<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><link>https://bsky.app/profile/carrier4n6.bsky.social</link><title>@carrier4n6.bsky.social - Brian Carrier</title><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lwtsvhonlk2d</link><description>#DFIR Automation Series&#xA;&#xA;I use 4 levels of automation ranging from none to fully automated. &#xA;&#xA;I think an ideal solution is to use full automation for low risk decisions. And recommendations for higher risk. &#xA;&#xA;We use recommendations in Cyber Triage by scoring each artifact. You ultimately decide.</description><pubDate>20 Aug 2025 16:10 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lwtsvhonlk2d</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lwc53yrr7227</link><description>I&#39;m super excited for this webinar. Sid is a super smart AI / LLM guy and it will be a good session to learn how to use AI in #DFIR and what&#39;s hype. &#xA;&#xA;We&#39;ll also show Cyber Triage hooked up to an LLM so that you can query artifacts.&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>13 Aug 2025 15:25 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lwc53yrr7227</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lwc4o3jsms27</link><description>Digital forensics has always relied on automation and &#34;push buttons&#34;. What&#39;s changed is how many things we automate and the technologies used. &#xA;&#xA;No one ever chose to manually parse FAT12 floppy drives with a hex editor when they could have a tool list out the file names.</description><pubDate>13 Aug 2025 15:17 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lwc4o3jsms27</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lvnzmkk6fk2u</link><description>Adding automation to your #DFIR investigations means you have less decisions to make. Get rid of the tedious work! Focus on the fun stuff!&#xA;&#xA;Here are my three thoughts on the most effective ways to add automation and which tools do them. &#xA;&#xA;What are yours? &#xA;&#xA;https://www.cybertriage.com/blog/3-ways-to-make-digital-investigations-faster-with-automation/</description><pubDate>05 Aug 2025 15:29 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lvnzmkk6fk2u</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lolqtqv25s2b</link><description>Webinar Tomorrow - Automation and AI in DFIR and the SOC.&#xA;&#xA;Myself, Sentinel1, and CompassMSP will talk about pros/cons of automating DFIR and SOC tasks. &#xA;&#xA;Come tell us we&#39;re wrong!&#xA;&#xA;May 8. 11AM Eastern.&#xA;&#xA;https://register.gotowebinar.com/register/6725661396735089756?source=BC</description><pubDate>07 May 2025 15:51 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lolqtqv25s2b</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3loj4f5b2pk2n</link><description>New Cyber Triage release with:&#xA;* New UIs to give you an overview of the endpoint&#xA;* Hyabusa integration&#xA;* Baseline&#xA;* Public key encryption on collector&#xA;* LOTS more....&#xA;&#xA;Blog and Download Link: https://www.cybertriage.com/blog/3-14-release-brings-new-uis-hayabusa-baselining-and-much-more/</description><pubDate>06 May 2025 14:39 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3loj4f5b2pk2n</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lo4mtedgg22b</link><description>EDR Evasion 101 - Blocking&#xA;&#xA;Data needs to get to the EDR server to be analyzed for attacks. Blocking techniques prevent data from getting to the server.&#xA;&#xA;Example: Network filter to block packets destined to the server.&#xA;&#xA;www.cybertriage.com/edr_evasion</description><pubDate>01 May 2025 15:29 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lo4mtedgg22b</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lmx433cx522x</link><description>EDR Evasion 101&#xA;Types of Evasion Tactics&#xA;&#xA;1) Blinding - prevent agent from seeing&#xA;2) Blocking - prevent data from analysis&#xA;3) Hiding - prevent detections&#xA;&#xA;https://www.cybertriage.com/blog/how-edr-evasion-works-attacker-tactics/</description><pubDate>16 Apr 2025 17:20 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lmx433cx522x</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lmx3wzw6as2x</link><description>Webinar Tomorrow @ 11AM&#xA;Endpoint Triage from 4 experts (I get to moderate)&#xA;&#xA;- Harlan Carvey (Huntress)&#xA;-  Kai Thomsen (Dragos)&#xA;- Quinnlan Varcoe (Blueberry Security)&#xA;- Mike Wilkinson (Sleuth Kit Labs)&#xA;&#xA;Each presents their top 3!&#xA;&#xA;Hope to see you there: https://register.gotowebinar.com/register/600430551977945693</description><pubDate>16 Apr 2025 17:18 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lmx3wzw6as2x</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3llrasdpwcs2m</link><description>Learn from 4 IR experts on how they do Endpoint Triage. &#xA;&#xA;Apr 17. &#xA;&#xA;I&#39;ll MC and you&#39;ll hear from @keydet89.bsky.social (Huntress), Kai Thomsen (Dragos), @dfirmike.bsky.social (Sleuth Kit Labs) and Quinnlan Varcoe (Blueberry Security).