Все публикации

NTFS FILE Record Reuse

13Cubed XINTRA Lab Walkthrough

Linux Memory Forensics Challenge

Shimcache Execution Is Back - What You Need to Know!

Mounting Linux Disk Images in Windows

New Course! Investigating Linux Devices

The Weird Windows Feature You've Never Heard Of

The Ultimate Guide to Arsenal Image Mounter

Where's the 4624? - Logon Events vs. Account Logons

RDP Authentication vs. Authorization

Investigating Windows Courses

Hyper-V Memory Forensics - MemProcFS to the Rescue!

An Important Change to ShellBags - Windows 11 2023 Update!

VMware Memory Forensics - Don't Miss This Important Detail!

Old School MS-DOS Commands for DFIR

Detecting PsExec Usage

A File's Life - File Deletion and Recovery

Two Thumbs Up - Thumbnail Forensics

Interview with Lesley Carhart (hacks4pancakes)

It's About Time - Timestamp Changes in Windows 11

EZ Tools Manuals Interview with Andrew Rathbun

A New Program Execution Artifact - Windows 11 22H2 Update!

The Dissect Effect - An Open Source IR Framework

Let's Talk About MUICache