Doug Metz's Avatar

Doug Metz

@dwmetz

#DFIR 🫆@ Magnet Forensics Blog ✍️ @ BakerStreetForensics.com Opinions are my own and are subject to change.

195
Followers
263
Following
93
Posts
18.11.2024
Joined
Posts Following

Latest posts by Doug Metz @dwmetz

Preview
MalChela Meets AI: Three Paths to Smarter Malware Analysis In a previous post I wrote about integrating MalChela with OpenCode on REMnux and giving the AI a quick briefing on the tool suite so it could incorporate them into its analysis workflow. That was a promising proof of concept, but it raised a natural follow-up question: how do you make these integrations more robust, reproducible, and persistent? Since that post, I've been experimenting with three different approaches to bringing MalChela into AI-assisted workflows — each suited to a different environment and use case.

MalChela Meets AI: Three Paths to Smarter Malware Analysis

In a previous post I wrote about integrating MalChela with OpenCode on REMnux and giving the AI a quick briefing on the tool suite so it could incorporate them into its analysis workflow. That was a promising proof of concept, but it…

03.03.2026 16:39 👍 1 🔁 0 💬 0 📌 0
Video thumbnail

On Feb 24 at Magnet's FREE virtual summit, @dwmetz.bsky.social and I will be talking about DF and IR, but not about "DFIR", if you know what I mean. magnetvirtualsummit.com/registration... #DFIR

20.02.2026 17:45 👍 2 🔁 2 💬 1 📌 0

@aaroncti.bsky.social interested in seeing the platform

19.02.2026 13:59 👍 1 🔁 0 💬 0 📌 0
Preview
Streamline Malware Hash Search with FOSSOR We’ve all encountered this scenario: you’re reading a threat report from CISA or Microsoft and come across hashes related to a malware infection. You start copying these hashes and head to one of your favorite virus repositories to check if there’s a source available for download so you can analyze the malware yourself. Unfortunately, you don’t find a match. So, you move on to another site and repeat the process.

Streamline Malware Hash Search with FOSSOR

We’ve all encountered this scenario: you’re reading a threat report from CISA or Microsoft and come across hashes related to a malware infection. You start copying these hashes and head to one of your favorite virus repositories to check if there’s a…

10.02.2026 15:27 👍 0 🔁 0 💬 0 📌 0
Preview
Enhancing Malware Analysis with REMnux and AI Those familiar with my work know that I’m a big fan of the REMnux Linux distribution for malware analysis. When I developed MalChela, I included a custom configuration that can be invoked that not only includes the MalChela tool suite but also integrates many of the CLI tools installed in REMnux, providing an easy-to-use GUI. Recently, a new REMnux release was released on Ubuntu 24.04.

Enhancing Malware Analysis with REMnux and AI

Those familiar with my work know that I’m a big fan of the REMnux Linux distribution for malware analysis. When I developed MalChela, I included a custom configuration that can be invoked that not only includes the MalChela tool suite but also…

09.02.2026 17:23 👍 0 🔁 0 💬 0 📌 0
Video thumbnail
23.01.2026 00:42 👍 2 🔁 0 💬 0 📌 0

Sounds pretty atomic

06.12.2025 01:30 👍 1 🔁 0 💬 0 📌 0
Preview
2025 Year in Review: Open Source DFIR Tools and Malware Analysis Projects In 2025, significant advancements in DFIR toolkit development were achieved, including the evolution of MalChela for malware analysis, streamlined CyberPipe tools, and the introduction of Toby, a portable forensics platform. The focus was on creating practical solutions for digital forensics professionals, with all tools available as open-source on GitHub. #DFIR #MalwareAnalysis #OpenSource

Wrapping up 2025 with the year in code, including the evolution of MalChela for malware analysis, streamlined CyberPipe tools, and the introduction of Toby, a portable forensics platform. Focus was on creating practical solutions for #DFIR professionals and students for triage and #MalwareAnalysis

05.12.2025 18:21 👍 2 🔁 0 💬 0 📌 0
Post image
22.11.2025 15:33 👍 316 🔁 78 💬 5 📌 4
Post image

What a start…

22.11.2025 21:34 👍 1 🔁 0 💬 0 📌 0
Preview
CyberPipe-Timeliner: From Collection to Timeline in One Script CyberPipe-Timeliner was developed in response to a colleague's query about integrating Magnet Response collections with ForensicTimeliner. This tool automates the workflow, transforming collection data into a unified forensic timeline. With features like date filtering and flexible input options, it streamlines the timeline generation process, making it efficient and user-friendly. #DFIR

