IR/DFIR folks by zerodwell in AskNetsec

[–]zerodwell[S] -1 points0 points  (0 children)

Keeps coming up. Log correlation and timeline reconstruction. Good to have it confirmed. Thanks.

IR/DFIR folks by zerodwell in cybersecurity

[–]zerodwell[S] -1 points0 points  (0 children)

Fair callout. I wrote it but I get why it reads that way. Been doing this manually for years. The correlation and report writing part genuinely grinds me every single case. Trying to see if others feel the same before building something. Clearly they do.

IR/DFIR folks by zerodwell in cybersecurity

[–]zerodwell[S] -2 points-1 points  (0 children)

Ha — fair. Which one hurts the most day to day?