<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Hashir Asad · writeups &amp; research</title><description>Hashir Asad: information security professional and researcher focused on identity &amp; access management and threat detection &amp; response. Research, writeups and projects.</description><link>https://hashir-ruddy.vercel.app</link><language>en</language><item><title>[Research] LLM-Assisted Forensic Timeline Analysis</title><link>https://hashir-ruddy.vercel.app/research/llm-assisted-forensic-timeline-analysis</link><guid isPermaLink="true">https://hashir-ruddy.vercel.app/research/llm-assisted-forensic-timeline-analysis</guid><description>Compares reading a forensic file-activity timeline from The Sleuth Kit on its own with having an open-source LLM, Falcon-7B-Instruct, interpret it. Tested against simulated malware activity, the model flagged files being suspiciously modified and encrypted, along with a suspicious new .exe and .txt file, as possible ransomware, making the threat easier to understand.</description><pubDate>Thu, 01 Aug 2024 00:00:00 GMT</pubDate><category>research</category><category>DFIR</category><category>LLM</category><category>Ransomware</category><category>The Sleuth Kit</category><category>Falcon-7B</category><category>Python</category></item></channel></rss>