DFIR Articles
The 11th Annual Volatility Plugin Contest!
We are excited to announce that the 11th Annual Volatility Plugin Contest is now open!
// INTEL ARCHIVE //
Authorized digital forensics and threat intelligence repository. Auto-updated daily with verified releases and digests.
DAILY INTELLIGENCE BRIEF
DFIR Articles
We are excited to announce that the 11th Annual Volatility Plugin Contest is now open!
DFIR Articles
Reading Time: 24 minutes Case001 Super Timeline Creation and Analysis Before Starting this lab it is strongly recommended you examine the memory, autoruns, pcap, or logs first. Come to this lab with indicators to search for.
DFIR Articles
Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually. Contact us today for pricing or a demo!
DFIR Articles
Reading Time: 3 minutes Case 002 – Hudak’s Honeypot The Case of The Forgotten Honeypot Readme: The best way to introduce this is to start with the README from Tyler: This Ubuntu Linux honeypot was put online in Azure in early October with the sole purpose of watching what happens with those exploiting […] The post Case 002 – Tyler Hudak’s Honeypot appeared first on DFIR Madness .
DFIR Articles
An NCSC assessment highlighting the impacts on cyber threat from AI developments between now and 2027.
DFIR Articles
Key findings and full report from the 6th year of the Active Cyber Defence (ACD) programme.
DFIR Articles
Report informing readers about the threat to UK industry and society from commercial cyber tools and services.
Forensics
Publication date: January 2027 Source: Forensic Science International: Genetics, Volume 86 Author(s): Chelsea Lennartz, Sarah Radecke, Philip Fremont-Smith, Adam Michaleas, Martha Petrovick, Joana Antunes, June Snedecor, Gothami Padmabandu, Kathryn Stephens, Natalie Damaso
Forensics
The New Detectives: Case Studies in Forensic Science (1996) IMDb
Forensics
Bones Was Based On A Series Of Popular Novels And A Real Forensic Scientist TVLine
Forensics
New Fresno-based training teaches first responders to find human remains after wildfires KVPR
Forensics
Microscopy in Forensic Pathology Lab Manager
Forensics
UCF Researchers Create the “Fantastic Four” Chemical Standards for Forensic Science University of Central Florida
Forensics
Critical tips and trace evidence lead to arrest in 2023 Tigard hit-and-run investigation KATU
Forensics
Blood Stain Pattern Analysis in Forensic Science Legal Desire Media and Insights
Forensics
Latent fingerprint recovery on submerged non-porous surfaces using phloxine B-based small particle reagent Nature
Forensics
OSAC's Wildlife Forensic Biology Subcommittee Develops Process Map National Institute of Standards and Technology (.gov)
Forensics
How an Unproven Forensic Science Became a Courtroom Staple (Published 2018) The New York Times
Forensics
Publication date: August 2026 Source: Journal of Forensic and Legal Medicine, Volume 122 Author(s): Mark W. Kroll, Michael A. Brave, Jiri Adamec, Sebastian N. Kunz, Robert C. Bux, Howard E. Williams
Forensics
Publication date: September 2026 Source: Legal Medicine, Volume 85 Author(s): Jessika Camatti, Anna Laura Santunione, Rossana Cecchi, Erjon Radheshi, Edoardo Carretto, Maria Paola Bonasoni
Forensics
Publication date: January 2027 Source: Forensic Science International: Genetics, Volume 86 Author(s): Seiki Nakao, Kazuya Mori, Jun Yoshida, Misa Kitagawa, Koichi Suzuki, Takako Sato
Forensics
New Nanomaterial Effective for Visualizing Latent Prints Forensic Magazine
Forensics
Publication date: Available online 25 July 2026 Source: Science & Justice Author(s): Max M. Houck
Forensics
When an adult refuses to let an injustice pass—stands up to a bully or asserts their rights—we call it principle.
Forensics
As the construction of a hydroelectric dam loomed, archaeologists raced to uncover Angola's earliest dated burials and its only known cremation at a 15th-century settlement before it vanished beneath the water.
Forensics
Click the source link to read the full dispatch.
Forensics
Click the source link to read the full dispatch.