&#xA;&#xA;See you there!&#xA;&#xA;https://register.gotowebinar.com/register/600430551977945693?source=BS</description><pubDate>01 Apr 2025 16:04 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3llrasdpwcs2m</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3llc25zkeh22k</link><description>EDRs miss activity! 😲😱. &#xA;You should not miss webinar tmrw! 😀&#xA;&#xA;Markus and I will talk about why EDR alerts could be days after an attack started. &#xA;&#xA;We&#39;ll talk about how to do endpoint triage to see what else happened beyond the alert!&#xA;&#xA;Mar 27 @ 11 Eastern&#xA;&#xA;https://register.gotowebinar.com/register/9169201743748537433</description><pubDate>26 Mar 2025 14:55 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3llc25zkeh22k</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lkvdilagqs2k</link><description>For those in the #SOC: Alert Triage vs Endpoint Triage&#xA;&#xA;Blog post that is part of our Endpoint Triage series. &#xA;&#xA;Alert triage focuses on validating and prioritizing the EDR/SIEM alert.&#xA;&#xA;Endpoint triage focuses on prioritizing the host. How bad is it?&#xA;&#xA;https://www.cybertriage.com/blog/alert-triage-vs-endpoint-triage/</description><pubDate>21 Mar 2025 13:38 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lkvdilagqs2k</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lk4w7yvmgk2e</link><description>New Autopsy release is out!  🎉 &#xA;&#xA;It&#39;s been a minute, but it&#39;s out. Notable features are BitLocker support and it can run side-by-side with Cyber Triage.  Plus, a bunch of library updates. &#xA;&#xA;Now Cyber Triage and Autopsy can be used on the same case at the same time! &#xA;&#xA;https://www.autopsy.com/autopsy-4-22-0-bitlocker-support-cyber-triage-sidecar-library-updates/</description><pubDate>11 Mar 2025 20:36 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lk4w7yvmgk2e</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3liz6mg26vk2o</link><description>I&#39;m doing a webinar TMRW on investigation tools for endpoint triage. Basic idea is how to get quick and accurate results after an alert. EDR data plays a role in that, but it&#39;s not enough. &#xA;&#xA;Endpoint Triage should be in any security team&#39;s process. &#xA;&#xA;https://attendee.gotowebinar.com/register/281552387805466969?source=Brian+BS&#xA;https://attendee.gotowebinar.com/register/281552387805466969?source=Brian+LI</description><pubDate>25 Feb 2025 15:30 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3liz6mg26vk2o</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lhvzqsdcbc2q</link><description>3 places to automate #DFIR Endpoint Triage. Which do you do?</description><pubDate>11 Feb 2025 16:00 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lhvzqsdcbc2q</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lheztxtmsk2z</link><description>The 3 themes we focus on for #DFIR endpoint triage. What are yours?</description><pubDate>04 Feb 2025 21:47 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lheztxtmsk2z</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lhc7g4cdg223</link><pubDate>03 Feb 2025 18:48 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lhc7g4cdg223</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lh277b7rhs2v</link><pubDate>31 Jan 2025 14:23 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lh277b7rhs2v</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lgv6jqe2us2h</link><description>Endpoint triage allows you to prioritize your response after an EDR alert. &#xA;&#xA;Webinar: Tomorrow at 11 - Vendor Agnostic&#xA;https://register.gotowebinar.com/register/1427199522892126556?source=BC</description><pubDate>29 Jan 2025 14:28 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lgv6jqe2us2h</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lgstyhudus2q</link><description>Endpoint Triage: What you do after you validate the EDR alert to understand the impact. &#xA;&#xA;#DFIR Webinar Thu @ 11. &#xA;&#xA;https://register.gotowebinar.com/register/1427199522892126556?source=BC</description><pubDate>28 Jan 2025 16:14 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lgstyhudus2q</guid></item><item><link>https://bsky.app/profile/carrier4n6.bsky.social/post/3lgqhs7poc22q</link><description>We&#39;re using the term &#34;Information Artifacts&#34; for high-level #DFIR concepts like &#34;Processes&#34; and &#34;Inbound Logins&#34;. I think they are easier to train than low-level Prefetch, UserAssist etc. (i.e. Data Artifacts). Those map to an Info Artifact (Prefetch -&gt; Process).&#xA;&#xA;https://www.cybertriage.com/blog/information-artifacts-simplify-dfir-analysis/</description><pubDate>27 Jan 2025 17:30 +0000</pubDate><guid isPermaLink="false">at://did:plc:i56ryptuywjrwthm3h4d7dpb/app.bsky.feed.post/3lgqhs7poc22q</guid></item></channel></rss>