DEV Community

#dfir

Digital Forensics and Incident Response procedures, tools, and case studies.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Why I Built My Cloud-Native DFIR Pipeline (And Ditched AWS/OpenSearch for BigQuery)

Why I Built My Cloud-Native DFIR Pipeline (And Ditched AWS/OpenSearch for BigQuery)

Comments
2 min read
agent-trace-witness v0.1.0: signed readiness seal, post-execution capture, and PROV-DM causal graphs for autonomous AI agents

agent-trace-witness v0.1.0: signed readiness seal, post-execution capture, and PROV-DM causal graphs for autonomous AI agents

5
Comments
8 min read
High-Throughput Linux Audit Logging with Vector & ClickHouse DFIR Pipeline

High-Throughput Linux Audit Logging with Vector & ClickHouse DFIR Pipeline

Comments
4 min read
When Your AI Agent Gets Breached, Can You Prove What It Did?

When Your AI Agent Gets Breached, Can You Prove What It Did?

Comments 2
3 min read
I built an autonomous DFIR agent on Qwen Cloud that refuses to trust itself

I built an autonomous DFIR agent on Qwen Cloud that refuses to trust itself

Comments
6 min read
Reconstructing cloud identity intrusions from O365 and CloudTrail logs

Reconstructing cloud identity intrusions from O365 and CloudTrail logs

2
Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.