IOC Feed
ThreatFox reported a new active indicator of compromise (IOC) for Unknown malware. Type: ip:port. Threat Category: botnet_cc. Reporter: anonymous.
ThreatFox reported a new active indicator of compromise (IOC) for Unknown malware. Type: ip:port. Threat Category: botnet_cc. Reporter: anonymous.
ThreatFox reported a new active indicator of compromise (IOC) for Unknown malware. Type: ip:port. Threat Category: botnet_cc. Reporter: anonymous.
IOC Feed
ThreatFox reported a new active indicator of compromise (IOC) for Unknown malware. Type: ip:port. Threat Category: botnet_cc. Reporter: anonymous.
IOC Feed
ThreatFox reported a new active indicator of compromise (IOC) for ClearFake. Type: domain. Threat Category: payload_delivery. Reporter: anonymous.
IOC Feed
ThreatFox reported a new active indicator of compromise (IOC) for ClearFake. Type: domain. Threat Category: payload_delivery. Reporter: threatcat_ch.
IOC Feed
ThreatFox reported a new active indicator of compromise (IOC) for Aisuru. Type: ip:port. Threat Category: botnet_cc. Reporter: Bitsight.
ThreatFox reported a new active indicator of compromise (IOC) for Unknown malware. Type: ip:port. Threat Category: botnet_cc. Reporter: anonymous.
The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.
The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.
CVE & Vulnerabilities
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.
The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports.
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing.
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor (including administrators) of any WP page displaying that Place ID's reviews.
Malware Intelligence
Key Takeaways The DFIR Report Services Contact us today for pricing or a demo! The intrusion began in early March 2025 with a single successful Remote Desktop Protocol (RDP) logon to an internet-exposed system.
As mentioned in a recent blog post, our team is once again offering in-person training, and we have substantially updated our course for this occasion.
Malware Intelligence
Overview Bumblebee malware has been an initial access tool used by threat actors since late 2021. In 2023 the malware was first reported as using SEO poisoning as a delivery mechanism.
GitHub Releases
New Plugins: linux.boottime linux.ebpf linux.hidden_modules linux.kthreads linux.pagecache linux.pidhashtable linux.ptrace windows.amcache windows.cmdscan windows.consoles windows.debugregisters windows.orphan_kernel_threads windows.pe_symbols windows.scheduled_tasks windows.unhoooked_system_calls Improvements to: Output formatting and filtering in the CLI Additional architecture data files for vmscan Note: Python 3.8 is now the minimum supported version of python
GitHub Releases
In the last OneDrive blog post , I outlined how the ODL file format is structured. A working version of an ODL parser was also created to read these files.
GitHub Releases
The Virtual File System Like GRR, Velociraptor also maintains a virtual file system view (VFS) of the client's filesystem. GRR's VFS view is generated by adding a row for each file into the database.
This release contains the following changes of note: Bumps upstream dependencies. Fixes a bug in SRUM database parsing by updating libesedb to the latest release ( #234 ).
GitHub Releases
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]
CVE & Vulnerabilities
Anti-Virus False Positives Warning: You will get false positives from certain anti-virus programs like Windows Defender and Web Browsers saying they have detected malicious files.
