Doug Metz
@dwmetz.bsky.social
#DFIR 🫆@ Magnet Forensics Blog ✍️ @ BakerStreetForensics.com Projects 🦀 @ Github.com/dwmetz Opinions are my own and are subject to change.
MalChela v4.3 Version 4.3 introduces significant updates, including an At A Glance panel on the Home Screen displaying case statuses and integrations. New features include an Offline Mode for air-gapped scenarios, enhanced analysis tools, improved string detection capabilities in mStrings, and 25…
MalChela v4.3
Version 4.3 introduces significant updates, including an At A Glance panel on the Home Screen displaying case statuses and integrations. New features include an Offline Mode for air-gapped scenarios, enhanced analysis tools, improved string detection capabilities in mStrings, and 25 additional detection rules. Comprehensive documentation updates accompany these enhancements.
bakerstreetforensics.com
MalChela 4.2 Release MalChela v4.2 introduces improved functionality for Mac analysis, allowing four tools to interact directly with .app bundles, eliminating the need to find buried binaries. The new Analyze feature simplifies the triage process by automatically classifying files and dispatching…
MalChela 4.2 Release
MalChela v4.2 introduces improved functionality for Mac analysis, allowing four tools to interact directly with .app bundles, eliminating the need to find buried binaries. The new Analyze feature simplifies the triage process by automatically classifying files and dispatching necessary tools, streamlining malware analysis and reporting with concise summaries.
bakerstreetforensics.com
Join us July 29 at 11:00 AM ET for a live and interactive Ask Me Anything (#AMA) session with seasoned #DFIR practitioners as they tackle your toughest #IncidentResponse questions and share practical guidance from real-world investigations. Register now: https://ow.ly/RaYh50ZmchU
Where did I save that? Introducing Mind Palace — a free, open-source macOS menu bar app. It indexes Apple Notes, Safari Reading List, and any local folders you choose, and lets you search all of them from one place. Download: lnkd.in/e9A23DKw Learn more: bakerstreetforensics.com/mind-palace-2/
Mind Palace
Mind Palace is a free macOS menu bar app that indexes your Apple Notes, Safari Reading List, and local folders into a single, instantly searchable knowledge base — all on your own machine, with not…
bakerstreetforensics.com
Mind Palace: A Personal Search Engine for the Way I Actually Work "I consider that a man's brain originally is like a little empty attic, and you have to stock it with such furniture as you choose." — Sherlock Holmes, A Study in Scarlet There's a particular kind of frustration that I suspect a lot…
Mind Palace: A Personal Search Engine for the Way I Actually Work
"I consider that a man's brain originally is like a little empty attic, and you have to stock it with such furniture as you choose." — Sherlock Holmes, A Study in Scarlet There's a particular kind of frustration that I suspect a lot of researchers know well: you're in the middle of something, an analysis, a blog post, a deck, and you know you've written or read or bookmarked something about this before.
bakerstreetforensics.com
MalChela v4.1: Mac Malware Analysis Arrives MalChela v4.1 is out today, and the headline is something I've been wanting to tackle for a while: dedicated Mac malware analysis tooling. If you've been following the channel or the blog, you know MalChela started as a triage-first toolkit aimed at the…
MalChela v4.1: Mac Malware Analysis Arrives
MalChela v4.1 is out today, and the headline is something I've been wanting to tackle for a while: dedicated Mac malware analysis tooling. If you've been following the channel or the blog, you know MalChela started as a triage-first toolkit aimed at the kinds of samples that show up in Windows-centric IR engagements. That coverage was never the full picture. Mac malware — infostealers, adware loaders, APT implants — has become too common to treat as an edge case.
bakerstreetforensics.com
Unmasking the Moon: Comparing LunaStealer Samples with MalChela and Claude As one tends to do on Saturday mornings with coffee in hand, I was reviewing two samples that were attributed to the LunaStealer / LunaGrabber family. Originally I was validating that tiquery was working with the MCP…
Unmasking the Moon: Comparing LunaStealer Samples with MalChela and Claude
As one tends to do on Saturday mornings with coffee in hand, I was reviewing two samples that were attributed to the LunaStealer / LunaGrabber family. Originally I was validating that tiquery was working with the MCP configuration, however what started as a quick TI check turned into a full static analysis session — and it gave me a good opportunity to put the MalChela MCP integration through its paces in a real workflow.
bakerstreetforensics.com
The Long Game: MalChela v4.0 When I started building MalChela, I had a narrow problem to solve. I was doing a lot of malware triage during incident response engagements and I kept reaching for the same scattered set of tools — VirusTotal, some strings extraction, a hash lookup here, a YARA scan…
The Long Game: MalChela v4.0
When I started building MalChela, I had a narrow problem to solve. I was doing a lot of malware triage during incident response engagements and I kept reaching for the same scattered set of tools — VirusTotal, some strings extraction, a hash lookup here, a YARA scan there. The workflow existed, but it wasn't a workflow. It was a series of scripts and context switches dressed up as a process.
