About Olaf Schwarz
Olaf is an Incident Response and Digital Forensics expert within the NVISO CSIRT, where he supports complex DFIR investigations and projects across both IT and OT environments. With more than 15 years of experience in information security, he brings deep expertise in incident response, digital forensics, and hands-on investigative work. When time permits, he also develops and maintains several free DFIR tools.
Latest Articles
Ivanti EPMM ‘Sleeper Shells’ not so sleepy?
Forensics
In late January 2026, an advisory covering two remote code execution vulnerabilities (CVE-2026-1281 & CVE-2026-1340) in Ivanti Endpoint Manager Mobile…
Investigating an engineering workstation – Part 4
Forensics
Finally, as the last part of the blog series we will have a look at the network traffic observed. We…
Investigating an engineering workstation – Part 3
Forensics
In our third blog post (part one and two are referenced above) we will focus on information we can get…
Investigating an engineering workstation – Part 2
Forensics
In this second post we will focus on specific evidence written by the TIA Portal. As you might remember, in…
Investigating an engineering workstation – Part 1
Forensics
In this series of blog posts we will deal with the investigation of an engineering workstation running Windows 10 with…
Amcache contains SHA-1 Hash – It Depends!
Forensics
If you read about the Amcache registry hive and what information it contains, you will find a lot of references…
