The Forensic Lunch with David Cowen and Matthew Seyer

Follow The Forensic Lunch with David Cowen and Matthew Seyer
Share on
Copy link to clipboard

The Forensic Lunch! The one hour, mostly, live digital forensics and incident response focused video cast and podcast.


    • Sep 9, 2020 LATEST EPISODE
    • infrequent NEW EPISODES
    • 1h 1m AVG DURATION
    • 100 EPISODES


    Search for episodes from The Forensic Lunch with David Cowen and Matthew Seyer with a specific topic:

    Latest episodes from The Forensic Lunch with David Cowen and Matthew Seyer

    Forensic Lunch 8-28-20

    Play Episode Listen Later Sep 9, 2020 59:17


    The Forensic Lunch! This week with Willi Ballenthin from the Mandiant FLARE Team talking about their tools

    Forensic Lunch 8-14-20

    Play Episode Listen Later Sep 9, 2020 40:37


    The Forensic Lunch! This week with Sarah Edwards and Jared Barnhart talking about iphone testing labs, app testing and decoding apple photos machine learning identified photo metadata

    Forensic Lunch 7-24-20

    Play Episode Listen Later Sep 9, 2020 61:51


    Forensic Lunch! This week with Jordan Barth talking about Azure and the Cloud!

    Forensic Lunch 6-26-20

    Play Episode Listen Later Sep 9, 2020 74:36


    Forensic Lunch! This week it's time for the second Annual National Collegiate Cyber Defense Competition Redteam AMA!

    Forensic Lunch 6-19-20

    Play Episode Listen Later Sep 9, 2020 78:16


    Forensic Lunch! This week with Google Incident Response Management Team! Learn how Google does IR Management and hear from Joachim Metz, James Nettesheim, Matt Linton and Alex Jager

    Forensic Lunch 6-12-20

    Play Episode Listen Later Sep 9, 2020 73:16


    Forensic Lunch! This week with Eric Zimmerman showing SQLite Explorer and Javier Marcos discussing OSCtrl for OSQuery

    Forensic Lunch 5-29-20

    Play Episode Listen Later Sep 9, 2020 67:21


    Forensic Lunch! This week with Yogesh Kahtri talking about MAC_APT, Brian Moran and Yuri Gubanov from Belkasoft

    Forensic Lunch 5-22-20

    Play Episode Listen Later Sep 9, 2020 90:33


    Forensic Lunch! This week with Michael Cohen doing an hour and a half of Velociraptor!

    Forensic Lunch 5-15-20

    Play Episode Listen Later Sep 9, 2020 64:41


    The Forensic Lunch! This week we are bringing Jad Saliba and Jessica Hyde from Magnet talking about the month of great content they've been hosting and the new things coming out of Magnet. In addition we will have the winner of the Magnet Virtual CTF 2020!

    Forensic Lunch 5/8/20 - Jack Farley, Josh Brunty, Kevin Pagano, Tom Pace, Jim Arnold

    Play Episode Listen Later May 9, 2020 77:01


    This week on the Forensic Lunch we had: Josh Brunty, @joshbrunty,  talking about his DFIR program at Marshall   https://www.marshall.edu/cyber/ Tom Pace of Blackberry Cyclance and Jim Arnold of KPMG talking about recent ransomware trends.  Kevin Pagano, @kevpagano3,  talking about his Sunday Funday and the Magnet Virtual CTF  Jack Farley, @jackfarley248,  talking about MEAT and the Magnet Virtual CTF  https://github.com/jfarley248/MEAT     You can watch it here: https://youtu.be/fPzSm-hofA0

    Forensic Lunch 5/1/20 - Oleg Skulkin (FeatureUsage), Brian Marks (Office 365) , Lee Whitfield 4CAST

    Play Episode Listen Later May 1, 2020 85:07


          This week the Forensic Lunch went into Overtime! We went a full 25 minutes over the usual hour because we had so much to talk about. On this weeks show:   Matt Seyer (@forensic_matt) talked all about the etl parser and monitor he's working on in Rust! https://github.com/forensicmatt/RsWindowsThingies Oleg Skulkin (@oskulkin) talked about how he approaches Sunday Funday's (he's won 3!) and about his new blog post about the Windows FeatureUsage artifact.  https://www.group-ib.com/blog/featureusage Brian Marks (@briandfir) talked about how the Office365 UAL MailboxItemsAccessed Audit event works and what the entry details mean   Lee Whitfield (@lee_whitfield ) talked through the Forensic 4Cast Awards nominations that end in two weeks, and Matt and I gave who we will be nominating. https://forensic4cast.com/2020/02/2020-forensic-4cast-awards-nominations-are-open/  

    Forensic Lunch 4/24/20 with the Google IR Team (GRR, Timesketch, Turbinia, DTTimewolf, More!)

