banner
beercow.bsky.social
@beercow.bsky.social
410 followers 190 following 58 posts
"Distrust and caution are the parents of security." - Benjamin Franklin https://malwaremaloney.blogspot.com
Posts Media Videos Starter Packs
Adding a parser for Microsoft.FilesOnDemand.db to OneDriveExplorer. Yet another source to rebuild the user’s OnDrive. More to come. #DFIR
Correct me if I’m wrong bit what you described is Xbox from day one.
That time of year again when everybody starts abbreviating cybersecurity awareness month as CSAM. 21 pages deep of google searches for that term and not a single mention of cybersecurity awareness month. Go figure.
Appears OneDrive snuck a new sync client in. Works with personal accounts at the moment. It’s WebView2. You can find data in the following locations:
AppData\Local\Microsoft\OneDrive\OD4
AppData\Local\Microsoft\OneDrive\Logs\OD4
Where are my browser forensics experts at? #DFIR
Updated OneDrive Evolution. You can now compare two versions of OneDrive and see what has changed. #DFIR

malwaremaloney.blogspot.com/p/onedrive-e...
Today we learned Fishrocket (the one with the doughnut) has cancer. It’s an aggressive form of mast cell tumors. Treatment usually involves removing them but there are too many. They prescribe prednisone because they itch. Has diabetes so can’t give him prednisone. Poor guy.
Reposted
1/ I successfully tested a LSASS dumping technique on a Windows 10 lab machine, which we encountered on a recent Incident Response engagement (no EDR, default Defender installed).

The "MiniDumpWriteDump" technique, as described here [1], was successful in writing the LSASS process to disk.
Another interesting forensic artifact in OneDrive. UXDatabase.db
New folder and databases in the OneDrive sync client. Not sure what feature they are tied to yet. More to come. #DFIR
New laptop, new stickes. 😜
Been a little while. Was busy adding support for Microsoft.FileUsageSync.db to OneDriveExplorer. Update brings in data on files shared via email, Teams, SharePoint and more. Thank you Heather Barnhart for the bug report on search function issues. #DFIR

malwaremaloney.blogspot.com/2025/05/oned...
MALoney (It's in the name): OneDriveExplorer now supports Microsoft.FileUsageSync.db
Recently, I have been focused on adding support for Microsoft.FileUsageSync.db. See my previous post on Microsoft.FileUsag...
malwaremaloney.blogspot.com
15 strips would have at least been correct.
Ah gotcha. I threw some on the stick table also. It was nice meeting you.
Did you snag them from CypherCon?
Hmmmm. What are we up to here? 🤔