Trending
Derek Eiri's Avatar

Derek Eiri

@mreerie

Chicken herder. Corgi keeper. DFIR. mreerie.com

46
Followers
110
Following
21
Posts
06.12.2023
Joined
Posts Following

Latest posts by Derek Eiri @mreerie

Preview
Exploring frame-counts-galore and hashing pixelΒ data Derek counts all the video frames and learns a bit about hashing pixels.

I wrote a blog post counting all the video frames with Alexis Brignoni's frame-counts-galore and learn a bit about hashing pixels.

02.02.2026 13:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Extracting and Matching Faces with API Forensics’ ExponentΒ Faces Derek writes about detecting and matching faces using API Forensics’ Exponent Faces within X-Ways Forensics

Derek writes about detecting and matching faces using API Forensics’ Exponent Faces within X-Ways Forensics.

05.01.2026 13:31 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Reflecting on 2025 Derek wrote a blog post reflecting on 2025.

Derek wrote a blog post reflecting on 2025.

29.12.2025 13:33 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image

My kid has been having fun searching/finding things, so I’m gonna go with it.

25.12.2025 02:25 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
NVMe Serial Numbers with the Guardonix & USBΒ Stabilizer Derek follows up on a requested feature for DeepSpar's Guardonix and USB Stabilizer.

Derek follows up on a requested feature for DeepSpar's Guardonix and USB Stabilizer.

26.06.2025 13:01 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

I visited a LEGO store last weekend and got inspired! I’m going to see about getting a custom minifigure for it.

18.06.2025 14:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Leveling up some Digital Intelligence swag.

18.06.2025 05:12 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Exploring the macOS Native Commands Behind Andrea Lazzarotto’s Fuji When Andrea Lazzarotto publicly released Fuji (Forensic Unattended Juicy Imaging), I was actively maturing internal corporate processes to respond to security incidents involving macOS machines. Having experimented with Fuji, it became part of our overall data collection strategy as it is repeatable, accessible and efficient. As of May 2025, Fuji offers three acquisition capabilities: ASR, Rsync, and Sysdiagnose. True to Lazzarotto's goal, Fuji has a user-friendly interface that allows the examiner to logically acquire the entire drive or a single folder that is open source.

Derek explores the macOS native commands used in Andrea Lazzarotto's open-source project, Fuji.

26.05.2025 07:59 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Check out our latest Insights article "Introducing AIM Remote Agent" for some compelling use cases, screenshots, & photos involving computers booted with WinFE (Windows Forensic Environment) & disks shared over networks with Arsenal Image Mounter. arsenalrecon.com/insights/int.... #DFIR

11.03.2025 13:16 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Thought I’d do something fun. Presenting the DFIR_Toolbar. Basically a toolbar that can be anything you want it to be.

https://malwaremaloney.blogspot.com/2025/01/dfirtoolbar.html

03.01.2025 01:15 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 1
Post image

About 16 years of service. Replaced it with an Insinkerator Badger 5!

28.12.2024 02:01 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Reflecting on 2024 Derek wrote a blog post reflecting on 2024.

I wrote a blog post reflecting on selected topics from 2024.

mreerie.com/2024/12/27/r...

27.12.2024 17:01 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Placed a few glow in the dark stars in the kids room. These are nice and bright!

20.12.2024 04:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
S2: DFIRmas Podcast: Derek Eiri
S2: DFIRmas Podcast: Derek Eiri YouTube video by ArcPoint Forensics

It was great to chat #DFIR with @arcpoint-amy.bsky.social and Amy Moles in this festive themed podcast. Thank you for having me on!

m.youtube.com/watch?v=U0Zs...

12.12.2024 12:55 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
S2: DFIRmas Podcast: Alexis Brignoni Instagram: @4n6_abrignoniYouTube: Alexis BrignoniBlueSky: @abrignoni.comPodcast: Digital Forensics Now (DFN)Resources: https://dfir.pubpub.orgThe Importance...

πŸŽ„ArcPoint Forensics DFIRmas Podcast Season 2 Episode 1 is out!
❄️Topic: Validation
πŸŽ…Guest: Me!
β˜ƒοΈSubscribe to the channel for more interviews.
🌟Check it out at the link below:
https://buff.ly/4g4U6sk

#DFIR #DigitalForensics #MobileForensics

09.12.2024 18:16 πŸ‘ 7 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Preview
A Reflection on Continual Growth in DFIR: An InvestigativeΒ Mindset Derek reflects on continuous improvement of the investigative mindset.

I wrote a blog post reflecting on what I read from Brett Shavers' book, Placing the Suspect Behind the Keyboard: DFIR Investigative Mindset.

02.12.2024 12:38 πŸ‘ 14 πŸ” 6 πŸ’¬ 0 πŸ“Œ 0

An EDC blade for each week of the year!

28.11.2024 05:16 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
a fat man in a yellow jacket and suspenders is saying git in mah belleh ALT: a fat man in a yellow jacket and suspenders is saying git in mah belleh

If it’s DFIR related, I want it on my feed.

26.11.2024 02:56 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image Post image

I built an L-shaped desk in 2016. I’ve made some changes since then. Fortunately, I’ve made extra H-frame legs so I can keep the table tops independent. But today, I had use case to make a stubby table top to turn the L into a T. Just need to add coats of polyurethane, mount, and call it good.

21.11.2024 02:58 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

#iLEAPP v2.0.1 out now! #DFIR github.com/abrignoni/iL...

20.11.2024 16:57 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

I would like to introduce Lyman. A tool to aid in the creation of β€œmapping” cstruct files for OneDriveExplorer.

https://github.com/Beercow/Lyman

20.11.2024 15:15 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Linux Forensics with Hal Pomeranz - Antisyphon Training This 32-hour, hands-on course is a quick start into the world of Linux forensics. Learn how to use memory forensics to rapidly triage systems and spot attacker malware and rootkits.

And Hal’s Linux course: www.antisyphontraining.com/course/linux...

17.11.2024 16:33 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I have the following vendors on my roadmap focusing on Mac or Linux:

Linux: Cyber5w and 13Cubed

Mac: Hexordia and Sumuri

17.11.2024 16:31 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
FOR518: Mac and iOS Forensic Analysis and Incident Response, Re: SANS FOR518 OnDemandΒ Experience Derek completed the SANS FOR518 course. He's thinking differently.

FOR518: Mac and iOS Forensic Analysis and Incident Response, Re: SANS FOR518 OnDemandΒ Experience

Derek completed the SANS FOR518 course. He's thinking differently.

14.11.2024 13:35 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Sacramento, CA.

The HTCIA Northern California chapter will have our meeting on 12/05. MSAB will be hosting a lunch and learn with a dash of CTF.

Register here: bit.ly/registerctf

13.11.2024 01:50 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Just a picture of chickens to get this thing started.

13.11.2024 01:35 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0