    Play Episode Listen Later Apr 24, 2020 77:52


      We had a jam packed Forensic Lunch today with a portion of the Google IR team today talking all about the open source tools they develop, use and support in their work at Google.   Specifically we had : Mikhail Bushkov giving a big update on GRR https://github.com/google/grr Johan Berggren (https://twitter.com/jberggren) and Kristinn Gudjonsson (https://twitter.com/el_killerdwarf) talking about Timesketch and Data science https://github.com/google/timesketch Aaron Peterson (https://twitter.com/aarontpeterson) talking about Turbinia https://github.com/google/turbinia Thomas Chopitea (https://twitter.com/tomchop_) talking about DTTimewolf https://github.com/log2timeline/dftimewolf Theo Giovanna talking about libcloudforensics aka cloudforensicutils https://github.com/google/cloud-forensics-utils/tree/master/libcloudforensics Joachin Metz (https://twitter.com/joachimmetz) - Talking about Plaso, libntfs and Libyal Plaso: https://github.com/log2timeline/plaso  Libfsntfs: https://github.com/libyal/libfsntfs Libyal: https://github.com/libyal Join them on the Open Source DFIR Slack: https://join-open-source-dfir-slack.herokuapp.com/   Read more about what they are doing on the Open Source DFIR Blog: https://osdfir.blogspot.com/

    Forensic Lunch 4/17/20 with Zach Wasserman

    Play Episode Listen Later Apr 17, 2020 65:35


      Today on the Forensic Lunch we only had one guest, Zach Wasserman, from OSQuery technical steering committee. We only had one guest because we knew we would have so much to talk to Zach about! From OSQuery's future in the linux foundation, Kollide Fleet and other fleet managers to Zach's work at Dactiv, LLC you have alot waiting for you in this weeks broadcast.   You can reach Zach Wasserman on twitter @TheZachW or Zach can be reached at zach@dactiv.llc if you want to work with him!  

    Forensic Lunch 4/10/20 with Belkasoft, AWS IR Automation, MVS DFIRFIT and HTTP Security Headers

    Play Episode Listen Later Apr 15, 2020 65:33


    What a great Forensic Lunch today! On today's broadcast we had: Yuri Gubanov (@belkasoft) giving an update about whats going on at Belkasoft. Including their IOS 13.4 full file system acquisition using Checkm8, their new IR module in Belkasoft Evidence Center and a neat capability to do managed remote logical phone collections. Steve Gibson and Spencer Hendee (@stevegibson) from KPMG (disclaimer I work there too!) came on to discuss the really cool AWS Cloud IR Automation we've been working on. Brian Moran (@brimorlabs) social media maven and principal of BriMorLabs came on to discuss the Magnet Virtual Summit DFIRFIT 2020 where for a donation (and some excercise) you can get a cool prize pack shipped to you anywhere in the world! Register here: https://mvsdfirfit2020.com Caleb Queern (@HttpSecHeaders) also of KPMG came on to discuss the clearsite HTTP header. This was interesting as its a directive a website can give to a browser to tell it to clear/not store history or data about it. This will need to be tested, you can read more here https://w3c.github.io/webappsec-clear-site-data/ So great stuff this week, you can watch below. Otherwise next week we've already confirmed Zach Wasserman to come and talk about OSQuery and Kollide!

    Forensic Lunch 4/3/20

    Play Episode Listen Later Apr 15, 2020 58:11


    On this episode:   Mari Degrazia (@MariDegrazia) discussing her research into WinSCP and later movement, you can read more here: http://az4n6.blogspot.com/2020/02/detecting-laterial-movment-with-winscp.html Hal Pomeranz (@hal_pomeranz) talking about his new Linux Forensics course that you can download here: https://ia801406.us.archive.org/6/items/HalLinuxForensics/HalLinuxForens ics_archive.torrent Alex Levinson (@alexlevinson) Gave an update on the National Collegiate Cyber Defense Competition which as gone all virtual this year Matt Seyer (forensic_matt) talked about our upcoming SANS DFIR presentation and tools he's working on Sarah Edwards (@iamevltwin) gave colorful commentary and meaningful insights 

