    [] My reading/resource list (forensics, IR, infosec, malware, reverse engineering, programming, etc):

  2. New blog post up. Carving thumbnails from the Quicklook thumbnails.data file. Python parser included.

  3. Anyway, you should follow for /malware stuff.

  4. I'll never understand reddit. Users report "blogspam" because it was posted by the author -even when it's one of the better things submitted

    • @danielhbohannon

      Incident Response Consultant PowerShell (Invoke-Obfuscation)

  6. Remembered that I had a Facebook account from a very long time ago. Tried to access it & was presented w/this. mfw:

  7. 8. For anyone confused by my reference to the open source ransomware thing, see here:

  8. 7. The more detail, the better. Then I know exactly what can/cannot be investigated. Therefore, is too much detail a bad thing to share?

  9. 6. If I'm an attacker or someone who wants to cover my tracks, I'm Googling it and going beyond to understand what I need to do.

  10. 5. Not looking to argue for or against either side, but it's something that's always been interesting and difficult to think about.

  11. 4. Same goes for the other side. How will people know how to ID bad activity and evidence of it? There are two sides of this coin.

  12. 3. Sure, you'll almost always see the evidence of an anti-forensics job, but what gave them the knowledge to succeed in the first place?

  13. 2. Could pinpointing and detailing specific artifacts that anti-forensics devs could leverage (& otherwise wouldn't know about) be an issue?

  14. 1. With the open source ransomware debate heating up, what about ? Is it a bad idea to share or open source artifact findings?

