Go offline with the Player FM app!
Techno, Timeline, and Training Truths
Manage episode 491072517 series 3505865
We kick off this episode with highlights from the Techno Security Conference, our 80s-themed outfits, packed LEAPP labs, AI panel discussions, and great conversations with friends and colleagues across the field.
We discuss Brett Shavers’ recent series on DFIR entry-level work, and share our thoughts on the need for better forensic training and clearer distinctions between forensics, cybersecurity, and incident response.
We also talk about recent tool changes in the industry. Cellebrite’s acquisition of Corellium could make mobile app testing more accessible, and Magnet’s purchase of Dark Circuit Labs.
We cover Harper Shaw’s Vehicle Network App, a valuable source of vehicle-related data. Alongside that, we highlight a recent blog on cached screenshots in Windows 11.
Be sure to check out the excellent “Parsing the Truth” podcast.
Heather walks through her Easter road trip to test Android's Timeline feature (formerly Google Location History). The location data was impressively accurate, but also showed how easily some points can mislead without the right context.
Catch us at IACIS Reno in January and check out the some of the resources we mentioned.
Notes:
Parsing the Truth: One Byte at a Time
https://parsingthetruth.com/
Cached Screenshots on Windows 11
https://thinkdfir.com/2025/06/13/cached-screenshots-on-windows-11/
The Vehicle Network App from Harper Shaw
https://harpershaw.co.uk/the-vehicle-network-app-1
Beklkasoft CTF
https://belkasoft.com/belkactf7/
Brett Shavers 6 part series
https://www.linkedin.com/pulse/dfir-really-entry-level-brett-shavers-ewsvc/
https://www.dfir.training/new-to-dfir/dfir-career
Artifact of the Week/Android Location History
https://thebinaryhick.blog/2024/06/28/the-green-look-back-androids-on-device-location-history/
Chapters
1. Techno, Timeline, and Training Truths (00:00:00)
2. Welcome and Introduction (00:00:20)
3. Techno Security Conference Highlights (00:01:46)
4. IACIS Reno Event Announcement (00:11:11)
5. New Forensic Podcast Recommendation (00:12:29)
6. Company Acquisitions in Digital Forensics (00:15:30)
7. Windows 11 Cached Screenshots Location (00:24:04)
8. Vehicle Network App Introduction (00:27:02)
9. Digital Forensics Education Discussion (00:29:19)
10. Android Timeline Location Analysis (00:41:28)
11. Meme of the Week and Closing (01:05:52)
36 episodes
Manage episode 491072517 series 3505865
We kick off this episode with highlights from the Techno Security Conference, our 80s-themed outfits, packed LEAPP labs, AI panel discussions, and great conversations with friends and colleagues across the field.
We discuss Brett Shavers’ recent series on DFIR entry-level work, and share our thoughts on the need for better forensic training and clearer distinctions between forensics, cybersecurity, and incident response.
We also talk about recent tool changes in the industry. Cellebrite’s acquisition of Corellium could make mobile app testing more accessible, and Magnet’s purchase of Dark Circuit Labs.
We cover Harper Shaw’s Vehicle Network App, a valuable source of vehicle-related data. Alongside that, we highlight a recent blog on cached screenshots in Windows 11.
Be sure to check out the excellent “Parsing the Truth” podcast.
Heather walks through her Easter road trip to test Android's Timeline feature (formerly Google Location History). The location data was impressively accurate, but also showed how easily some points can mislead without the right context.
Catch us at IACIS Reno in January and check out the some of the resources we mentioned.
Notes:
Parsing the Truth: One Byte at a Time
https://parsingthetruth.com/
Cached Screenshots on Windows 11
https://thinkdfir.com/2025/06/13/cached-screenshots-on-windows-11/
The Vehicle Network App from Harper Shaw
https://harpershaw.co.uk/the-vehicle-network-app-1
Beklkasoft CTF
https://belkasoft.com/belkactf7/
Brett Shavers 6 part series
https://www.linkedin.com/pulse/dfir-really-entry-level-brett-shavers-ewsvc/
https://www.dfir.training/new-to-dfir/dfir-career
Artifact of the Week/Android Location History
https://thebinaryhick.blog/2024/06/28/the-green-look-back-androids-on-device-location-history/
Chapters
1. Techno, Timeline, and Training Truths (00:00:00)
2. Welcome and Introduction (00:00:20)
3. Techno Security Conference Highlights (00:01:46)
4. IACIS Reno Event Announcement (00:11:11)
5. New Forensic Podcast Recommendation (00:12:29)
6. Company Acquisitions in Digital Forensics (00:15:30)
7. Windows 11 Cached Screenshots Location (00:24:04)
8. Vehicle Network App Introduction (00:27:02)
9. Digital Forensics Education Discussion (00:29:19)
10. Android Timeline Location Analysis (00:41:28)
11. Meme of the Week and Closing (01:05:52)
36 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.