    Forensic Lunch 12/13/19 - CTI Summit

    Play Episode Listen Later Apr 15, 2020 58:45


    Live with Rick Holland, Ryan Johnson and Evan Dygert

    Forensic Lunch 10/25/19 - Champlain DFA Defcon DFIR CTF - Martin Korman - Regipy

    Play Episode Listen Later Apr 15, 2020 58:34


    The Forensic Lunch! This week with the Champlain Digital Forensics Association talking about the Defcon DFIR CTF and Martin Korman talking about his project regipy

    Forensic Lunch 7/19/19 with Alex Levinson

    Play Episode Listen Later Apr 15, 2020 51:00


    This week with Alex Levinson from Uber

    Forensic Lunch 5/3/19 CCDC AMA Live

    Play Episode Listen Later Apr 15, 2020 137:20


    The Forensic Lunch! Sli.do link https://app2.sli.do/event/hzkazryr/live/questions This broadcast we are doing a live AMA from Reddit all about the NCCDC Redteam

    Forensic Lunch 4/3/19 Live from MUS 2019

    Play Episode Listen Later Apr 15, 2020 35:18


    The Forensic Lunch! Live from the Magnet User Summit 2019!

    Forensic Lunch 3/20/20 - Lance Spitzner and Jessica Hyde

    Play Episode Listen Later Apr 15, 2020 57:24


    with Lance Spitzner talking about Sans Live Online, Jessica Hyde talking about the Magnet Virtual Summit

    Forensic Lunch 3/8/19 Eric Zimmerman, Lee Whitfield , Kape, Forensic 4Cast, Nominations

    Play Episode Listen Later Apr 15, 2020 61:34


    The Forensic Lunch 3/8/19! The twice a month, usually, podcast/videocast that's all about DFIR This week we have: Eric Zimmerman, talking about KAPE Lee Whitfield, talking about the Forensic 4Cast award nominations

    Forensic Lunch 2/21/20 - Anzac Edition

    Play Episode Listen Later Apr 15, 2020 74:56


    Forensic Lunch ANZAC edition with Michael Cohen talking about Velociraptor Shanna Daly talking about her work in Australia Phil Moore, Nick Klein talking about their new entity and thisweekin4n6

    Forensic Lunch 2/7/20 - Blackbag Update

    Play Episode Listen Later Apr 15, 2020 59:43


    Forensic Lunch with Sarah Edwards, Ashley Hernandez , Dr Joe Sylve catching us up with the new combined Celebrite/Blackbag  

    Forensic Lunch 2/1/19 Blanche Lagny Amcache DFIR Review

    Play Episode Listen Later Apr 15, 2020 62:12


    The Forensic Lunch 2/1/19! The twice a month, usually, podcast/videocast that's all about DFIR This week we have: Blanche Lagny talking about her paper on Amcache The DFIR Review crew talking about .. DFIR Review! crew entails: Jessica Hyde Vico Marziale Brett Shavers Tony Knutson

    Forensic Lunch 1/24/20 - Ryan Benson, Jessica Hyde and Aaron Sparling

    Play Episode Listen Later Apr 15, 2020 63:20


    Forensic Lunch! Live with Ryan Benson talking about Unfurl, Jessica Hyde and Aaron Sparling talking about Memory forensics

    Forensic Lunch 1/10/20 with Lee Whitfield

    Play Episode Listen Later Apr 15, 2020 60:03


    This week Lee Whitfield joins us to discuss the DFIR Summit and Matt showed us his rust based live windows monitors for DFIR Research

    Forensic Lunch 6/15/18

    Play Episode Listen Later Jun 15, 2018 58:56


    The Forensic Lunch! Live this week with jaco_za who walked us through how he won the Magnet User Summit CTF we built.

    Forensic Lunch 6/8/18

    Play Episode Listen Later Jun 15, 2018 29:03


    Live from the DFIR Summit in Austin, Texas.   This short episode we had Rob Lee talking about the new Windows Forensics Poster and Lee Whitfield talking about the Forensic 4cast awards.

