Practical content from industry professionals on digital forensics · data recovery · cyber security · KVKK compliance.
A write blocker is a device that provides only read access to a storage device and blocks writes. Why the operating system silently writes to a disk, how a write blocker works, the difference between hardware and software blockers, its place in the forensic process, its importance in data recovery and common mistakes.
Read moreBrowser forensics reveals what a user did online from browser traces. The artifacts the browser keeps, data living in SQLite, the incognito reality, recovering deleted history, the examination flow and timestamp pitfalls.
Read moreSteganography is the art of hiding the existence of data; a message is concealed inside an innocent file imperceptibly. Its difference from encryption, LSB and file structure techniques, a table of steganalysis detection methods, its role in exfiltration and evidence concealment, evidence integrity and false positive risk.
Read moreEmail forensics technically examines who an email truly came from and whether it was altered. Why the sender address is not evidence, the Received lines in the header and how to read them, SPF DKIM DMARC results, how to collect it as evidence (raw .eml, hash) and common mistakes.
Read moreddrescue is a free open source tool that images a failing or bad sector disk in a way suitable for data recovery. Its difference from dd, the easy data first strategy, the vital map file, two pass basic usage, rules for working with a failing disk, where ddrescue falls short and common mistakes.
Read moreSSRF is when an attacker tricks an application into making a request on the server's behalf, and it is dangerous enough to compromise a server in the cloud. How it works, why the cloud metadata service is so critical, SSRF types, defense with an allow list, verification and the OWASP A10 framework.
Read moreBAS is a validation approach that runs known attacker techniques automatically and continuously, measuring whether your defense catches them. The difference between installed and working, how BAS works, a table comparing it with penetration testing and red teaming, what BAS cannot measure, who it suits and common mistakes.
Read moreA physical penetration test measures, under authorization, whether an attacker can physically enter a building, server room or work area. Why physical security matters as much as digital, the areas the test covers, the authorization letter, its combination with social engineering and remediation recommendations.
Read morePTaaS is a continuous, platform based model replacing the once a year classic penetration test. Why classic pentest remains a snapshot, the three components of PTaaS, its difference from an automated scanner, a comparison with classic testing, who it suits and what to watch when choosing it.
Read moreA penetration test report is a decision document, not a technical list. The report sections, what CVSS scores (0 to 10) mean, why CVSS does not know business context, exploitability as the real proof, prioritizing findings with three questions, retesting and the most common mistakes when reading a report.
Read moreSIEM is the software collecting and correlating all logs in an organization, while SOC is the team watching those alerts and responding. The difference between them, SIEM's four stages, the tiered SOC model, the most common mistakes when building them and a comparison of in house SOC versus managed SOC (MSSP).
Read moreMITRE ATT&CK is a free knowledge base cataloguing attacker behaviors observed in real attacks. The tactic and technique distinction, the 14 tactic Enterprise matrix, seeing detection gaps, mapping SIEM rules, the common language for red and blue teams, ATT&CK misconceptions and the Enterprise Mobile ICS matrix variants.
Read more