Sign in

Doug Metz

@dwmetz.bsky.social
220 followers 285 following 119 posts

#DFIR 🫆@ Magnet Forensics Blog ✍️ @ BakerStreetForensics.com Projects 🦀 @ Github.com/dwmetz Opinions are my own and are subject to change.

PostsRepliesMedia
Doug Metz @dwmetz.bsky.social · 30/09/2026
Hey wait… I know that guy ;)
001
Reposted by Doug Metz
Sara Gibbs @sararoseg.bsky.social · 07/09/2026
Our audience for It’s a Superpower?? is building steadily - the next bit is going to be the hard part. We are doing this all on our own - no corporations & funded out of our own pockets. What we need is evangelists. If you enjoyed this show & it feels important to you, here’s how you can help 1/
15032
Doug Metz @dwmetz.bsky.social · 31/08/2026
A Non-DFIR Post: Come Have a Drink at 221B.bar Some of you found your way to Baker Street Forensics because you're Sherlockians first, and forensicators second. An unfathomable number of you showed up just for the 'Lack Rack'. And the rest of you, my trusted readers as King would say, are probably…
bakerstreetforensics.com
A Non-DFIR Post: Come Have a Drink at 221B.bar
Some of you found your way to Baker Street Forensics because you're Sherlockians first, and forensicators second. An unfathomable number of you showed up just for the 'Lack Rack'. And the rest of you, my trusted readers as King would say, are probably wondering what any of this has to do with disk images and timelines. Nothing. That's the point.
000
Doug Metz @dwmetz.bsky.social · 20/08/2026
Once again (and for the nth time too many) - expecting this to be @theonion.com and instead it’s our reality. #WTF #FDT
000
Reposted by Doug Metz
evacide @evacide.bsky.social · 26/07/2026
Just pump this directly into my veins. It looks perfect.
917217
Doug Metz @dwmetz.bsky.social · 23/07/2026
MalChela v4.3 Version 4.3 introduces significant updates, including an At A Glance panel on the Home Screen displaying case statuses and integrations. New features include an Offline Mode for air-gapped scenarios, enhanced analysis tools, improved string detection capabilities in mStrings, and 25…
bakerstreetforensics.com
MalChela v4.3
Version 4.3 introduces significant updates, including an At A Glance panel on the Home Screen displaying case statuses and integrations. New features include an Offline Mode for air-gapped scenarios, enhanced analysis tools, improved string detection capabilities in mStrings, and 25 additional detection rules. Comprehensive documentation updates accompany these enhancements.
010
Doug Metz @dwmetz.bsky.social · 20/07/2026
MalChela 4.2 Release MalChela v4.2 introduces improved functionality for Mac analysis, allowing four tools to interact directly with .app bundles, eliminating the need to find buried binaries. The new Analyze feature simplifies the triage process by automatically classifying files and dispatching…
bakerstreetforensics.com
MalChela 4.2 Release
MalChela v4.2 introduces improved functionality for Mac analysis, allowing four tools to interact directly with .app bundles, eliminating the need to find buried binaries. The new Analyze feature simplifies the triage process by automatically classifying files and dispatching necessary tools, streamlining malware analysis and reporting with concise summaries.
010
Reposted by Doug Metz
Magnet Forensics @magnetforensics.bsky.social · 09/07/2026
Join us July 29 at 11:00 AM ET for a live and interactive Ask Me Anything (#AMA) session with seasoned #DFIR practitioners as they tackle your toughest #IncidentResponse questions and share practical guidance from real-world investigations. Register now: ow.ly/RaYh50ZmchU
012
Doug Metz @dwmetz.bsky.social · 19/05/2026
Where did I save that? Introducing Mind Palace — a free, open-source macOS menu bar app. It indexes Apple Notes, Safari Reading List, and any local folders you choose, and lets you search all of them from one place. Download: lnkd.in/e9A23DKw Learn more: bakerstreetforensics.com/mind-palace-2/
bakerstreetforensics.com
Mind Palace
Mind Palace is a free macOS menu bar app that indexes your Apple Notes, Safari Reading List, and local folders into a single, instantly searchable knowledge base — all on your own machine, with not…
000
Doug Metz @dwmetz.bsky.social · 16/05/2026
Mind Palace: A Personal Search Engine for the Way I Actually Work "I consider that a man's brain originally is like a little empty attic, and you have to stock it with such furniture as you choose." — Sherlock Holmes, A Study in Scarlet There's a particular kind of frustration that I suspect a lot…
bakerstreetforensics.com
Mind Palace: A Personal Search Engine for the Way I Actually Work
"I consider that a man's brain originally is like a little empty attic, and you have to stock it with such furniture as you choose." — Sherlock Holmes, A Study in Scarlet There's a particular kind of frustration that I suspect a lot of researchers know well: you're in the middle of something, an analysis, a blog post, a deck, and you know you've written or read or bookmarked something about this before.
