Generated by All in One SEO v4.9.10, this is an llms.txt file, used by LLMs to index the site. # Ponder The Bits Musings and confusings. All things DFIR. ## Posts - [Generating File System Listings from the Command Line (with Full MACB Timestamps and Hashes)](https://ponderthebits.com/2018/02/generating-file-system-listings-from-the-command-line-with-full-macb-timestamps-and-hashes/) - Generating file system listings from the command line on both Linux and Mac/OSX using only native utilities, with full MACB timestamps and MD5/SHA1 hashes. - [Quick(er) Mounting and Dismounting of LVM’s on Forensic Images](https://ponderthebits.com/2017/03/quicker-mounting-and-dismounting-of-lvms-on-forensic-images/) - An explanation of, and cheat sheet for, successfully mounting LVM's spread across a variety of forensic image formats. - [OSX (Mac) Memory Acquisition and Analysis Using OSXpmem and Volatility](https://ponderthebits.com/2017/02/osx-mac-memory-acquisition-and-analysis-using-osxpmem-and-volatility/) - Acquiring OSX (Mac) memory using OSXpmem and generating a memory profile for analysis using Volatility. - [Windows RDP-Related Event Logs: Identification, Tracking, and Investigation](https://ponderthebits.com/2018/02/windows-rdp-related-event-logs-identification-tracking-and-investigation/) - A cohesive and comprehensive walk-through of the most common and empirically useful RDP-related Windows Event Log Sources and ID's, grouped by stage of occurrence (Connection, Authentication, Logon, Disconnect/Reconnect, Logoff). - [Mac Dumpster Diving - Identifying Deleted File References in the Trash (.DS_Store) Files - Part 1](https://ponderthebits.com/2017/01/mac-dumpster-diving-identifying-deleted-file-references-in-the-trash-ds_store-files-part-1/) - Part 1/2. A walkthrough of identifying historical references to deleted files (often with full paths on disk) within users' .Trash/.DS_Store files. - [Decompressing and Extracting Artifacts from Windows 8 / Server 2012+ Hibernation Files](https://ponderthebits.com/2017/07/decompressing-and-extracting-artifacts-from-windows-8-server-2012-hibernation-files/) - Decompressing Windows 8/Server 2012+ Hibernation files with Hibernation Recon, and extracting artifacts using Strings, Page_Brute, Bulk_Extractor, and Volatility. - [The Importance of Incident Scoping/Assessment](https://ponderthebits.com/2017/03/the-importance-of-incident-scopingassessment/) - A baseline set of questions and information critical to properly scoping/assessing/understanding an incident for effective and efficient incident response. - [Mac Dumpster Diving - Identifying Deleted File References in the Trash (.DS_Store) Files - Part 2](https://ponderthebits.com/2017/02/mac-dumpster-diving-identifying-deleted-file-references-in-the-trash-ds_store-files-part-2/) - Part 2/2. A walkthrough of how historical references to deleted files (often with full paths on disk) are re-populated within users' .Trash/.DS_Store files. - [Know Your Tools: Linux (GNU) vs. Mac (BSD) Command Line Utilities](https://ponderthebits.com/2017/01/know-your-tools-linux-gnu-vs-mac-bsd-command-line-utilities-grep-strings-sed-and-find/) - Learn some of the major differences between core Linux (GNU) and Mac (BSD) command line utilities, along with tips and tricks for DFIR analysis. - [Knowing Your Tools](https://ponderthebits.com/2017/01/knowing-your-tools/) - It is critical to know and understand your FOSS and commercial tools for DFIR investigations. - [A Response to "The Cloud is Evil..."](https://ponderthebits.com/2017/01/a-response-to-the-cloud-is-evil/) - My response and input to "The Cloud is Evil...". - [DFIR Community Inspirations](https://ponderthebits.com/2016/12/dfir-community-inspirations/) - DFIR Community Inspirations. - [Hello. Whirled.](https://ponderthebits.com/2016/12/hello-whirled/) - Intro to my DFIR blog. ## Pages - [Presentations & Podcasts](https://ponderthebits.com/presentations-podcasts/) - Presentations I've given and podcasts on which I've been. - [About](https://ponderthebits.com/about/) - Jonathon Poling has over a decade of experience in Incident Response and Forensics, with expertise spanning all major operating systems (Windows, Linux, Mac, and Cloud/AWS). - [DFIR Resources](https://ponderthebits.com/dfir-resources/) - DFIR Resources ## Categories - [Uncategorized](https://ponderthebits.com/category/uncategorized/) - [Inspirations](https://ponderthebits.com/category/inspirations/) - [DFIR Community](https://ponderthebits.com/category/dfir-community/) - [Introduction](https://ponderthebits.com/category/introduction/) - [Know Your Tools](https://ponderthebits.com/category/know-your-tools/) - [Tools](https://ponderthebits.com/category/tools/) - [Command Line](https://ponderthebits.com/category/command-line/) - [Linux](https://ponderthebits.com/category/linux/) - [Mac](https://ponderthebits.com/category/mac/) - [AWS](https://ponderthebits.com/category/aws/) - [Azure](https://ponderthebits.com/category/azure/) - [Cloud](https://ponderthebits.com/category/cloud/) - [OSX](https://ponderthebits.com/category/osx/) - [Volatility](https://ponderthebits.com/category/volatility/) - [Yara](https://ponderthebits.com/category/yara/) - [Rekall](https://ponderthebits.com/category/rekall/) - [osxpmem](https://ponderthebits.com/category/osxpmem/) - [Scoping](https://ponderthebits.com/category/scoping/) - [Assessment](https://ponderthebits.com/category/assessment/) - [Incident Response](https://ponderthebits.com/category/incident-response/) - [Forensics](https://ponderthebits.com/category/forensics/) - [LVM](https://ponderthebits.com/category/lvm/) - [VMDK](https://ponderthebits.com/category/vmdk/) - [Hibernation File](https://ponderthebits.com/category/hibernation-file/) - [Hibernation Recon](https://ponderthebits.com/category/hibernation-recon/) - [Windows](https://ponderthebits.com/category/windows/) - [Event Logs](https://ponderthebits.com/category/event-logs/) - [Remote Desktop](https://ponderthebits.com/category/remote-desktop/) - [RDP](https://ponderthebits.com/category/rdp/)