Brian Maloney (@bmmaloney97) 's Twitter Profile
Brian Maloney

@bmmaloney97

"Distrust and caution are the parents of security." - Benjamin Franklin

ID: 2678343348

linkhttp://malwaremaloney.blogspot.com calendar_today25-07-2014 01:33:58

5,5K Tweet

2,2K Followers

606 Following

Ali Alwashali (@ali_alwashali) 's Twitter Profile Photo

Check out this project if you wanna deep dive into AWS logging. The documented logs include a log example, detection rule and simulation command. traildiscover.cloud

Check out this project if you wanna deep dive into AWS logging. The documented logs include a log example, detection rule and simulation command. 
traildiscover.cloud
Brian Maloney (@bmmaloney97) 's Twitter Profile Photo

I just came across email information in one of the OneDrive databases. Sender, recipients, subject, mailbox, attachments, etc… Pretty much everything except the body. More to come. 🤔 #DFIR

Brian Maloney (@bmmaloney97) 's Twitter Profile Photo

I started exploring OneDrive’s FileUsageSync.bd. There is some useful information on files shared via email, Teams, etc… that may not be in the user’s OneDrive. malwaremaloney.blogspot.com/2025/02/onedri…

Brian Maloney (@bmmaloney97) 's Twitter Profile Photo

Managed to reduce the parsing of ODL files by 7 minutes over 1.8 million logs with OneDriveExplorer. From 25 min down to 18 min. Still takes a while but huge improvement.

Brian Maloney (@bmmaloney97) 's Twitter Profile Photo

Interesting thing with OneDrive Offline Mode for web. You can get the last two modification times of a file. Could come in handy. #DFIR

Interesting thing with OneDrive Offline Mode for web. You can get the last two modification times of a file. Could come in handy. #DFIR
Peter Kaloroumakis (@netfl0) 's Twitter Profile Photo

D3FEND 1.1.0 is now available. Check out our blog post on how to create D3FEND Graphs with D3FEND CAD! d3fend.mitre.org/blog/building-…

Brian Maloney (@bmmaloney97) 's Twitter Profile Photo

Been a little while. Was busy adding support for Microsoft.FileUsageSync.db to OneDriveExplorer. Update brings in data on files shared via email, Teams, SharePoint and more. Thank you Heather Mahalik Barnhart for the bug report on search function issues. #DFIR malwaremaloney.blogspot.com/2025/05/onedri…

Brian Maloney (@bmmaloney97) 's Twitter Profile Photo

Sorry for the delay in OneDrive Evolution. It appears I'm a wee bit behind. This is what happens when I go down a rabbit hole of researching data in OneDrive for 3 months. 😦

Sorry for the delay in OneDrive Evolution. It appears I'm a wee bit behind. This is what happens when I go down a rabbit hole of researching data in OneDrive for 3 months. 😦
Brian Maloney (@bmmaloney97) 's Twitter Profile Photo

Not sure if people realize it. I install every version of OneDrive that comes out and look at the data. This is to give you the best OneDrive analysis possible.

Brian Maloney (@bmmaloney97) 's Twitter Profile Photo

Catching up on my back log of OneDrive versions. Noticed the schema number has changed for SyncEngineDatabase.db. Wonder what goodies they added. 🤔

Brian Maloney (@bmmaloney97) 's Twitter Profile Photo

Nothing too interesting in the schema updates so far. Maybe I’ll see what they are up to at the next OneDrive Office Hours.

Brian Maloney (@bmmaloney97) 's Twitter Profile Photo

Found a few bugs that would cause crashes in OneDriveExplorer around ODL and FileUsageSync. Update available. github.com/Beercow/OneDri…