F for Forensics

F is for Fragments in Time - Building Forensic Timelines

34 min · 17. dec. 2025
episode F is for Fragments in Time - Building Forensic Timelines cover

Description

In this episode of F for Forensics, we explore how investigators transform scattered artifacts into a clear digital narrative using forensic timelines. From MACB timestamps and registry entries to browser data, logs, and super timelines, this episode breaks down how timelines reveal patterns, expose anomalies, and connect user actions across systems. Real-world examples show how seconds, not hours, can make or break a case. #FforForensics, #ForensicTimelines, #DigitalForensics, #DFIR, #CyberForensics, #TimelineAnalysis, #EventLogs, #Plaso, #Timesketch, #ComputerForensics, #ForensicAnalysis, #CyberCrime, #IncidentResponse, #ForensicPodcast

Comments

0

Be the first to comment

Sign up now and become a member of the F for Forensics community!

Get Started

2 months for 19 kr.

Then 99 kr. / month · Cancel anytime.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

11 episodes

episode F is for Federated Identity: When Login Is the Crime artwork

F is for Federated Identity: When Login Is the Crime

In this episode we dive into the modern reality of identity-driven attacks. In today’s cloud-first world, attackers don’t need malware or exploits — they simply log in. Learn how federated identity systems like Microsoft Entra ID, Okta, and Google Workspace change the forensic landscape, why credentials and tokens have become the new attack surface, and how investigators can uncover evidence hidden inside authentication logs, access events, and OAuth permissions. If you want to understand how to investigate cases where login itself is the crime, this episode is essential listening. #FforForensics #DigitalForensics #DFIR #CloudForensics #IdentitySecurity #FederatedIdentity #CyberForensics #IncidentResponse #CyberSecurity #AuthenticationLogs #MFA #TokenAbuse #ForensicPodcast

17. feb. 202632 min