Ryan Benson

1K posts

Ryan Benson banner
Ryan Benson

Ryan Benson

@_RyanBenson

I do digital forensics and work on open source DFIR tools @Google. I kinda like web browsers, too. Not on Twitter often anymore, reach me at ryan 'at' https://t.co/Zcq6BJG4xC

SF Bay Area Katılım Nisan 2009
265 Takip Edilen4.4K Takipçiler
Sabitlenmiş Tweet
Ryan Benson
Ryan Benson@_RyanBenson·
Here's the blog post on my new tool: dfir.blog/introducing-un… Unfurl takes a URL🔗 and expands ("unfurls") it to show all the data it contains. It's amazing how much can be hidden inside URLs! Take it for a spin and tell me what interesting stuff you find🔗🌿#DFIR #Python
GIF
English
9
341
882
0
Ryan Benson retweetledi
not puppycat
not puppycat@not_puppycat·
@GergelyOrosz FYI that link in the screenshot is acquired by the user tapping "Copy Link" button from the Twitter app on iPhone. That's what the parameter "s=46" means. It's safe to also drop that from the final URL. Here's where I got the s-parameter table to look up: dfir.blog/unfurl-parsing…
English
0
1
7
0
Ryan Benson
Ryan Benson@_RyanBenson·
With all the uncertainty @Twitter, I've seen more people talking about alternatives like #Mastodon. Like tweets, Mastodon IDs have embedded timestamps in them, and Unfurl can parse them: 🔗@Gargron/109256990373721673" target="_blank" rel="nofollow noopener">dfir.blog/unfurl/?url=ht… #DFIR #OSINT
Ryan Benson tweet media
English
1
15
47
0
inversecos
inversecos@inversecos·
1\ #DFIR: Chrome Forensics - How to Recover CLEARED History If a user just cleared their browser history, you can still recover everything they were just looking at from the session files: %appdata%\Local\Google\Chrome\User Data\Default\Sessions inversecos.com/2022/10/recove…
inversecos tweet media
English
37
526
1.8K
0
Ryan Benson retweetledi
Chris Sanders 🔎 🧠
Chris Sanders 🔎 🧠@chrissanders88·
A key mindset to grasp as you transition from junior analyst to a more experienced level is that you won't have all the answers, but you can ask the right questions and know where to start looking for the answers.
English
1
15
58
0
Ryan Benson
Ryan Benson@_RyanBenson·
@WebBreacher Double-click any node and it copies the text to clipboard. I need to make that feature more visible, sorry.
English
1
0
1
0
Micah
Micah@WebBreacher·
@_RyanBenson for unfurl...when it decodes one of the long URLs I have into all the parts, I cannot select a decoded part and copy it to clipboard. I have to use CyberChef or something to recreate what unfurl does. Any way we can get a copy/paste of the nodes as text?
English
1
0
1
0
Ryan Benson
Ryan Benson@_RyanBenson·
@WebBreacher Ha, thanks 😉. I updated the logo at least for dark mode, other components will take more time.
Ryan Benson tweet media
English
0
1
1
0
Micah
Micah@WebBreacher·
@_RyanBenson LOL. It is a terrific tool! I appreciate all the work you put into it. And yes, the logo could look nicer in DM....but that was not my intent of this post!
English
1
0
0
0
Ryan Benson retweetledi
Micah
Micah@WebBreacher·
Have a long URL to decode? Use dfir.blog/unfurl/. It decodes parameters & values in the URL. Ex: I used Amazon & ran a search, copied URL, pasted into Unfurl. It broke the URL down & revealed "qid" param (2) is a time stamp and a date (3). #osint #cyber #tools
Micah tweet media
English
2
26
60
0
Ryan Benson
Ryan Benson@_RyanBenson·
@WebBreacher Thanks! Glad you like it. And after seeing your screenshot, I'll make the logo look better in dark mode ;)
English
1
0
1
0
Ryan Benson
Ryan Benson@_RyanBenson·
If you want a refresher on the benefits of allowlisting vs denylisting, just ask a 5 year old to stop doing something.
English
1
0
2
0
White Hat Inspector
White Hat Inspector@WHInspector·
Ok I am doing my first steps on browser #DFIR. I know one thing for sure: If someone steals your laptop/PC and he knows what he is doing, you are screwed. 😨😱
English
2
2
18
0
Ryan Benson retweetledi
🔎Julia Evans🔍
🔎Julia Evans🔍@b0rk·
debugging strategy: write a message asking for help
🔎Julia Evans🔍 tweet media
English
49
636
3.2K
0