    Forensic Lunch 5/21/18

    Play Episode Listen Later May 23, 2018 60:31


    Live from the Magnet User Summit in Las Vegas with Jessica Hyde, Heather Mahalik, Jad Saliba, Matthew Seyer and David Cowen

    Forensic Lunch 5/18/18

    Play Episode Listen Later May 20, 2018 64:42


    Live with Jason Jordaan talking about DFIR in South Africa, James Cooksey talking about Belkasoft, Troy Schnack talking about his work and being nominated for Forensicator of the Year, Matthew Seyer and David Cowen

    Forensic Lunch 5/4/18

    Play Episode Listen Later May 20, 2018 62:33


    Live with Maxime Lamothe-Brassard, Nicole Ibrahim, Matthew Seyer and David Cowen talking about ETLs, the SANS DFIR Summit, and Lima Charlie

    Forensic Lunch 4/20/18

    Play Episode Listen Later May 20, 2018 64:35


    Live with Lee Whitfield, Matthew Seyer and David Cowen talking about the Forensic 4Cast award Nominees

    Forensic Lunch: 4/6/18

    Play Episode Listen Later May 20, 2018 50:33


    The Forensic Lunch live with Matthew Seyer and David Cowen talking about how Office saves files and more testing

    Forensic Lunch 3/9/18

    Play Episode Listen Later May 20, 2018 59:38


    Live with Maxim Suhanov (@errno_fail), Matthew Seyer and David Cowen talking about Registry Forensics, Transactional Registry logs and his library YARP

    Forensic Lunch 3/2/18

    Play Episode Listen Later May 20, 2018 51:08


    Live with Eric Zimmerman, Matthew Seyer and David Cowen talking about Registry Explorer and transactional registries

    Forensic Lunch 2/23/18

    Play Episode Listen Later May 20, 2018 67:12


    Live with Phill Moore, Dr. Bradley Schatz, Matthew Seyer and David Cowen talking about This week in forensics and Evimetry

    Forensic Lunch 2/16/18

    Play Episode Listen Later May 20, 2018 66:17


    Live with Ashley Hernandez, Joe Sylve, Matthew Seyer and David Cowen talking about Blacklight and Blackbag

    Forensic Lunch 1/26/18

    Play Episode Listen Later May 20, 2018 70:24


    Forensic Lunch Live with Devon Ackerman, Matthew Seyer and David Cowen. Devon Ackerman presented on Office365 forensics

    Forensic Lunch 1/19/18

    Play Episode Listen Later May 20, 2018 35:46


    Forensic Lunch Live with Lee Whitfield, Matthew Seyer and David Cowen

    Forensic Lunch Test Kicthen 12/7/17

    Play Episode Listen Later May 20, 2018 73:45


    Forensic Lunch Test Kitchen live DFIR testing on 12/7/17

    Forensic Lunch Test Kitchen 12/6/17

    Play Episode Listen Later May 20, 2018 71:26


    Forensic Lunch Test Kitchen live DFIR testing on 12/6/17

    Forensic Lunch Test Kitchen 12/5/17

    Play Episode Listen Later May 20, 2018 93:37


    Forensic Lunch Test Kitchen live DFIR testing on 12/5/17

    Forensic Lunch Test Kitchen 12/4/17

    Play Episode Listen Later May 20, 2018 58:52


    The Forensic Lunch Test Kitchen 12/4/17, live testing of forensic artifacts

    Forensic Lunch 10/17/17

    Play Episode Listen Later May 20, 2018 29:06


    The Forensic Lunch live with Mark Mckinnon, Brian Moran, Brian Carrier and Jessica Hyde

    Forensic Lunch 10/13/17

    Play Episode Listen Later May 20, 2018 1:21


    The Forensic Lunch live with Rebekah Brown

    Forensic Lunch 8/18/17

    Play Episode Listen Later May 20, 2018 46:57


    The Forensic Lunch with Chuck Norris, correlation in Arrango DB and shellbags testing

    Forensic Lunch 8/11/17

    Play Episode Listen Later May 20, 2018 63:37


    Forensic Lunch With Elizabeth Schweinsberg talking about DFRWS

    Forensic Lunch 7/14/17

    Play Episode Listen Later May 20, 2018 57:42


    The Forensic Lunch with Mary Ellen Kennel and Devon Ackerman talking about the AbourDFIR project

    Forensic Lunch 5/26/17

    Play Episode Listen Later May 18, 2018 61:16


    This week Jessica Hyde and Brian Moran joined us talking about their research into Amazon Alexa and Google Home.

    Forensic Lunch 5/25/17

    Play Episode Listen Later May 18, 2018 79:20


    Live From Enfuse Day 3! This week with Lesley Carhart, @hacks4pancakes talking about being the very first Women in Technology solving for X award presented by Guidance Software, hacks4kids and her dfir research interests Dr. Bradley Shatz, @wirespeed4n6, talking about DFRWS evimetry, aff4 and his new advanced imager Ashley Hernandez, @ashleyatencase, talking about all the new things coming from guidance regarding Encase Forensic, Endpoint investigator and mobile acquisition/examiner

    Claim The Forensic Lunch with David Cowen and Matthew Seyer

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel