Up early on a holiday weekend, working on ransomware DFIR... just like all of my other colleagues. Sharing your frustration and disappointment. Thank you for your efforts.
This pages contain my list of Recommended Reading books related to #DFIR & #infosec:
dfir.org/?q=node/8
If you know of a book written in the last 2-3 years that is missing then please let me know so that I can review it!
When I get to BTRFS it will be a series of blog posts like my earlier EXT4 and XFS work. But it's going to take a big case with a lot of BTRFS to get me to do that research.
For your weekend reading pleasure, I'm happy to announce a small update to my Linux Forensics class-- now with a new module on EXT4 and some fixes of previous errata. Always free at archive.org/details/HalLinux…
Hey folks, your ransomware encrypted endpoints are EVIDENCE and need to be treated as such. PLEASE preserve copies before beginning the process of restoring operations.