000
Doug Metz @dwmetz.bsky.social · 06/05/2026
MalChela v4.1: Mac Malware Analysis Arrives MalChela v4.1 is out today, and the headline is something I've been wanting to tackle for a while: dedicated Mac malware analysis tooling. If you've been following the channel or the blog, you know MalChela started as a triage-first toolkit aimed at the…
bakerstreetforensics.com
MalChela v4.1: Mac Malware Analysis Arrives
MalChela v4.1 is out today, and the headline is something I've been wanting to tackle for a while: dedicated Mac malware analysis tooling. If you've been following the channel or the blog, you know MalChela started as a triage-first toolkit aimed at the kinds of samples that show up in Windows-centric IR engagements. That coverage was never the full picture. Mac malware — infostealers, adware loaders, APT implants — has become too common to treat as an edge case.
000
Doug Metz @dwmetz.bsky.social · 02/05/2026
Unmasking the Moon: Comparing LunaStealer Samples with MalChela and Claude As one tends to do on Saturday mornings with coffee in hand, I was reviewing two samples that were attributed to the LunaStealer / LunaGrabber family. Originally I was validating that tiquery was working with the MCP…
bakerstreetforensics.com
Unmasking the Moon: Comparing LunaStealer Samples with MalChela and Claude
As one tends to do on Saturday mornings with coffee in hand, I was reviewing two samples that were attributed to the LunaStealer / LunaGrabber family. Originally I was validating that tiquery was working with the MCP configuration, however what started as a quick TI check turned into a full static analysis session — and it gave me a good opportunity to put the MalChela MCP integration through its paces in a real workflow.
000
Doug Metz @dwmetz.bsky.social · 01/05/2026
The Long Game: MalChela v4.0 When I started building MalChela, I had a narrow problem to solve. I was doing a lot of malware triage during incident response engagements and I kept reaching for the same scattered set of tools — VirusTotal, some strings extraction, a hash lookup here, a YARA scan…
bakerstreetforensics.com
The Long Game: MalChela v4.0
When I started building MalChela, I had a narrow problem to solve. I was doing a lot of malware triage during incident response engagements and I kept reaching for the same scattered set of tools — VirusTotal, some strings extraction, a hash lookup here, a YARA scan there. The workflow existed, but it wasn't a workflow. It was a series of scripts and context switches dressed up as a process.
000
Doug Metz @dwmetz.bsky.social · 25/04/2026
From QR to Threat Identification in one Click Recently I introduced Threat Intel Query (tiquery), a multi-source threat intelligence lookup tool. The first iteration expanded on the capability of malhash and enabled for the submission of malware hashes against multiple threat intel sites. Then…
bakerstreetforensics.com
From QR to Threat Identification in one Click
Recently I introduced Threat Intel Query (tiquery), a multi-source threat intelligence lookup tool. The first iteration expanded on the capability of malhash and enabled for the submission of malware hashes against multiple threat intel sites. Then yesterday I was targeted with an SMS phishing message. (Note: I don't know why but I detest the term 'smishing', or any of the other '
000
Doug Metz @dwmetz.bsky.social · 17/04/2026
MalChela 3.2: More Cowbell? More Intel! One of the things I value most about the open-source community is that the best improvements to a tool often don’t come from inside it — they come from outside conversations.  A short while back, the author of mlget, xorhex,  reached out and suggested I add…
bakerstreetforensics.com
MalChela 3.2: More Cowbell? More Intel!
One of the things I value most about the open-source community is that the best improvements to a tool often don’t come from inside it — they come from outside conversations.  A short while back, the author of mlget, xorhex,  reached out and suggested I add more malware retrieval sources to FOSSOR, one of my earlier tools for pulling down samples from threat intel repositories.  