GitHub Releases
What's Changed ✨ New Features & Major Enhancements Add a custom prompt field to the AI investigation view by @itsmvd in #3612 feat: timeline tooltip & local defaults by @jkppr in #3641 Feat: Add delete-group and help commands to tsctl by @jaegeral in #3574 Feat: High-performance streaming event export API and client support by @jkppr in #3611 feat(tsctl): Add sync-groups-from-json command for bulk user management by @jkppr in #3619 feat: tsctl analyzer-management by @jaegeral in #3636 feat: Add story section in cli-client by @jaegeral in #3599 📈 Improvements & Refinements URL handling improvements by @jeflagel in #3573 feat: add list of registered test classes in end2end tests by @jaegeral in #3594 Cleanup: Remove e2e tests for Opensearch v1 & Ubuntu 22.04 by @jkppr in #3603 feat: API client: refactor retry logic by @jaegeral in #3581 feat: decoupled the profiling configuration from the debug setting by @jaegeral in #3613 build(e2e): Optimize Dockerfile by using official Plaso base image by @jkppr in #3620 UI: Add icons to user/group autocomplete in Share dialog by @jkppr in #3621 feat: tsctl chunked for check-opensearch-links by @jaegeral in #3618 Update secgemini_log_analyzer_agent.py by @babirous in #3623 test: new e2e test for events with comments by @jaegeral in #3588 Improve LLM error handling: reduce log noise and refine frontend feedback by @jkppr in #3633 Upgrade GitHub Actions to latest versions by @salmanmkc in #3638 Upgrade GitHub Actions for Node 24 compatibility by @salmanmkc in #3637 feat: add sketch id and analysis id on multiple logging points in analyzer/interface.py by @jaegeral in #3639 docs: by @jaegeral in #3601 🐞 Bug Fixes fix: API client - ensure functions in scenario return strings by @jkppr in #3598 fix: Ensure safe default return fields for saved views by @jkppr in #3602 Fix back-to-back SecGemini investigations by @gpavlidi in #3597 api_client: fix: some smaller fixes to retry logic by @jaegeral in #3608 fix: API Client: safely retrieve _retry_count and _backoff_factor using getattr with d… by @jaegeral in #3609 Revert "fix: API Client: safely retrieve _retry_count and _backoff_factor using getattr with d…" by @jaegeral in #3610 Fix: Handle issue in events with CommentsMixin.get_with_comments() by @jaegeral in #3590 initial attempt to fix some delete workflows by @jaegeral in #3587 Fix: Remove unsupported 'features' argument in tsctl by @jaegeral in #3631 Fix: [importer] Prevent duplicate jsonl uploads by fixing ImportStreamer.close() by @jkppr in #3640 ⬆️ Dependency Updates build(deps): bump vega from 5.32.0 to 6.2.0 in /timesketch/frontend-ng in the npm_and_yarn group across 1 directory by @dependabot [bot] in #3596 build(deps): bump js-yaml from 3.14.1 to 3.14.2 in /timesketch/frontend-ng in the npm_and_yarn group across 1 directory by @dependabot [bot] in #3606 build(deps): bump js-yaml from 4.1.0 to 4.1.1 in /timesketch/frontend-v3 in the npm_and_yarn group across 1 directory by @dependabot [bot] in #3604 build(deps): bump node-forge from 1.3.1 to 1.3.2 in /timesketch/frontend-ng in the npm_and_yarn group across 1 directory by @dependabot [bot] in #3614 build(deps): bump werkzeug from 3.0.6 to 3.1.4 in the pip group across 1 directory by @dependabot [bot] in #3616 ⚠️ Ensure to update your local timesketch.conf with the new config value.
GitHub Releases
3.5.0 [2025/08/16] - Obon Release Enhancements: Hayabusa now supports the base64 field modifier. ( #1677 ) ( @fukusuket ) 改善 : * base64 フィールド修飾子に対応した。 ( #1677 ) ( @fukusuket )
GitHub Releases
3.4.0 [2025/08/01] - Black Hat Arsenal USA 2025 Release Enhancements: Field names are now abbreviated in the search command. You can disable with -b, --disable-abbreviations .
CVE & Vulnerabilities
Research from the NCSC designed to eradicate vulnerability classes and make the top-level mitigations easier to implement.
GitHub Releases
Release of version 20240826
GitHub Releases
Release of version 20230717
GitHub Releases
KAPE 0.8.6.1 released Changes in this release include: - When using transfer options, transfer module output to destination when --zm true is used. This pushes the output from modules as a zip file to the destination server.
GitHub Releases
Get all the details here!! 0.8.3.0 info
GitHub Releases
Changes in this release include: Change ConsoleLog from being file based to memory based.
The database query returned 0 active intelligence feeds.
Try adjusting your filters, searching for other keywords, or bookmarking articles to view them here.
ARCHIVE INTELLIGENCE OVERVIEW
// DAILY INTEL BRIEF //
// DAILY INTEL BRIEF //
// DAILY INTEL BRIEF //
// DAILY INTEL BRIEF //
// DAILY INTEL BRIEF //
// DAILY INTEL BRIEF //
// DAILY INTEL BRIEF //
// DAILY INTEL BRIEF //
// DAILY INTEL BRIEF //
// DAILY INTEL BRIEF //
// DAILY INTEL BRIEF //