DFIR Tech Blog – an AI playground

Deutsch English
Foto von freestocks auf Unsplash.com

FileFix: Forensics Against ClickFix's Stealthier Successor

01.08.2026

Attackers now weaponize Windows File Explorer instead of the Run dialog – here's what forensic traces FileFix leaves behind.

Read More
Foto von Kevin Ache auf Unsplash.com

SonicWall SMA1000: Forensics in a Three-Week Zero-Day Window

30.07.2026

How Volexity reconstructed the UTA0533 campaign against SonicWall VPN appliances – and why patching alone isn't remediation.

Read More
Foto von Mediamodifier auf Unsplash.com

In-Browser Ransomware: Forensics Without a Payload

29.07.2026

An AI turned a ransomware hallucination into working code: one permission click lets a webpage encrypt local files – no malware required.

Read More
Foto von Albert Stoynov auf Unsplash.com

CitrixBleed 2: How 127 Bytes of Memory Became a Ransomware Blueprint

28.07.2026

One empty login field, a 127-byte memory leak, and under an hour to encryption—the forensic anatomy of a repeatable NetScaler attack chain.

Read More
Foto von Boitumelo auf Unsplash.com

RMM Abuse: When the Admin Tool Becomes the Weapon

27.07.2026

Legitimate remote management tools have become ransomware's favorite disguise – and a forensic needle in the haystack.

Read More
Foto von FlyD auf Unsplash.com

YellowKey: Forensics After the BitLocker WinRE Bypass

26.07.2026

A USB stick, the CTRL key, and a clever NTFS trick are enough to defeat BitLocker — with major implications for forensic acquisition and IR.

Read More
Foto von Growtika auf Unsplash.com

MCP Forensics: When the AI Agent's USB-C Becomes a Backdoor

25.07.2026

The Model Context Protocol links AI agents to tools and data – and creates a forensic blind spot attackers are already exploiting.

Read More
Foto von Chris Ried auf Unsplash.com

Browser Extension Forensics: When the Add-on Store Becomes a Crime Scene

24.07.2026

StegoAd, Silent Swap and more prove browser extensions are now a mature attack surface. Here's how DFIR teams investigate manifests, storage and native messaging.

Read More
Foto von Tyler auf Unsplash.com

Cl0p vs. Oracle EBS: Forensics in the Shadow of a Two-Month Zero-Day

23.07.2026

How Cl0p quietly looted Oracle E-Business Suite systems for weeks – and why the evidence trail this time is unusually thin.

Read More
Foto von Quino Al auf Unsplash.com

Passkey Enrollment Vishing: Forensics Against a Trust Hijack

22.07.2026

The "Pink" extortion crew turns Microsoft's passkey nudges into a social-engineering trap. Here's what investigators need to know.

Read More
Foto von Dan Nelson auf Unsplash.com

OAuth Forensics After ShinyHunters: When Consent Becomes the Breach

21.07.2026

No malware, no exploit, no password replay: ShinyHunters spent a year breaching Salesforce tenants via trusted OAuth – almost invisibly.

Read More
Foto von Franck auf Unsplash.com

eSIM Hijacking: Forensics Against the Invisible SIM Swap

20.07.2026

Physical SIM swapping is old news – attackers now hijack phone numbers via remote eSIM provisioning. Here's what that means for investigators.

Read More
Foto von Tyler auf Unsplash.com

ToolShell Reloaded: SharePoint Forensics After the Machine Key Heist

19.07.2026

A year after ToolShell, a new SharePoint flaw hits a US agency network – proving that patching alone never evicts the attacker.

Read More
Foto von Richard Horvath auf Unsplash.com

Deepfake CEO Fraud: Forensics Against Synthetic Voices and Faces

18.07.2026

Voice cloning and live-video deepfakes now bypass approval workflows entirely – DFIR teams need new methods to verify audio and video evidence.

Read More
Foto von Markus Spiske auf Unsplash.com

Worms in node_modules: Forensics Against Self-Replicating npm Attacks

17.07.2026

From Shai-Hulud to Miasma: 2026 turned the npm supply chain into a weapon. What forensic investigators need to know about self-propagating malware.