011
Doug Metz @dwmetz.bsky.social · 21/03/2026
Just got an email for a “Cyber Easter” sale. Can we please stop making everything Cyber? Yes I wrote CyberPipe and host Cyber Unpacked… but still…
An AI image of Jesus rising in a cyber apocalyptic landscape
000
Doug Metz @dwmetz.bsky.social · 18/03/2026
A Study in DFIR: Open-Source, Enterprise, and the Art of Analysis Someone asked me recently how I see DFIR evolving — tooling, automation, and open-source versus enterprise platforms. It's the kind of question that sounds like a conference panel topic, but the answer is grounded in how work…
bakerstreetforensics.com
A Study in DFIR: Open-Source, Enterprise, and the Art of Analysis
Someone asked me recently how I see DFIR evolving — tooling, automation, and open-source versus enterprise platforms. It's the kind of question that sounds like a conference panel topic, but the answer is grounded in how work actually gets done. In practice, it isn't a binary choice. The most effective IR practitioners I've worked with use a combination of both commercial and open-source tools, depending on the problem in front of them.
010
Doug Metz @dwmetz.bsky.social · 11/03/2026
New YouTube Video series covering the free open-source YARA & Malware Analysis toolkit, MalChela. Covers installation, Initial static analysis, YARA rule creation, REMnux integration and more.
bakerstreetforensics.com
The Game Is Afoot: Introducing the MalChela Video Series
There's a moment every analyst knows — the one where an unknown file lands on your desk and the clock starts ticking. You need answers, and you need them fast. MalChela was built for exactly that moment. Today I'm excited to announce the MalChela Video Series on YouTube — a growing collection of tutorial episodes walking through real malware analysis workflows using…
000
Doug Metz @dwmetz.bsky.social · 03/03/2026
MalChela Meets AI: Three Paths to Smarter Malware Analysis In a previous post I wrote about integrating MalChela with OpenCode on REMnux and giving the AI a quick briefing on the tool suite so it could incorporate them into its analysis workflow. That was a promising proof of concept, but it…
bakerstreetforensics.com
MalChela Meets AI: Three Paths to Smarter Malware Analysis
In a previous post I wrote about integrating MalChela with OpenCode on REMnux and giving the AI a quick briefing on the tool suite so it could incorporate them into its analysis workflow. That was a promising proof of concept, but it raised a natural follow-up question: how do you make these integrations more robust, reproducible, and persistent? Since that post, I've been experimenting with three different approaches to bringing MalChela into AI-assisted workflows — each suited to a different environment and use case.
010
Reposted by Doug Metz
Brett Shavers @brettshavers.bsky.social · 20/02/2026
On Feb 24 at Magnet's FREE virtual summit, @dwmetz.bsky.social and I will be talking about DF and IR, but not about "DFIR", if you know what I mean. magnetvirtualsummit.com/registration... #DFIR
122
Doug Metz @dwmetz.bsky.social · 19/02/2026
@aaroncti.bsky.social interested in seeing the platform
010
Doug Metz @dwmetz.bsky.social · 10/02/2026
Streamline Malware Hash Search with FOSSOR We’ve all encountered this scenario: you’re reading a threat report from CISA or Microsoft and come across hashes related to a malware infection. You start copying these hashes and head to one of your favorite virus repositories to check if there’s a…
bakerstreetforensics.com
Streamline Malware Hash Search with FOSSOR
We’ve all encountered this scenario: you’re reading a threat report from CISA or Microsoft and come across hashes related to a malware infection. You start copying these hashes and head to one of your favorite virus repositories to check if there’s a source available for download so you can analyze the malware yourself. Unfortunately, you don’t find a match. So, you move on to another site and repeat the process.
000
Doug Metz @dwmetz.bsky.social · 09/02/2026
Enhancing Malware Analysis with REMnux and AI Those familiar with my work know that I’m a big fan of the REMnux Linux distribution for malware analysis. When I developed MalChela, I included a custom configuration that can be invoked that not only includes the MalChela tool suite but also…
bakerstreetforensics.com
Enhancing Malware Analysis with REMnux and AI
Those familiar with my work know that I’m a big fan of the REMnux Linux distribution for malware analysis. When I developed MalChela, I included a custom configuration that can be invoked that not only includes the MalChela tool suite but also integrates many of the CLI tools installed in REMnux, providing an easy-to-use GUI. Recently, a new REMnux release was released on Ubuntu 24.04.
