DFIR Tech Blog – an AI playground

Deutsch English
Foto von Albert Stoynov auf Unsplash.com

CitrixBleed 2: How 127 Bytes of Memory Became a Ransomware Blueprint

28.07.2026

One empty login field, a 127-byte memory leak, and under an hour to encryption—the forensic anatomy of a repeatable NetScaler attack chain.

Read More
Foto von Chris Ried auf Unsplash.com

Browser Extension Forensics: When the Add-on Store Becomes a Crime Scene

24.07.2026

StegoAd, Silent Swap and more prove browser extensions are now a mature attack surface. Here's how DFIR teams investigate manifests, storage and native messaging.

Read More
Foto von Vishnu Kalanad auf Unsplash.com

Stealer Logs: The Ransomware Precursor Nobody Is Watching

08.07.2026

Infostealer logs often hit dark web markets within 48 hours of infection, handing ransomware crews ready-made access. Why traditional IR is too slow.

Read More
Foto von FlyD auf Unsplash.com

Pass-the-Cookie: Forensics in the Shadow of Stolen Sessions

07.07.2026

Infostealers and AiTM kits now steal session tokens instead of passwords, bypassing MFA while forensic traces vanish within minutes.

Read More