@ArsenalRecon

Developers of digital forensics weapons which include Arsenal Image Mounter, Hibernation Recon, LevelDB Recon, HBIN Recon, & Registry Recon. Arm Yourself! #DFIR

Boston
Joined August 2012
Arm yourself with our tools & eliminate blind spots in digital forensics! ArsenalRecon.com #DFIR
2
6
2,459
Check out the first draft of our guide "Using Windows x64 to Build IntelWinFE with AIM Remote Agent" & please let us know if you have any suggestions! ArsenalRecon.com #DFIR
9
1
16
914
ARMWinFE & AIM Remote Agent in action!
Have you considered building WinFE on Arm (a/k/a ARMWinFE) or perhaps tried, but were unsuccessful? Check out the first draft of our guide "Using Windows x64 to Build ARMWinFE with AIM Remote Agent." ArsenalRecon.com #DFIR
3
7
929
Have you considered building WinFE on Arm (a/k/a ARMWinFE) or perhaps tried, but were unsuccessful? Check out the first draft of our guide "Using Windows x64 to Build ARMWinFE with AIM Remote Agent." ArsenalRecon.com #DFIR
2
1
2
1,205
Did you know that LevelDB Recon can recover data from partially overwritten (corrupt) LevelDB files? Here’s a short video of LevelDB files being ingested from The TechHive Scenario (a Windows on Arm disk image) & some quick geolocation analysis. ArsenalRecon.com #DFIR
2
3
353
How do you analyze Windows hibernation? Did you know that Hibernation Recon’s core functionality is free? Here’s a brief demonstration of Hibernation Recon running against The TechHive Scenario, a publicly-accessible Windows on Arm disk image. ArsenalRecon.com #DFIR
1
2
342
What have your digital forensics instructors told you about the analysis of Windows swap? Have they explained that without the use of Swap Recon you are blind to massive volumes of data? ArsenalRecon.com #DFIR
4
7
698
Our digital forensics tools have put extremely powerful & fundamentally unique functionality into the hands of our customers for ~15 years. If you're a #DFIR practitioner, it's in your best interest (& those you serve) to be aware of what we're doing! ArsenalRecon.com
2
2
11
710
The new Arsenal Image Mounter includes many Recon Report enhancements. Can you see how the new hardware information might come in useful? ArsenalRecon.com #DFIR
2
4
454
Did you know that the latest Arsenal Image Mounter exposes BitLocker metadata in Free Mode that is unavailable from manage-bde & elsewhere? Check out these screenshots to see some examples made possible by our new BitLocker library. ArsenalRecon.com #DFIR
3
6
525
Arsenal Image Mounter v3.13.368 just released with even more powerful & unique BitLocker functionality (Free & Professional Modes!) thanks to a new BitLocker library developed by Joakim Schicht & many late nights from Olof Lagerkvist. ArsenalRecon.com #DFIR
1
8
9
1,347
One of our summer interns has been spending a lot of time with LevelDB... here's a couple screenshots of Olek using the new LevelDB Recon to decode a JSON Web Token (JWT) from The TechHive Scenario (a publicly-accessible Windows on Arm disk image). ArsenalRecon.com #DFIR
2
6
549
Check out LevelDB Recon's new Content Viewer identifying latitude/longitude coordinates in a key/value pair's embedded JSON (within our publicly accessible disk image, The TechHive Scenario) & displaying them on a map. ArsenalRecon.com #DFIR
1
7
611
Just released LevelDB Recon v1.0.0.62 with a new "Content Viewer" that displays embedded data in a more human-friendly manner & much more, see the change log for details! ArsenalRecon.com #DFIR
3
7
734
The "TechHive Scenario" is a Windows on Arm disk image we made available to the public via NIST CFReDS (cfreds.nist.gov/all/MarkSpen…) about a month ago. Have you used it for #DFIR training or R&D? We just used it for LevelDB Recon R&D, here's a couple internal build screenshots.
2
4
311
Have you thought about how Hibernation Recon could be used to gain new insight into your highest-stakes cold cases? We released a new version (v1.2.3.96) yesterday with significant updates. ArsenalRecon.com #DFIR
Hibernation Recon has recovered smoking guns in some of the highest-stakes cases involving digital forensics anywhere, ever. Here's a network packet recovered from the third level of a NetWire victim's Windows hibernation slack involving file transfer to an attacker's C2. #DFIR
1
3
691
Hibernation Recon has recovered smoking guns in some of the highest-stakes cases involving digital forensics anywhere, ever. Here's a network packet recovered from the third level of a NetWire victim's Windows hibernation slack involving file transfer to an attacker's C2. #DFIR
6
1
17
2,941
Here's the new Hibernation Recon running on Windows on Arm (WoA) & processing WoA, Windows x64, & Windows x86 hibernation (hiberfil.sys) files! We continue to put extremely powerful & unique functionality in the hands of #DFIR practitioners. Arm yourself! ArsenalRecon.com
2
5
598
Here's the new Hibernation Recon (v1.2.3.96) in action! What do you notice about Windows architecture support? Did you know that Hibernation Recon also supports hibernation from Windows XP through the latest build of 11? ArsenalRecon.com #DFIR
2
2
481
We just released Hibernation Recon v1.2.3.96 with some awesome updates - Windows 24H2 & 25H2 support, new decompression algorithms, now runs on Windows on Arm & Linux, etc. How do you analyze Windows hibernation? ArsenalRecon.com #DFIR
4
5
402
Back in the office after sponsoring & exhibiting at the @IACIS 2026 Orlando Training Conference. It was great meeting so many digital forensics practitioners in person! We brought a Neo Geo for students to play towards the end of training... next year we'll have prizes! #DFIR
1
5
383