000
Doug Metz @dwmetz.bsky.social · 05/12/2025
Wrapping up 2025 with the year in code, including the evolution of MalChela for malware analysis, streamlined CyberPipe tools, and the introduction of Toby, a portable forensics platform. Focus was on creating practical solutions for #DFIR professionals and students for triage and #MalwareAnalysis
bakerstreetforensics.com
2025 Year in Review: Open Source DFIR Tools and Malware Analysis Projects
In 2025, significant advancements in DFIR toolkit development were achieved, including the evolution of MalChela for malware analysis, streamlined CyberPipe tools, and the introduction of Toby, a portable forensics platform. The focus was on creating practical solutions for digital forensics professionals, with all tools available as open-source on GitHub. #DFIR #MalwareAnalysis #OpenSource
020
Reposted by Doug Metz
Darth Tugmutton @sheeparecheaper.bsky.social · 22/11/2025
531378
Doug Metz @dwmetz.bsky.social · 22/11/2025
What a start…
010
Doug Metz @dwmetz.bsky.social · 05/11/2025
CyberPipe-Timeliner was developed to integrate Magnet Response collections with ForensicTimeliner. This tool automates the workflow of EZTools, and transforms collection data into a unified forensic timeline. #DFIR
bakerstreetforensics.com
CyberPipe-Timeliner: From Collection to Timeline in One Script
CyberPipe-Timeliner was developed in response to a colleague's query about integrating Magnet Response collections with ForensicTimeliner. This tool automates the workflow, transforming collection data into a unified forensic timeline. With features like date filtering and flexible input options, it streamlines the timeline generation process, making it efficient and user-friendly. #DFIR
021
Doug Metz @dwmetz.bsky.social · 04/11/2025
CyberPipe v5.3: Enhanced PowerShell Compatibility and Reliability I'm pleased to announce the release of CyberPipe v5.3, bringing critical compatibility improvements for Windows PowerShell 5.1 and enhanced reliability across all PowerShell environments. The Problem After releasing v5.2 with the…
bakerstreetforensics.com
CyberPipe v5.3: Enhanced PowerShell Compatibility and Reliability
I'm pleased to announce the release of CyberPipe v5.3, bringing critical compatibility improvements for Windows PowerShell 5.1 and enhanced reliability across all PowerShell environments. The Problem After releasing v5.2 with the new unified banner design, several users reported an interesting issue: CyberPipe would execute perfectly in PowerShell Core, but in Windows PowerShell 5.1, the script would complete the Magnet Response collection successfully—then immediately fail with an exit code error and stop before running EDD and BitLocker key recovery.
010
Reposted by Doug Metz
Kris 🎃 HORRORchild @direkris.itch.io · 23/10/2025
You'll pry these Oxford commas out of my cold, dead, third thing hands
121380479
Doug Metz @dwmetz.bsky.social · 20/10/2025
When you’re paranoid but any old tin foil hat won’t do. a.co/d/1GvRbfT
a.co
Gardava Faraday Beanie Protection Hat - Blocks 99.9% E.M.Fs, 5G, WiFi, R.adiation, 3rd Party Tested, Unisex-Adults, Black at Amazon Men’s Clothing store
Buy Gardava Faraday Beanie Protection Hat - Blocks 99.9% E.M.Fs, 5G, WiFi, R.adiation, 3rd Party Tested, Unisex-Adults, Black: Shop top fashion brands Skullies & Beanies at Amazon.com ✓ FREE DELIVERY ...
000
Doug Metz @dwmetz.bsky.social · 16/10/2025
CyberPipe, a PowerShell script for digital evidence collection, has been updated with enhancements in collection, capabilities, and reliability. New features include intelligent collection with dual disk space validation, a QuickTriage profile, and improved BitLocker recovery. #DFIR
bakerstreetforensics.com
Streamline Digital Evidence Collection with CyberPipe 5.2
CyberPipe, developed for incident response, is a PowerShell script facilitating efficient digital evidence collection in enterprise settings. Recent updates include improved collection methods, capabilities like QuickTriage for faster artifact gathering, and enhanced reliability with advanced error handling. Version 5.2 aims to streamline operations while ensuring forensic integrity and transparency. #DFIR
032
Doug Metz @dwmetz.bsky.social · 10/10/2025
Swore I was reading @theonion.com
010
Doug Metz @dwmetz.bsky.social · 07/10/2025
A trick and a treat this week with a quiet milestone for cross-platform DFIR tooling — MalChelaGUI now runs seamlessly inside Windows through Ubuntu WSL2, with zero configuration required. #DFIR #MalwareAnalysis
bakerstreetforensics.com
Cross-Platform DFIR Tools: MalChelaGUI on Windows
A trick and a treat this week with a quiet milestone for cross-platform DFIR tooling — MalChelaGUI now runs seamlessly inside Windows through Ubuntu WSL2, with zero configuration required. #DFIR #MalwareAnalysis
021
Reposted by Doug Metz
Magnet Forensics @magnetforensics.bsky.social · 25/09/2025
On Oct 8, join us for a special episode of #CyberUnpacked where hosts @dwmetz.bsky.social & Jeff Rutherford will bring together a panel of #DFIR leaders to explore top challenges investigative teams face and the state of #DigitalInvestigations today: ow.ly/jRVq50X2r0L
ow.ly
S2:E4 // Voices from the field: Trends, challenges, and what’s next in DFIR - Magnet Forensics
Digital Forensics and Incident Response (DFIR) has evolved rapidly from purely reactive investigations to incorporating proactive approaches that utilize cloud-powered forensics and AI. But while the ...