CyberPipe-Timeliner was developed to integrate Magnet Response collections with ForensicTimeliner. This tool automates the workflow of EZTools, and transforms collection data into a unified forensic timeline. #DFIR

05.11.2025 16:23 👍 2 🔁 1 💬 0 📌 0
CyberPipe v5.3: Enhanced PowerShell Compatibility and Reliability I'm pleased to announce the release of CyberPipe v5.3, bringing critical compatibility improvements for Windows PowerShell 5.1 and enhanced reliability across all PowerShell environments. The Problem After releasing v5.2 with the new unified banner design, several users reported an interesting issue: CyberPipe would execute perfectly in PowerShell Core, but in Windows PowerShell 5.1, the script would complete the Magnet Response collection successfully—then immediately fail with an exit code error and stop before running EDD and BitLocker key recovery.

CyberPipe v5.3: Enhanced PowerShell Compatibility and Reliability

I'm pleased to announce the release of CyberPipe v5.3, bringing critical compatibility improvements for Windows PowerShell 5.1 and enhanced reliability across all PowerShell environments. The Problem After releasing v5.2 with the…

04.11.2025 14:45 👍 1 🔁 0 💬 0 📌 0

God is an Eagles fan. #GoBirds

24.10.2025 20:45 👍 1 🔁 0 💬 0 📌 0

You'll pry these Oxford commas out of my cold, dead, third thing hands

23.10.2025 19:30 👍 1392 🔁 481 💬 12 📌 2
Gardava Faraday Beanie Protection Hat - Blocks 99.9% E.M.Fs, 5G, WiFi, R.adiation, 3rd Party Tested, Unisex-Adults, Black at Amazon Men’s Clothing store Buy Gardava Faraday Beanie Protection Hat - Blocks 99.9% E.M.Fs, 5G, WiFi, R.adiation, 3rd Party Tested, Unisex-Adults, Black: Shop top fashion brands Skullies & Beanies at Amazon.com ✓ FREE DELIVERY ...

When you’re paranoid but any old tin foil hat won’t do. a.co/d/1GvRbfT

20.10.2025 01:27 👍 0 🔁 0 💬 0 📌 0
Preview
Streamline Digital Evidence Collection with CyberPipe 5.2 CyberPipe, developed for incident response, is a PowerShell script facilitating efficient digital evidence collection in enterprise settings. Recent updates include improved collection methods, capabilities like QuickTriage for faster artifact gathering, and enhanced reliability with advanced error handling. Version 5.2 aims to streamline operations while ensuring forensic integrity and transparency. #DFIR

CyberPipe, a PowerShell script for digital evidence collection, has been updated with enhancements in collection, capabilities, and reliability. New features include intelligent collection with dual disk space validation, a QuickTriage profile, and improved BitLocker recovery. #DFIR

16.10.2025 14:23 👍 3 🔁 2 💬 0 📌 0

Swore I was reading @theonion.com

10.10.2025 00:13 👍 1 🔁 0 💬 0 📌 0
Preview
Cross-Platform DFIR Tools: MalChelaGUI on Windows A trick and a treat this week with a quiet milestone for cross-platform DFIR tooling — MalChelaGUI now runs seamlessly inside Windows through Ubuntu WSL2, with zero configuration required. #DFIR #MalwareAnalysis

A trick and a treat this week with a quiet milestone for cross-platform DFIR tooling — MalChelaGUI now runs seamlessly inside Windows through Ubuntu WSL2, with zero configuration required. #DFIR #MalwareAnalysis

07.10.2025 19:50 👍 2 🔁 1 💬 0 📌 0
Preview
S2:E4 // Voices from the field: Trends, challenges, and what’s next in DFIR - Magnet Forensics Digital Forensics and Incident Response (DFIR) has evolved rapidly from purely reactive investigations to incorporating proactive approaches that utilize cloud-powered forensics and AI. But while the ...

On Oct 8, join us for a special episode of #CyberUnpacked where hosts @dwmetz.bsky.social & Jeff Rutherford will bring together a panel of #DFIR leaders to explore top challenges investigative teams face and the state of #DigitalInvestigations today: ow.ly/jRVq50X2r0L

25.09.2025 19:29 👍 2 🔁 1 💬 0 📌 1

Go Birds!

