Anti-Forensics - You are Doing it Wrong (Believe Me, Im an IR Consultant) @FIRSTdotorg
Anti-Forensics - You are Doing it Wrong (Believe Me, Im an IR Consultant)  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 1 hour ago
Stephan Berger (InfoGuard AG, CH)

Stephan Berger has over a decade of experience in cybersecurity. Currently working with the Swiss-based company InfoGuard, Stephan investigates breaches and hacked networks as Head of Investigation of the Incident Response team. An avid Twitter user under the handle @malmoeb, he actively shares insights on cybersecurity trends and developments. Stephan also authors the blog DFIR.ch, where he provides in-depth analysis and commentary on digital forensics and incident response. Stephan has spoken at numerous conferences, sharing his expertise with audiences worldwide.
--
In this talk, we'll dissect common anti-forensics strategies -- like USN Journal deletion, shellbag clearing, timestamp manipulation, and disabling access time updates -- and reveal how they are often executed ineffectively or misunderstood. We'll explore practical examples, such as:- Deleting the USN Journal (fsutil usn deletejournal /d C:) and why it's rarely a perfect solution.- Clearing shellbags to wipe file explorer history but failing to account for deeper registry artifacts.- Time stomping (Get-Item "C:pathtofile.txt").CreationTime = "2022-01-01 00:00:00) and how forensic tools detect inconsistencies.- Disabling last access time updates (fsutil behavior set disablelastaccess 1) and its limited effectiveness against comprehensive timeline analysis.- Wiping MFT free space (sdelete -z C:) while ignoring the traces left behind in unstructured data.From registry edits like masking user account activity to configuring Windows EFS, we'll examine why these techniques often fail against modern investigative workflows and how defenders use these "footprints of erasure" to uncover malicious intent.Attendees will gain a comprehensive understanding of what works and what doesn't and how to identify these techniques during incident response. Whether you're an IR consultant, security analyst, or blue teamer, this talk offers actionable knowledge to outsmart adversarial anti-forensics tactics.We use Python code to show how 'clean' evidence cleaning can be done, e.g., if only individual MFT entries are deleted or even if entries in the SRUM database are deleted or manipulated. This means it is not immediately obvious that the data has been manipulated, unlike when everything is deleted.
Anti-Forensics - You are Doing it Wrong (Believe Me, Im an IR Consultant)What Can Cybersecurity Incident Responders Learn from Real-World Crises?Enhancing Incident Response with AWS CIRT, MSSPs, and ISVsEpisode 55: Merike Kaeo, FIRSTCON26 Program ChairProactive EDR Against Adaptive Evasion: Countering Self‑Modifying Agentic MalwareProduction Is the New Attack Surface: Why Post-Deployment Endpoint Detection Is Now CriticalOROCHIFY - An Assist to Product Developers in Manufacturing Industry to Find VulnerabilitiesRemediation-Aware Reachability: Patching Containers, Prioritizing with Agentic-CTI, and Scaling...Threat Hunting with Python & PandasEpisode 56: Mor Weinberger and Lior Kaplan, FIRSTCON26 SpeakersBuilding a Regional ISAC for West Africa that Works: Governance, Tools and Community MaturityThe EUs Cybersecurity Resilience Act (CRA) has Begun – How Can Manufacturers Confidently Addres ...
FIRST |

Anti-Forensics - You are Doing it Wrong (Believe Me, I'm an IR Consultant)

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER