tag:blogger.com,1999:blog-9518042.post3165101061053849211..comments2024-03-19T07:46:20.437-05:00Comments on Windows Incident Response: 10 Years of BloggingUnknownnoreply@blogger.comBlogger9125tag:blogger.com,1999:blog-9518042.post-21589568996708389622014-12-27T18:25:12.885-05:002014-12-27T18:25:12.885-05:00Armindo,
My only complaint is that you don't ...Armindo,<br /><br /><i>My only complaint is that you don't have many more books on the market. </i><br /><br />Well, I don't know about more books, but I've wanted to provide more coverage of other things (Windows Phone, etc.) but I can't do that without support from the community.<br /><br />Thanks for your comments.H. Carveyhttps://www.blogger.com/profile/08966595734678290320noreply@blogger.comtag:blogger.com,1999:blog-9518042.post-42165508679026792892014-12-27T12:14:21.235-05:002014-12-27T12:14:21.235-05:00Hi Harlan,
Congrats on the milestone. I picked u...Hi Harlan, <br /><br />Congrats on the milestone. I picked up two of your books this past week, Registry Forensics and the latest edition of the Windows Forensic Analysis series. I just finished my MS focusing on forensics and have read a bunch of forensics related books over the last 4 years. I can confidently say that your books are by far my favorite. My only complaint is that you don't have many more books on the market. I can't get enough! I'm glad I found your blog.Mindohttps://www.blogger.com/profile/18340691917135211348noreply@blogger.comtag:blogger.com,1999:blog-9518042.post-41256692342214866802014-12-21T06:51:48.924-05:002014-12-21T06:51:48.924-05:00Claus,
Thanks, I know that I've enjoyed your ...Claus,<br /><br />Thanks, I know that I've enjoyed your blog over the years, as well.<br /><br />Re: Technical posts...I can keep that up, but one thing I've noticed over time is that while lots of folks want to see things like that, few are willing to share any of their own stories.<br /><br />Re: Courses, etc. - I don't think I can speak competently to that, sorry. The only training course I've taken in recent years is the memory forensics course from Volatility, which is THE BOMB DIGGITY.H. Carveyhttps://www.blogger.com/profile/08966595734678290320noreply@blogger.comtag:blogger.com,1999:blog-9518042.post-13562467689577388372014-12-20T13:28:09.616-05:002014-12-20T13:28:09.616-05:00Congratulations Harlan for reaching this milestone...Congratulations Harlan for reaching this milestone!<br /><br />I deeply appreciate your postings and have no doubts you are making a difference in my humble sysadmin and incident response skills and approaches.<br /><br />I have so much to learn and your posts help me to refine where I need to apply my learning growth.<br /><br />I also appreciate the personalized comments and advice (and shout-outs) you provide to me as a blogger. The encouragement keeps me going when blogging enthusiasm is slow or my focus is a bit off the mark.<br /><br />As for recommendations? Keep up the technical posts. I particularly benefit from "the case of" type posts that walk through a scenario and its response/post-analysis. Not only do they help me learn new approaches and methods, but help me step out of the trap of "there's just one way to do it" in my own responses. Those can probably be more challenging to compose if based on "real-life" situations (changing details to protect the innocent/p0wned) but they help so much.<br /><br />One other thing I might enjoy is a another "sidebar" link page under your "Pages" listing other books, online courses, etc. that in your considerable experience and wisdom you might encourage us padawan sysadmin incident responders with so that we don't muck things up for the Jedi masters but actually learn. Not only will our skills improve but we might better apply IR best-practices at the get-go in case we do find (or have to make the case for) escalation and hand-off to the IR masters...despite organizational challenges and buy-in to do so (rather than just comply with a wipe/reimage/move-on order).<br /><br />Cheers!<br /><br />-Claus ValcaClaus Valcahttp://grandstreamdreams.blogspot.comnoreply@blogger.comtag:blogger.com,1999:blog-9518042.post-72900879191628750422014-12-08T12:55:52.409-05:002014-12-08T12:55:52.409-05:00Chad,
Thanks. Any thoughts on what I might do to...Chad,<br /><br />Thanks. Any thoughts on what I might do to improve the content?H. Carveyhttps://www.blogger.com/profile/08966595734678290320noreply@blogger.comtag:blogger.com,1999:blog-9518042.post-68653133598271953052014-12-08T12:46:30.151-05:002014-12-08T12:46:30.151-05:00Congratulations, Harlan! Ten years of DFIR bloggi...Congratulations, Harlan! Ten years of DFIR blogging is a tremendous accomplishment. Thank you for taking the time to share so much with the community.Chad Tilburyhttp://forensicmethods.comnoreply@blogger.comtag:blogger.com,1999:blog-9518042.post-66962070614369091122014-12-08T08:39:06.796-05:002014-12-08T08:39:06.796-05:00Harlan,
Congrats on the achievement. Every since ...Harlan,<br /><br />Congrats on the achievement. Every since I entered this field I have seen blogs come and go; but yours has been a mainstay in our field over the years. Being able to continue producing new and different content month in and month out is a great accomplishment. Keep up the good work.<br />Corey Harrellhttp://journeyintoir.blogspot.comnoreply@blogger.comtag:blogger.com,1999:blog-9518042.post-75848226792689095362014-12-08T07:18:00.693-05:002014-12-08T07:18:00.693-05:00Walter, thanks.
Any thoughts on what I could do t...Walter, thanks.<br /><br />Any thoughts on what I could do to improve the content?H. Carveyhttps://www.blogger.com/profile/08966595734678290320noreply@blogger.comtag:blogger.com,1999:blog-9518042.post-56861584186135844712014-12-08T07:14:14.627-05:002014-12-08T07:14:14.627-05:00Harlan, Congrats. I believe I have been enjoying y...Harlan, Congrats. I believe I have been enjoying your posts for almost that long. Thanks and keep them coming.<br /><br />Walt BobbyAnonymoushttps://www.blogger.com/profile/17101540673504150233noreply@blogger.com