04.09.2025 22:38 👍 6 🔁 0 💬 1 📌 0
Preview
Sign Petition: Stop Masked Immigration Raids. This Is Not How a Democracy Operates. These agents are using masks to shield themselves from accountability for their willingness to participate in dangerous overreach. (51529 signatures on petition)

Masked ICE aren’t about safety; they’re about fear and evading responsibility. Demand transparency and accountability by adding your name to this petition:

30.08.2025 21:00 👍 6905 🔁 2035 💬 184 📌 71
Is your USB device slowing down your forensic investigation? In digital forensics, reliable storage is essential for effective workflows. Crabwise, a USB benchmarking utility, addresses performance variability by calculating read and write speeds under direct conditions, bypassing caching. It logs results for easy comparison, allowing users to optimize connections. This tool ensures informed decisions on hardware setups, improving efficiency and consistency in forensics tasks.

In DFIR, reliable storage is essential for effective workflows. Crabwise, a USB benchmarking utility, addresses performance variability by calculating read and write speeds under direct conditions, bypassing caching and logs results for easy comparison. #DFIR

27.08.2025 19:53 👍 1 🔁 1 💬 0 📌 0
Post image
27.08.2025 04:35 👍 0 🔁 0 💬 0 📌 0
Preview
Enhance Threat Hunting with MITRE Lookup in MalChela 3.0.2 The recent update of MalChela 3.0.2 introduces MITRE Lookup, a tool that allows forensic investigators to search the MITRE ATT&CK framework offline. This feature enhances investigation speed by supporting keyword and Technique ID searches while providing tactic categories and detection guidance. Users can save results directly for future reference, enhancing analysis efficiency.

MalChela 3.0.2 introduces MITRE Lookup, a tool that allows forensic investigators to search the MITRE ATT&CK framework offline. This feature enhances investigation speed by supporting keyword and Technique ID searches while providing tactic categories and detection guidance. #DFIR #MalwareAnalysis

02.08.2025 20:22 👍 2 🔁 0 💬 0 📌 0

💙🐕 Toby ! :)

30.07.2025 16:25 👍 0 🔁 0 💬 0 📌 0
Preview
Toby-Find: Simplifying Command-Line Forensics Tools Toby-Find is a terminal-based tool designed for digital forensics, providing users with an easy way to discover command-line tools available in KALI and REMnux. Initially created for a university course, it allows quick searches for tools, descriptions, and examples, enhancing usability in forensic analysis without memorization or manual searching.

Toby-Find is a terminal-based tool designed for digital forensics, providing users with an easy way to discover command-line tools available in KALI and REMnux. It allows quick searches for tools, descriptions, and examples, enhancing usability in forensic analysis. #DFIR #MalwareAnalysis

29.07.2025 17:30 👍 0 🔁 0 💬 0 📌 0
Preview
Sharper Strings and Smarter Signals: MalChela 3.0.1 🎯 MalChela v3.0.1 is live Sharper strings. Smarter signals. This update tightens forensic detection across the board: • ✅ Improved mstrings output and MITRE mappings • 🔎 Built-in MITRE technique lookup (GUI) • 📁 FileMiner gets “select all” + subtool optimizations • 🧠 Smarter regex, better signal-to-noise for analysts • 🦀 Compiled & tuned for --release performance Still a one-crab shop, but contributions welcome. 👉 🧰 Docs: #DFIR #MalwareAnalysis

🎯 MalChela v3.0.1 is live

Sharper strings. Smarter signals.

This update includes:
✅ Improved mstrings output and MITRE mappings
🧠 Smarter regex
🔎 Built-in MITRE technique lookup (GUI)
📁 FileMiner gets “select all” + subtool optimizations
🦀 Compiled for performance

#DFIR #MalwareAnalysis

28.07.2025 19:15 👍 1 🔁 0 💬 0 📌 0
Photo of a small crab on the beach

Photo of a small crab on the beach

A MalChela 🦀 sighting in the wild

22.07.2025 15:05 👍 0 🔁 0 💬 0 📌 0
Preview
Portable Forensics with Toby: A Raspberry Pi Toolkit Toby is a compact, portable forensics toolkit built on a Raspberry Pi Zero 2 W, designed for ease of use in field analysis and malware triage. It operates headlessly via SSH or VNC, supports variou…

Portable Forensics with Toby: A Raspberry Pi Toolkit

Toby is a compact, portable forensics toolkit built on a Raspberry Pi Zero 2 W, designed for ease of use in field analysis and malware triage.

bakerstreetforensics.com/2025/07/20/p...

#DFIR #MalwareAnalysis #RaspberryPi

20.07.2025 14:52 👍 3 🔁 2 💬 1 📌 0

Happy terrorize the dogs and veterans to all who celebrate.

05.07.2025 02:42 👍 0 🔁 0 💬 0 📌 0