bakerstreetforensics.com
From QR to Threat Identification in one Click Recently I introduced Threat Intel Query (tiquery), a multi-source threat intelligence lookup tool. The first iteration expanded on the capability of malhash and enabled for the submission of malware hashes against multiple threat intel sites. Then…
From QR to Threat Identification in one Click
Recently I introduced Threat Intel Query (tiquery), a multi-source threat intelligence lookup tool. The first iteration expanded on the capability of malhash and enabled for the submission of malware hashes against multiple threat intel sites. Then yesterday I was targeted with an SMS phishing message. (Note: I don't know why but I detest the term 'smishing', or any of the other '
bakerstreetforensics.com
MalChela 3.2: More Cowbell? More Intel! One of the things I value most about the open-source community is that the best improvements to a tool often don’t come from inside it — they come from outside conversations.  A short while back, the author of mlget, xorhex,  reached out and suggested I add…
MalChela 3.2: More Cowbell? More Intel!
One of the things I value most about the open-source community is that the best improvements to a tool often don’t come from inside it — they come from outside conversations.  A short while back, the author of mlget, xorhex,  reached out and suggested I add more malware retrieval sources to FOSSOR, one of my earlier tools for pulling down samples from threat intel repositories. Â
bakerstreetforensics.com
Just got an email for a “Cyber Easter” sale. Can we please stop making everything Cyber? Yes I wrote CyberPipe and host Cyber Unpacked… but still…
A Study in DFIR: Open-Source, Enterprise, and the Art of Analysis Someone asked me recently how I see DFIR evolving — tooling, automation, and open-source versus enterprise platforms. It's the kind of question that sounds like a conference panel topic, but the answer is grounded in how work…
A Study in DFIR: Open-Source, Enterprise, and the Art of Analysis
Someone asked me recently how I see DFIR evolving — tooling, automation, and open-source versus enterprise platforms. It's the kind of question that sounds like a conference panel topic, but the answer is grounded in how work actually gets done. In practice, it isn't a binary choice. The most effective IR practitioners I've worked with use a combination of both commercial and open-source tools, depending on the problem in front of them.
bakerstreetforensics.com
New YouTube Video series covering the free open-source YARA & Malware Analysis toolkit, MalChela. Covers installation, Initial static analysis, YARA rule creation, REMnux integration and more.
The Game Is Afoot: Introducing the MalChela Video Series
There's a moment every analyst knows — the one where an unknown file lands on your desk and the clock starts ticking. You need answers, and you need them fast. MalChela was built for exactly that moment. Today I'm excited to announce the MalChela Video Series on YouTube — a growing collection of tutorial episodes walking through real malware analysis workflows using…
bakerstreetforensics.com
MalChela Meets AI: Three Paths to Smarter Malware Analysis In a previous post I wrote about integrating MalChela with OpenCode on REMnux and giving the AI a quick briefing on the tool suite so it could incorporate them into its analysis workflow. That was a promising proof of concept, but it…
MalChela Meets AI: Three Paths to Smarter Malware Analysis
In a previous post I wrote about integrating MalChela with OpenCode on REMnux and giving the AI a quick briefing on the tool suite so it could incorporate them into its analysis workflow. That was a promising proof of concept, but it raised a natural follow-up question: how do you make these integrations more robust, reproducible, and persistent? Since that post, I've been experimenting with three different approaches to bringing MalChela into AI-assisted workflows — each suited to a different environment and use case.
bakerstreetforensics.com
On Feb 24 at Magnet's FREE virtual summit, @dwmetz.bsky.social and I will be talking about DF and IR, but not about "DFIR", if you know what I mean. magnetvirtualsummit.com/registration... #DFIR
Streamline Malware Hash Search with FOSSOR We’ve all encountered this scenario: you’re reading a threat report from CISA or Microsoft and come across hashes related to a malware infection. You start copying these hashes and head to one of your favorite virus repositories to check if there’s a…
Streamline Malware Hash Search with FOSSOR
We’ve all encountered this scenario: you’re reading a threat report from CISA or Microsoft and come across hashes related to a malware infection. You start copying these hashes and head to one of your favorite virus repositories to check if there’s a source available for download so you can analyze the malware yourself. Unfortunately, you don’t find a match. So, you move on to another site and repeat the process.
bakerstreetforensics.com
Enhancing Malware Analysis with REMnux and AI Those familiar with my work know that I’m a big fan of the REMnux Linux distribution for malware analysis. When I developed MalChela, I included a custom configuration that can be invoked that not only includes the MalChela tool suite but also…
Enhancing Malware Analysis with REMnux and AI
Those familiar with my work know that I’m a big fan of the REMnux Linux distribution for malware analysis. When I developed MalChela, I included a custom configuration that can be invoked that not only includes the MalChela tool suite but also integrates many of the CLI tools installed in REMnux, providing an easy-to-use GUI. Recently, a new REMnux release was released on Ubuntu 24.04.
