Frankie Li’s Post

View profile for Frankie Li, graphic

An independent researcher in malware analysis and digital forensics (@ran2.bsky.social)

Just complete a DFIR investigation engagement. Instead of repeatedly sharing the ransomware actors’ TTP, I want to point out quite some first responders on how they handle the artifact collection may jeopardize the whole investigation. #BattlefieldDFIR #ShutdowntheEdgeDevice #MissingLog #CherryPickRootCause #NoSiteVisitbutRemote #SeeingPretendNotSeeing #BlametheMalware #BlameNoMFA #BlameNoPatch #BlameNoPentesting #BlameOutdatedProduct

To view or add a comment, sign in

Explore topics