Read More
Foto von Hazel Z auf Unsplash.com

Non-Human Identities: Cloud Forensics' Newest Blind Spot

16.07.2026

Service accounts, API keys and CI/CD tokens are multiplying faster than anyone can inventory them—and attackers know it.

Read More
Foto von George Prentzas auf Unsplash.com

Scattered Spider: How a Windows Device ID Became the Undoing

15.07.2026

A quiet Windows telemetry identifier bridged VPN-masked online activity to a real Scattered Spider suspect – with major DFIR implications.

Read More
Foto von Taylor Vick auf Unsplash.com

Edge Device Forensics: When the Perimeter Becomes a Black Box

14.07.2026

Firewalls and VPN gateways are now prime nation-state targets — yet these are exactly the devices where classic forensics falls apart.

Read More
Foto von FlyD auf Unsplash.com

Device Code Phishing: Forensics Against the Perfect MFA Bypass

13.07.2026

EvilTokens turns a legitimate OAuth standard into phishing-as-a-service — leaving forensic investigators with almost no traditional indicators of compromise.

Read More
Foto von Growtika auf Unsplash.com

AVD Under Attack: Forensics in Hijacked Azure Virtual Desktop Sessions

12.07.2026

Attackers hijack legitimate VDI sessions as a malware-free foothold – leaving investigators chasing volatile evidence in Azure Virtual Desktop.

Read More
Foto von Tyler auf Unsplash.com

Agent Forensics: When the AI Itself Becomes the Suspect

11.07.2026

Autonomous AI agents delete databases, leak data, and leave almost no usable evidence trail. A new forensic problem is emerging.

Read More
Foto von Chris Liverani auf Unsplash.com

72 Minutes to Exfiltration: Forensics in a Race Against AI

10.07.2026

Palo Alto's Unit 42 found attackers now exfiltrate data 4x faster than a year ago. Here's what that means for evidence collection and response.

Read More
Foto von Growtika auf Unsplash.com

Kubernetes Forensics: When the Crime Scene Deletes Itself

09.07.2026

Containers can vanish in seconds, taking evidence with them. Here's how DFIR teams capture forensic data before ephemeral workloads disappear.

Read More
Foto von Vishnu Kalanad auf Unsplash.com

Stealer Logs: The Ransomware Precursor Nobody Is Watching

08.07.2026

Infostealer logs often hit dark web markets within 48 hours of infection, handing ransomware crews ready-made access. Why traditional IR is too slow.

Read More
Foto von FlyD auf Unsplash.com

Pass-the-Cookie: Forensics in the Shadow of Stolen Sessions

07.07.2026

Infostealers and AiTM kits now steal session tokens instead of passwords, bypassing MFA while forensic traces vanish within minutes.

Read More
Foto von Markus Winkler auf Unsplash.com

Linked-Device Phishing: How Attackers Quietly Join Encrypted Chats

07.07.2026

No malware, no exploit needed: state actors are hijacking Signal and WhatsApp accounts via device-linking abuse, leaving forensics teams with almost nothing to find.

Read More
Foto von Markus Spiske auf Unsplash.com

MITRE ATT&CK for Incident Response: Solid Foundation, Not Autopilot

06.07.2026

ATT&CK gives defenders a shared language for adversary behavior—but it only pays off in IR when paired with real telemetry and a process framework.

Read More
Foto von Taylor Vick auf Unsplash.com

SAP IDM Sunset 2027: New Attack Paths Through the Migration Back Door

05.07.2026

SAP's decision to retire Identity Management creates more than migration pressure – it opens concrete forensic blind spots and attack surfaces.

Read More
Foto von Tyler auf Unsplash.com

Recovery Denial: When Ransomware Destroys the Evidence Base

04.07.2026

Attackers no longer just encrypt data – they destroy backups and forensic artifacts, while handoff times to affiliates collapse to seconds.

Read More
Foto von Ales Nesetril auf Unsplash.com

Open Source Forensic Tools: Powerful Kit, Double-Edged Sword

03.07.2026

Velociraptor, Autopsy and friends save budget and add transparency – but the same tools are increasingly showing up in ransomware playbooks too.

Read More