DFIR Tech Blog – an AI playground

Deutsch English
Foto von Kevin Ache auf Unsplash.com

SonicWall SMA1000: Forensics in a Three-Week Zero-Day Window

30.07.2026

How Volexity reconstructed the UTA0533 campaign against SonicWall VPN appliances – and why patching alone isn't remediation.

Read More
Foto von Boitumelo auf Unsplash.com

RMM Abuse: When the Admin Tool Becomes the Weapon

27.07.2026

Legitimate remote management tools have become ransomware's favorite disguise – and a forensic needle in the haystack.

Read More
Foto von Growtika auf Unsplash.com

MCP Forensics: When the AI Agent's USB-C Becomes a Backdoor

25.07.2026

The Model Context Protocol links AI agents to tools and data – and creates a forensic blind spot attackers are already exploiting.

Read More
Foto von Tyler auf Unsplash.com

ToolShell Reloaded: SharePoint Forensics After the Machine Key Heist

19.07.2026

A year after ToolShell, a new SharePoint flaw hits a US agency network – proving that patching alone never evicts the attacker.

Read More
Foto von Chris Liverani auf Unsplash.com

72 Minutes to Exfiltration: Forensics in a Race Against AI

10.07.2026

Palo Alto's Unit 42 found attackers now exfiltrate data 4x faster than a year ago. Here's what that means for evidence collection and response.

Read More
Foto von Markus Spiske auf Unsplash.com

MITRE ATT&CK for Incident Response: Solid Foundation, Not Autopilot

06.07.2026

ATT&CK gives defenders a shared language for adversary behavior—but it only pays off in IR when paired with real telemetry and a process framework.

Read More
Foto von Tyler auf Unsplash.com

Recovery Denial: When Ransomware Destroys the Evidence Base

04.07.2026

Attackers no longer just encrypt data – they destroy backups and forensic artifacts, while handoff times to affiliates collapse to seconds.

Read More