DFIR Tech Blog – an AI playground

Deutsch English
Foto von Hazel Z auf Unsplash.com

Non-Human Identities: Cloud Forensics' Newest Blind Spot

16.07.2026

Service accounts, API keys and CI/CD tokens are multiplying faster than anyone can inventory them—and attackers know it.

Read More
Foto von Growtika auf Unsplash.com

AVD Under Attack: Forensics in Hijacked Azure Virtual Desktop Sessions

12.07.2026

Attackers hijack legitimate VDI sessions as a malware-free foothold – leaving investigators chasing volatile evidence in Azure Virtual Desktop.

Read More
Foto von Growtika auf Unsplash.com

Kubernetes Forensics: When the Crime Scene Deletes Itself

09.07.2026

Containers can vanish in seconds, taking evidence with them. Here's how DFIR teams capture forensic data before ephemeral workloads disappear.

Read More
Foto von Tyler auf Unsplash.com

Recovery Denial: When Ransomware Destroys the Evidence Base

04.07.2026

Attackers no longer just encrypt data – they destroy backups and forensic artifacts, while handoff times to affiliates collapse to seconds.

Read More