Ryan Benson @hindsig.ht · 25/09/2026The Unfurl v2026.09 release adds parsers for Gmail, Safe Links, Facebook, Instagram, and GitHub, decodes more timestamps in tokens and IDs, and gives the web UI new Tree and Text views. hindsig.ht/blog/unfurl-... Check it out! 011
Ryan Benson @hindsig.ht · 21/09/2026I found www.elastic.co/security-lab... interesting for a few reasons: - the install vector for the malicious browser extension is pretty neat, and - the "customer id" is a UUIDv1 and Unfurl can extract the timestamp Unfurl on the download URL: hindsig.ht/unfurl/?url=... #DFIR #Malware #BF4SA 010
Ryan Benson @hindsig.ht · 19/09/2026dfir[.]blog is now Hindsight Foundry (hindsig.ht): a site dedicated to browser forensics research, open source tools, and related resources. hindsig.ht/blog/introdu...hindsig.htHindsight FoundryOpen source DFIR tools for digital forensics and incident response. Home of Hindsight (browser forensics) and Unfurl (URL analysis). 050
Ryan Benson @hindsig.ht · 04/05/2026There's a new Hindsight release! New features in v2026.04 include: - Parsing Sessions_* and Tabs_* files (SNSS) into the Timeline and a "Sessions" tab - Parsing of Platform Notifications (shown/clicked) - More fields for URL Visit rows (with KGraph lookups) dfir.blog/hindsight-pa... #DFIR #Chromedfir.blogHindsight v2026.04 Released!Hindsight v2026.04 adds parsing of Session files (including form data), platform notifications, & Google Knowledge Graph lookups for page categories and entities! 021
Ryan Benson @hindsig.ht · 10/02/2026Have a big number (or hex value) you found and think might be a timestamp? Drop it in `unfurl` in the terminal and see what comes out! (add -d or --detailed if you want the type of timestamp, or run without it if you just want the value) #DFIR #BF4SA #Unfurl 🌿 031
Ryan Benson @hindsig.ht · 05/02/2026There's a new Hindsight release! v2026.01 brings new features, including: 🔄 Parsing Sync Data ⌨️ Updated terminal interface 📂 Improved output formats ⚙️ Many fixes and enhancements Read more at dfir.blog/hindsight-v2... or download the new version from GitHub: github.com/obsidianfore...dfir.blogHindsight v2026.01 Released!Hindsight v2026.01 brings new features, including parsing Sync Data, an updated terminal interface, improved output formats, and dozens of fixes and enhancements. 010
Ryan Benson @hindsig.ht · 11/08/2025A new Unfurl release (unfurl.link) is here! v2025.08 has: 🆔 Parsing more from TikTok IDs (millisecond timestamp, entity type (user account, device, live session, or video), and more). Thanks to Benjamin Steel for the paper arxiv.org/abs/2504.13279 📝 Full release notes: github.com/obsidianfore... 084
Reposted by Ryan BensonMatt Johansen @mattjay.com · 17/03/2025This story is absolutely insane. And we don't usually get a front-row seat to insider threat investigations Spy got tricked by a honeypot and implicated the most senior leaders at the victim's biggest competitors. I go through it all here: youtu.be/tDG1WfbSZFo 1104
Ryan Benson @hindsig.ht · 13/03/2025Unfurl v2025.03 is live and adds new features, including: 🔎 Parsing #Google Search's UDM parameter 🐘 Recognizing #Mastodon usernames and parsing forks (like truthsocial[.]com and gab[.]com) 🧹 Utility parser to "clean up" inputs Try it: unfurl.link Blog post: dfir.blog/unfurl-parse... #DFIR #OSINTdfir.blogUnfurl 2025.03Unfurl v2025.03 adds new features, including parsing Google Search's UDM parameter, support for Mastodon forks (like Truth Social), and a utility parser to "clean up" inputs. 020
Ryan Benson @hindsig.ht · 11/03/2025There's a new Hindsight release! Hindsight v2025.03 focuses on Extensions - parsing more activity and state records, highlighting Extension permissions, and making it easier to examine Manifests. 🌐 Blog: dfir.blog/hindsight-pa... 🛠️ Tool download: hindsig.ht/release #DFIR #Chrome #Extensionsdfir.blogHindsight v2025.03 Released!Hindsight v2025.03 focuses on Extensions - parsing more activity and state records, highlighting Extension permissions, and making it easier to examine Manifests. 084
Ryan Benson @hindsig.ht · 19/02/2025A new Unfurl release is here! v2025.02 adds: 🌐 Parsing encoded/obfuscated IP addresses 🦋 Resolving #Bluesky handles to their identifiers (DIDs) and looking up their creation timestamps 🐛 Bug fixes & better bulk parsing Blog: dfir.blog/unfurl-parse... Code: github.com/obsidianfore... #DFIR #OSINTunfurl.linkunfurlExtract and Visualized Data from URLs 087
Reposted by Ryan BensonJessica Hyde @b1n2h3x.bsky.social · 10/02/2025Want to break down what is in a URL? Try Unfurl from Ryan Benson and gain further insights! dfir.blog/unfurl/ #DFIRdfir.blogunfurlExtract and Visualized Data from URLs 0178
Ryan Benson @hindsig.ht · 13/01/2025Over the winter holiday, I was watching Netflix's Carry-On and got a bit nerd-sniped by a real Google Search URL on-screen... and then proceeded to "authenticate" it. dfir.blog/authenticati... #DFIR #OSINT #Unfurl #Netflix 030
Reposted by Ryan BensonDoug Metz @dwmetz.bsky.social · 23/11/2024CTFs present challenges that you likely haven’t seen before. I’ve taken away new skills from every CTF I’ve ever participated in. 121
Reposted by Ryan BensonKevin 🤖🕵️🍺 @stark4n6.bsky.social · 21/11/2024A new episode is live now of @dfnpodcast.bsky.social www.youtube.com/live/4H9TLL8...youtube.comYouTubeShare your videos with friends, family, and the world 022
Ryan Benson @hindsig.ht · 21/11/2024Since I'm trying out #Bluesky, I figured I should add in support for it in Unfurl! The v2024.11.20 release has some minor updates, but the biggest feature is the ability to parse a timestamp from Bluesky post IDs (or atproto TIDs). Example: dfir.blog/unfurl/?url=... Give it a try at unfurl.link! 02712
Reposted by Ryan BensonJohan Berggren @jbn.the4711.net · 26/10/2023New Timesketch release is out. Two highlights: - Unfurl [1] integration, get information from URLs directly in your timeline. - DFIQ [2] support with context aware SearchHistory. Changelog: timesketch.org/changelog/#v... [1] dfiq.org [2] dfir.blog/introducing-... 002
Ryan Benson @hindsig.ht · 14/11/2024Oh hi everyone! I've missed what #DFIR Twitter used to be - here's to hoping we can get something similar going here! 2111