4Cast Awards nominations that end in two weeks, and Matt and I gave who we will be nominating. https://forensic4cast.com/2020/02/2020-forensic-4cast-awards-nominations-are-open/  

    • 1 hr 25 min
    Forensic Lunch 4/24/20 with the Google IR Team (GRR, Timesketch, Turbinia, DTTimewolf, More!)

    Forensic Lunch 4/24/20 with the Google IR Team (GRR, Timesketch, Turbinia, DTTimewolf, More!)

      We had a jam packed Forensic Lunch today with a portion of the Google IR team today talking all about the open source tools they develop, use and support in their work at Google.
     
    Specifically we had :
    Mikhail Bushkov giving a big update on GRR https://github.com/google/grr Johan Berggren (https://twitter.com/jberggren) and Kristinn Gudjonsson (https://twitter.com/el_killerdwarf) talking about Timesketch and Data science https://github.com/google/timesketch Aaron Peterson (https://twitter.com/aarontpeterson) talking about Turbinia https://github.com/google/turbinia Thomas Chopitea (https://twitter.com/tomchop_) talking about DTTimewolf https://github.com/log2timeline/dftimewolf Theo Giovanna talking about libcloudforensics aka cloudforensicutils https://github.com/google/cloud-forensics-utils/tree/master/libcloudforensics Joachin Metz (https://twitter.com/joachimmetz) - Talking about Plaso, libntfs and Libyal Plaso: https://github.com/log2timeline/plaso  Libfsntfs: https://github.com/libyal/libfsntfs Libyal: https://github.com/libyal Join them on the Open Source DFIR Slack: https://join-open-source-dfir-slack.herokuapp.com/
     
    Read more about what they are doing on the Open Source DFIR Blog: https://osdfir.blogspot.com/

    • 1 hr 17 min
    Forensic Lunch 4/17/20 with Zach Wasserman

    Forensic Lunch 4/17/20 with Zach Wasserman

      Today on the Forensic Lunch we only had one guest, Zach Wasserman, from OSQuery technical steering committee. We only had one guest because we knew we would have so much to talk to Zach about! From OSQuery's future in the linux foundation, Kollide Fleet and other fleet managers to Zach's work at Dactiv, LLC you have alot waiting for you in this weeks broadcast.
     
    You can reach Zach Wasserman on twitter @TheZachW or Zach can be reached at zach@dactiv.llc if you want to work with him!
     

    • 1 hr 5 min
    Forensic Lunch 4/10/20 with Belkasoft, AWS IR Automation, MVS DFIRFIT and HTTP Security Headers

    Forensic Lunch 4/10/20 with Belkasoft, AWS IR Automation, MVS DFIRFIT and HTTP Security Headers

    What a great Forensic Lunch today!
    On today's broadcast we had:
    Yuri Gubanov (@belkasoft) giving an update about whats going on at Belkasoft. Including their IOS 13.4 full file system acquisition using Checkm8, their new IR module in Belkasoft Evidence Center and a neat capability to do managed remote logical phone collections.
    Steve Gibson and Spencer Hendee (@stevegibson) from KPMG (disclaimer I work there too!) came on to discuss the really cool AWS Cloud IR Automation we've been working on.
    Brian Moran (@brimorlabs) social media maven and principal of BriMorLabs came on to discuss the Magnet Virtual Summit DFIRFIT 2020 where for a donation (and some excercise) you can get a cool prize pack shipped to you anywhere in the world! Register here: https://mvsdfirfit2020.com
    Caleb Queern (@HttpSecHeaders) also of KPMG came on to discuss the clearsite HTTP header. This was interesting as its a directive a website can give to a browser to tell it to clear/not store history or data about it. This will need to be tested, you can read more here https://w3c.github.io/webappsec-clear-site-data/

    So great stuff this week, you can watch below. Otherwise next week we've already confirmed Zach Wasserman to come and talk about OSQuery and Kollide!

    • 1 hr 5 min
    Forensic Lunch 4/3/20

    Forensic Lunch 4/3/20

    On this episode:
     
    Mari Degrazia (@MariDegrazia) discussing her research into WinSCP and later movement, you can read more here: http://az4n6.blogspot.com/2020/02/detecting-laterial-movment-with-winscp.html Hal Pomeranz (@hal_pomeranz) talking about his new Linux Forensics course that you can download here: https://ia801406.us.archive.org/6/items/HalLinuxForensics/HalLinuxForens ics_archive.torrent Alex Levinson (@alexlevinson) Gave an update on the National Collegiate Cyber Defense Competition which as gone all virtual this year Matt Seyer (forensic_matt) talked about our upcoming SANS DFIR presentation and tools he's working on Sarah Edwards (@iamevltwin) gave colorful commentary and meaningful insights 

    • 58 min

Customer Reviews

5.0 out of 5
4 Ratings

4 Ratings

Darthsaac ,

Excellent podcast about digital forensics

"it's the forensic lunch". This podcast presented by one of the most respectable digital forensics analysts in our field. The Forensic lunch will provide any listener with an incredible amount of knowledge, groundbreaking technology, and very interesting interviews with respectable personalities that work on DFIR field.

Top Podcasts In Technology

Listeners Also Subscribed To