021
Reposted by Doug Metz
George Takei @georgetakei.bsky.social · 30/08/2025
Masked ICE aren’t about safety; they’re about fear and evading responsibility. Demand transparency and accountability by adding your name to this petition:
thepetitionsite.com
Sign Petition: Stop Masked Immigration Raids. This Is Not How a Democracy Operates.
These agents are using masks to shield themselves from accountability for their willingness to participate in dangerous overreach. (51529 signatures on petition)
18268642024
Doug Metz @dwmetz.bsky.social · 27/08/2025
In DFIR, reliable storage is essential for effective workflows. Crabwise, a USB benchmarking utility, addresses performance variability by calculating read and write speeds under direct conditions, bypassing caching and logs results for easy comparison. #DFIR
bakerstreetforensics.com
Is your USB device slowing down your forensic investigation?
In digital forensics, reliable storage is essential for effective workflows. Crabwise, a USB benchmarking utility, addresses performance variability by calculating read and write speeds under direct conditions, bypassing caching. It logs results for easy comparison, allowing users to optimize connections. This tool ensures informed decisions on hardware setups, improving efficiency and consistency in forensics tasks.
011
Doug Metz @dwmetz.bsky.social · 02/08/2025
MalChela 3.0.2 introduces MITRE Lookup, a tool that allows forensic investigators to search the MITRE ATT&CK framework offline. This feature enhances investigation speed by supporting keyword and Technique ID searches while providing tactic categories and detection guidance. #DFIR #MalwareAnalysis
bakerstreetforensics.com
Enhance Threat Hunting with MITRE Lookup in MalChela 3.0.2
The recent update of MalChela 3.0.2 introduces MITRE Lookup, a tool that allows forensic investigators to search the MITRE ATT&CK framework offline. This feature enhances investigation speed by supporting keyword and Technique ID searches while providing tactic categories and detection guidance. Users can save results directly for future reference, enhancing analysis efficiency.
020
Doug Metz @dwmetz.bsky.social · 30/07/2025
💙🐕 Toby ! :)
000
Doug Metz @dwmetz.bsky.social · 29/07/2025
Toby-Find is a terminal-based tool designed for digital forensics, providing users with an easy way to discover command-line tools available in KALI and REMnux. It allows quick searches for tools, descriptions, and examples, enhancing usability in forensic analysis. #DFIR #MalwareAnalysis
bakerstreetforensics.com
Toby-Find: Simplifying Command-Line Forensics Tools
Toby-Find is a terminal-based tool designed for digital forensics, providing users with an easy way to discover command-line tools available in KALI and REMnux. Initially created for a university course, it allows quick searches for tools, descriptions, and examples, enhancing usability in forensic analysis without memorization or manual searching.
000
Doug Metz @dwmetz.bsky.social · 28/07/2025
🎯 MalChela v3.0.1 is live Sharper strings. Smarter signals. This update includes: ✅ Improved mstrings output and MITRE mappings 🧠 Smarter regex 🔎 Built-in MITRE technique lookup (GUI) 📁 FileMiner gets “select all” + subtool optimizations 🦀 Compiled for performance #DFIR #MalwareAnalysis
bakerstreetforensics.com
Sharper Strings and Smarter Signals: MalChela 3.0.1
🎯 MalChela v3.0.1 is live Sharper strings. Smarter signals. This update tightens forensic detection across the board: • ✅ Improved mstrings output and MITRE mappings • 🔎 Built-in MITRE technique lookup (GUI) • 📁 FileMiner gets “select all” + subtool optimizations • 🧠 Smarter regex, better signal-to-noise for analysts • 🦀 Compiled & tuned for --release performance Still a one-crab shop, but contributions welcome. 👉 🧰 Docs: #DFIR #MalwareAnalysis
010
Doug Metz @dwmetz.bsky.social · 22/07/2025
A MalChela 🦀 sighting in the wild
Photo of a small crab on the beach
000
Doug Metz @dwmetz.bsky.social · 20/07/2025
Portable Forensics with Toby: A Raspberry Pi Toolkit Toby is a compact, portable forensics toolkit built on a Raspberry Pi Zero 2 W, designed for ease of use in field analysis and malware triage. bakerstreetforensics.com/2025/07/20/p... #DFIR #MalwareAnalysis #RaspberryPi
bakerstreetforensics.com
Portable Forensics with Toby: A Raspberry Pi Toolkit
Toby is a compact, portable forensics toolkit built on a Raspberry Pi Zero 2 W, designed for ease of use in field analysis and malware triage. It operates headlessly via SSH or VNC, supports variou…
132
Doug Metz @dwmetz.bsky.social · 05/07/2025
Happy terrorize the dogs and veterans to all who celebrate.
