
Vikas Singh
@vikas891
Followers
469
Following
518
Media
96
Statuses
284
I do DF/IR @KrollWire GX-IH. GCIH. GCFA. Lethal Forensicator. DFIR Netwars Champion.
Ahmedabad, India
Joined January 2012
RT @RusEmbIndia: Happy Republic Day, #India! . From Russia with love β€οΈ. #RepublicDay2024 #RussiaIndia #Π΄ΡΡΠΆΠ±Π°ΰ€¦ΰ₯ΰ€Έΰ₯ΰ€€ΰ₯
0
4K
0
It's a really nice initiative, Phil! I have some ideas, I can't wait to contribute. Also, thank you for the mention π.
I made a thing, based on the excellent work of other people and some of my own experience. It's ok for a v1, but it still needs work to make it more useful. I'm still learning proper source management, so it's a start. #DFIR.
0
0
2
RT @EricRZimmerman: @SwiftOnSecurity if youve never tried EVTXECmd for event logs, try it. take your favorite logs, generate CSV, load intoβ¦.
0
1
0
Instead of selecting the Hive along with transaction logs, saving them as System_Clean, do this instead. Select the Hive. Hold Shift while clicking on Open! .@chad ππ .Tool: Reg Explorer by @EricRZimmerman
1
0
2
Interested in Cloud Forensics? .Check out my latest blogpost which walks you through a simulated breach within an AWS environment. We'll ingest AWS CoudTrail in Splunk and run queries - it's all free and exciting! π.#FOR509 @PwnedLabs .
vikas-singh.notion.site
Introduction
1
8
29
Pretty excited to announce my 11 Year workiversary by smashing the π of IR certifications out there. 25 Practical Questions mimicking real world scenarios. I so wanted to choose GX-CS because it looked easier π but switched to GX-IH!.@CertifyGIAC πDM for Coupon Collab maybe?
2
0
6
π«‘.
Peter Mackenzie, Director of Incident Response, shares details on the MOVEIt software exploit, how to protect against #SupplyChain attacks and more on @BBCNews:
0
0
0
DFIR nerds, here's a helpful bookmark for you. Remote Access Software (ab)used by adversaries. Of course the list is looong, but we have to start somewhere, right? .. @MITREattack T1219
0
0
2
Malware Persistence? .Windows Scheduled Tasks β Linux Cronjobs. A quick refresher attached from a Live case. You can also grep your way through to which user had it installed if it isn't a system-wide job. @SentinelOne Terminal Color Scheme βπ
0
1
4
I wrote my first KAPE Module! It parses Windows Tasks XMLs recursively to give you a neat CSV as an output!.Read: Happy Holidays ππ
.#forensics
0
4
10