top of page


The Big Data Blog


SAM Hive: The Registry Knows Who You Are
Every investigation eventually comes back to the same question: who was actually sitting at that keyboard? You can find the most damning files, the most suspicious network connections, the most carefully hidden evidence — but none of it means much until you can tie it to a specific person. That's where the SAM hive comes in. It's Windows' own internal roster of every local account on the machine, and it's usually one of the first stops in any serious forensic examination. Thi
Mar 26, 20244 min read


The Registry's Dirty Little Secret: Transaction Logs
So you've pulled the registry hives off a suspect machine. You've loaded them into your forensic tool. You're feeling good. Timestamps are lining up, keys are telling their stories, and you're building a solid picture of what happened. And then you realize you might be missing the most recent — and most critical — data entirely. Welcome to the world of registry transaction logs . The part of Windows forensics that quietly humbles analysts who think grabbing the hive files is
Mar 25, 20243 min read


The Windows Registry: The Black Box Flight Recorder of Your PC
You know those crime shows where the detective walks into a room and somehow reads the entire history of what happened just by looking around? That's basically what a forensic analyst does with the Windows Registry — except instead of a crime scene, it's your computer, and instead of cigarette ash and broken glass, it's a labyrinth of cryptic keys, timestamps, and nested data. The Registry isn't something most people ever think about. It sits silently in the background, hummi
Mar 24, 20244 min read


Volume Shadow Copies: The Hidden Evidence Goldmine You Need to Know About
Updated 22 Feb, 2026 v2 Section 1 — Why Attackers Can't Always Hide Their Tracks When a sophisticated attacker gets into a system, one of the first things they think about is cleanup. We're talking file wipers, free space wipers, deleting archive files — the whole nine yards. Say they used a privilege escalation tool to move through the network. Before they leave, they'll try to wipe that tool so nobody finds it. Same goes for those .rar archives they used to bundle up stole
Mar 23, 20244 min read


Overview the Core Components of NTFS File System
The $MFT, $J, $LogFile, $T, and $I30 are all important components of the NTFS (New Technology File System) file system used in Windows...
Mar 22, 20243 min read
Ready to discuss:
- Schedule a call for a consultation
- Message me via "Let's Chat" for quick questions
Let's connect!
bottom of page