top of page


The Big Data Blog


Azure Architecture: First 15 Commands to Run the Moment You Get Access
You just got Azure access mid-incident. The clock is running, the client is watching, and you need to move fast without missing anything. This is not the time to figure out what to look at — that thinking should already be done. Fifteen commands, organized in the exact sequence you should run them, with a clear explanation of what each one tells you and what red flags to look for. Bookmark it. Run it on every Azure engagement. All commands work in Azure Cloud Shell (Bash or P
May 188 min read


Azure Architecture: What Every Incident Responder Must Understand Before Touching a Case
Azure incident response is not the same as endpoint IR. The telemetry is different, the artifacts are different, and if you approach it the same way, you will miss everything that matters. Lets start with this series Before you can investigate anything in Microsoft Azure, you need to speak the language. Not the marketing language — the actual structural language that determines who can see what, where logs live, and why you might be staring at a completely blind spot without
May 178 min read


Using KAPE to Collect Cloud Storage Artifacts
Hey everyone, First things first — I owe you an apology for going quiet. Life got a little hectic on the personal side and I had to step away for a bit, but I'm back now and planning to write and post a lot more frequently going forward. Good to be back. Before we get into today's topic, I want to mention something quickly — www.cyberengage.org/ started as just sharing knowledge, and honestly it's grown into something bigger than I expected. Because of that, I'm actually look
May 105 min read


The Registry Analyst's Toolkit: Choosing Your Weapon
Every craftsman will tell you the same thing — knowing your tools is half the battle. You could understand the Windows Registry inside and out, but if you're staring at raw hex dumps with no way to decode them, you're going to have a bad time. The good news? The forensic community has spent years building some genuinely excellent registry analysis tools. Some are free. Some cost money. Some have been around for a decade. One was practically rebuilt from scratch in a modern pr
Apr 134 min read


Tracking USB Activity Through Event Logs: Every Plug Tells a Story
So, I had previously created a quick summary about USB activity, but I got a lot of requests asking for a more detailed version. That’s exactly why I’m here with this updated article! I’ve tried to keep things simple while adding a bit more depth so it’s easier to understand and actually useful. If you’re curious to learn even more, don’t forget to check out the full USB forensics series as well — it covers everything in much greater detail.. USB activity summary Windows Even
Apr 75 min read
Ready to discuss:
- Schedule a call for a consultation
- Message me via "Let's Chat" for quick questions
Let's connect!
bottom of page