bakerstreetforensics.com
Wrapping up 2025 with the year in code, including the evolution of MalChela for malware analysis, streamlined CyberPipe tools, and the introduction of Toby, a portable forensics platform. Focus was on creating practical solutions for #DFIR professionals and students for triage and #MalwareAnalysis
2025 Year in Review: Open Source DFIR Tools and Malware Analysis Projects
In 2025, significant advancements in DFIR toolkit development were achieved, including the evolution of MalChela for malware analysis, streamlined CyberPipe tools, and the introduction of Toby, a portable forensics platform. The focus was on creating practical solutions for digital forensics professionals, with all tools available as open-source on GitHub. #DFIR #MalwareAnalysis #OpenSource
bakerstreetforensics.com
CyberPipe-Timeliner was developed to integrate Magnet Response collections with ForensicTimeliner. This tool automates the workflow of EZTools, and transforms collection data into a unified forensic timeline. #DFIR
CyberPipe-Timeliner: From Collection to Timeline in One Script
CyberPipe-Timeliner was developed in response to a colleague's query about integrating Magnet Response collections with ForensicTimeliner. This tool automates the workflow, transforming collection data into a unified forensic timeline. With features like date filtering and flexible input options, it streamlines the timeline generation process, making it efficient and user-friendly. #DFIR
bakerstreetforensics.com
CyberPipe v5.3: Enhanced PowerShell Compatibility and Reliability I'm pleased to announce the release of CyberPipe v5.3, bringing critical compatibility improvements for Windows PowerShell 5.1 and enhanced reliability across all PowerShell environments. The Problem After releasing v5.2 with the…
CyberPipe v5.3: Enhanced PowerShell Compatibility and Reliability
I'm pleased to announce the release of CyberPipe v5.3, bringing critical compatibility improvements for Windows PowerShell 5.1 and enhanced reliability across all PowerShell environments. The Problem After releasing v5.2 with the new unified banner design, several users reported an interesting issue: CyberPipe would execute perfectly in PowerShell Core, but in Windows PowerShell 5.1, the script would complete the Magnet Response collection successfully—then immediately fail with an exit code error and stop before running EDD and BitLocker key recovery.
bakerstreetforensics.com
You'll pry these Oxford commas out of my cold, dead, third thing hands
When you’re paranoid but any old tin foil hat won’t do. a.co/d/1GvRbfT
Gardava Faraday Beanie Protection Hat - Blocks 99.9% E.M.Fs, 5G, WiFi, R.adiation, 3rd Party Tested, Unisex-Adults, Black at Amazon Men’s Clothing store
Buy Gardava Faraday Beanie Protection Hat - Blocks 99.9% E.M.Fs, 5G, WiFi, R.adiation, 3rd Party Tested, Unisex-Adults, Black: Shop top fashion brands Skullies & Beanies at Amazon.com âś“ FREE DELIVERY ...
a.co
CyberPipe, a PowerShell script for digital evidence collection, has been updated with enhancements in collection, capabilities, and reliability. New features include intelligent collection with dual disk space validation, a QuickTriage profile, and improved BitLocker recovery. #DFIR
Streamline Digital Evidence Collection with CyberPipe 5.2
CyberPipe, developed for incident response, is a PowerShell script facilitating efficient digital evidence collection in enterprise settings. Recent updates include improved collection methods, capabilities like QuickTriage for faster artifact gathering, and enhanced reliability with advanced error handling. Version 5.2 aims to streamline operations while ensuring forensic integrity and transparency. #DFIR
bakerstreetforensics.com
A trick and a treat this week with a quiet milestone for cross-platform DFIR tooling — MalChelaGUI now runs seamlessly inside Windows through Ubuntu WSL2, with zero configuration required. #DFIR #MalwareAnalysis
Cross-Platform DFIR Tools: MalChelaGUI on Windows
A trick and a treat this week with a quiet milestone for cross-platform DFIR tooling — MalChelaGUI now runs seamlessly inside Windows through Ubuntu WSL2, with zero configuration required. #DFIR #MalwareAnalysis
bakerstreetforensics.com
On Oct 8, join us for a special episode of #CyberUnpacked where hosts @dwmetz.bsky.social & Jeff Rutherford will bring together a panel of #DFIR leaders to explore top challenges investigative teams face and the state of #DigitalInvestigations today: ow.ly/jRVq50X2r0L
S2:E4 // Voices from the field: Trends, challenges, and what’s next in DFIR - Magnet Forensics
Digital Forensics and Incident Response (DFIR) has evolved rapidly from purely reactive investigations to incorporating proactive approaches that utilize cloud-powered forensics and AI. But while the ...
ow.ly