000
Doug Metz @dwmetz.bsky.social · 23/06/2025
Still a work in progress but very happy with my GaZendo (gazebo/zendo) so far…
Gazebo painted in the colors of a Japanese tea house, set in a large area of stone pebbles, with a dark path with 8 stepping stones leading to entrance.
000
Doug Metz @dwmetz.bsky.social · 21/06/2025
If you’re working in #MalwareAnalysis I’d appreciate it if you gave MalChela a try and share your feedback. There’s a very comprehensive user guide to get started. github.com/dwmetz/MalCh...
github.com
000
Doug Metz @dwmetz.bsky.social · 21/06/2025
MalChela v3.0 enhances investigative workflows by introducing cases for organization, replacing MismatchMiner with FileMiner for improved file analysis, and suggesting tools based on file characteristics, streamlining the analysis process. #MalChela #DFIR #MalwareAnalysis
bakerstreetforensics.com
MalChela v3.0: Case Management, FileMiner, and Smarter Triage
MalChela v3.0 enhances investigative workflows by introducing cases for organization, replacing MismatchMiner with FileMiner for improved file analysis, and suggesting tools based on file characteristics, streamlining the analysis process. #MalChela #DFIR #MalwareAnalysis
001
Doug Metz @dwmetz.bsky.social · 26/05/2025
Hashes for the Masses: Finding What Matters in a Sea of Samples #DFIR #MalwareAnalysis #Hash #MalChela
bakerstreetforensics.com
Hashes for the Masses: Finding What Matters in a Sea of Samples
A short while back, I released a pair of tools for building MD5 hash sets — one targeting known-good gold builds, the other designed for scanning malware corpora. The goal was simple: generate hash sets that could be used in forensics tools like Axiom Cyber to flag IOC matches during case processing. Recently, I hit a familiar problem: I had a hash and wanted to know if that file existed in my malware library.
011
Doug Metz @dwmetz.bsky.social · 21/05/2025
MalChela 2.2 “REMnux” Release More tools. More Docs. More Power. #DFIR #MalwareAnalysis #YaraX #Volatility #Tshark #MalChela
bakerstreetforensics.com
MalChela 2.2 “REMnux” Release
MalChela’s 2.2 update is packed with practical and platform-friendly improvements. It includes native support for REMnux, better tool settings, and deeper integrations with analysis tools like YARA-X, Tshark, Volatility3, and the newly improved fileanalyzer module. 🦀 REMnux Edition: Built-In Support, Zero Tweaks When the GUI loads a REMnux-specific tools.yaml profile, it enters REMnux mode.
011
Doug Metz @dwmetz.bsky.social · 08/05/2025
CyberPipe v5.1 is out with a few targeted improvements to make live response a bit smoother. Collection profiles can now be passed directly as arguments using -CollectionProfile. No need to modify the script or hardcode anything… bakerstreetforensics.com/2025/05/08/c... #DFIR
bakerstreetforensics.com
CyberPipe v5.1 – Streamlined Profiles, Better Flexibility
CyberPipe v5.1 is out with a few targeted improvements to make live response a bit smoother. What’s New: Collection profiles can now be passed directly as arguments using -CollectionProfile. No nee…
001
Doug Metz @dwmetz.bsky.social · 02/05/2025
Teepublic was kind enough to arrange a 30% + discount on MalChela swag to coordinate with the new release. Head on over and grab yourself something while the sale lasts. ~14 hrs. to go #DFIR #MalwareAnalysis #Rust www.teepublic.com/t-shirt/7325...
teepublic.com
MalChela by baker-street-forensics
MalChela - the Rust based YARA and Malware analysis toolkit.
000