DFIR Notes

design, build, teach threat-informed information security programs and techniques. Also: boosts of interesting classes, tools, research. (they/them)

2026-01-21

Shared a few notes on my professional development activity in Jan 2026:
1) Applied Cybersecurity Threat Intelligence course, Joe Slowik / Paralus
2) “2026 Cybersecurity Career Blueprint” , Taylor Banks / ImpactOS
3) “Rethinking Trust and Leadership” Rachel Botsman, seminar hosted by ISACA
4) We’re moving! Blog hosting updates soon, but DNS willing y’all won’t notice anything.
5) I’m counting this: writing up and posting this update. 😺
at dfirnotes.net/jan26_devel/

DFIR Notes boosted:
2026-01-07

Does anybody else type random words into the search feature and see what kind of weird rabbit holes you can climb into? Maybe that’s just me.

DFIR Notes boosted:
Kevin Lawverkpl@social.lol
2026-01-07

I think that sometimes the secret to survival is figuring out what food pairs best with your emotions and just going with it.

DFIR Notes boosted:
Jess Rosejessie
2026-01-07

The nice folks at @ghost are hiring for a product designer
- remote
- to $180k
- 4 day workweeks
- actually solid looking benefits

Put in a good word for me if you get this job?

careers.ghost.org/?lang=en

DFIR Notes boosted:

We're having a chip tunes dance party over here and I highly encourage this course of action

DFIR Notes boosted:
DFIR Notes boosted:
🦠Toxic Flange (Gurjeet)🔬⚱️🌚Toxic_Flange@infosec.exchange
2026-01-07

Oh god, i'm feeling old.. Matrix confuses me, how the heck do i join rooms on other servers without creating a new account?

#matrix

DFIR Notes boosted:
2026-01-07

if anyone knows where I can get daily index data (historical, don't need live/real time) for the Bloomberg Global Aggregate Index or FTSE World Government Bond Index - I would find that very interesting, thank you

DFIR Notes boosted:
Em :official_verified:Em0nM4stodon@infosec.exchange
2026-01-07

Periodic reminder to boost the posts you like to keep the Fediverse alive.

WE are the algorithm here :boost_ok:

#Mastodon

DFIR Notes boosted:
Otto Sulinottosulin
2026-01-07

I reluctantly agree with this blog: email encryption is a battle we can't seem to win. The oligopoly of email also makes it less appealing already anyway. I see Matrix as far better alternative as future of communications.

soatok.blog/2026/01/04/everyth

DFIR Notes boosted:
Nils Goroll 🕊️:varnishcache:slink@fosstodon.org
2026-01-07

saving a deleted post

2026 is starting with a kick: A client of ours just updated their vendor selection criteria.
TLDR; partners must be able to operate without involvement from US corps or infrastructure... and they must outline their dependencies to prove it.
Of course we/l comply by default and I'm happy to see the industry responding to this.
DFIR Notes boosted:
2026-01-07

got sent an unsolicited message like "hey do you know how to reverse engineer on macos?" yes I do and the fact that you clearly work at an AI spamming (sorry, "messaging") startup with a 20yo ceo leads me to reverse engineer that this is a suspicious situation

DFIR Notes boosted:
Sweet Home Alaberta 🇨🇦 🇺🇦 🏳️‍🌈 🏳️‍⚧️ 🇲🇽NMBA@mstdn.ca
2026-01-07

We need this desperately in Canada:
"Media literacy has been part of the Finnish educational curriculum since the 1990s, and additional courses are available for older adults who might be especially vulnerable to misinformation.

The skills are so ingrained into the culture that the Nordic nation of 5.6 million people regularly ranks at the top of the European Media Literacy Index. The index was compiled by the Open Society Institute in Sofia, Bulgaria, between 2017 and 2023."

ctvnews.ca/lifestyle/article/f

#Disinformation #EUpol #CdnPol

Finnish children learn media literacy at 3 years old. It’s protection against Russian propaganda
DFIR Notes boosted:
2026-01-07

Start considering moving your communities out of Discord now. Don’t wait for the enshittiffication to arrive, the clock is ticking. No one will listen to me, but let’s talk again later. reuters.com/business/chat-plat

Chat platform Discord files confidentially for US IPO, Bloomberg News reports
DFIR Notes boosted:
Kevin Lawverkpl@social.lol
2026-01-07

I got a 49" curved monitor and WOW can I fit a lot of distractions on this thing!

DFIR Notes boosted:

Having an extreme case of the January burn-it-all-downs, in which I question every single career and life choice and consider drastic changes.

DFIR Notes boosted:
Prof. Emily M. Bender(she/her)emilymbender@dair-community.social
2026-01-07

Anthropomorphizing language can be cute when applied to your favorite car, but it helps to muddy the discourse when applied to tech sold as "AI", especially given all the boosters and AGI-cult members peddling their nonsense about imminent artificial minds. New from me & Nanna Inie on Tech Policy Press -- how to spot & revise away from anthropomorphizing language applied to "AI":

techpolicy.press/we-need-to-ta

DFIR Notes boosted:
Dany :verified_gay:Dany@hsnl.social
2026-01-07

I felt that Microsoft Copilot, formerly known as Office, could use a mascot. So I asked Copilot to design something in the spirit of Clippy.

Let me introduce you to Sloppy, a cheerful slightly gooey assistant with glasses and a headset.

#Microslop

A blue blobish figure wearing glasses and a microphone headset, smiling.
DFIR Notes boosted:
2026-01-07

#100DaysofYARA - Day 7
@malwrhunterteam identified a suspicious file signed by "Xiamen Jialan Guang Information Technology Service Co., Ltd."

While we have a pretty good idea it'll be abused, it hasn't been yet.
So, lets watch for it to be abused.

Rule at end
1/5

DFIR Notes boosted:
Chris Sanders 🔎 🧠chrissanders88@infosec.exchange
2026-01-07

"Did the host successfully download the EXE? If so, what changes were made to the system?"

How could we improve this investigative path with stronger questions?

#SOC #DFIR

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst