top of page

Search Results

Search results for "forensic"

318 results found for "forensic"

  • USB Device Identifiers and Forensic Insights: iSerialNumber, SCSI Serial Numbers, UASP Devices, and Cleanup in Windows

    This makes it incredibly useful for tracking where a device has been used—whether for forensic investigations These numbers may not match, and forensic tools can sometimes show one but not the other. under SYSTEM\<CurrentControlSet>\Enum\SCSI key, which requires some unique steps to extract useful forensic These keys allow forensic analysts to go back in time and recover information about devices previously Leverage Forensic Logs Logs like setupapi.dev.log and event logs (other than Microsoft-Windows-Partition

  • Tracing Reused $MFT Entries Paths : Recovering Deleted File Paths Forensically with CyberCX UsnJrnl Rewind

    Screenshot of $J Forensic tools often correlate $UsnJrnl with $MFT to reconstruct file paths, but reused This research has taught us valuable insights into forensic investigations.

  • Understanding macOS App Preference Files, (MRU) Files Shared File Lists and Account Artifacts for Digital Forensics

    Preferences/ These files store user-defined settings for applications, making them an essential resource in forensic Although they are less persistent, they can sometimes hold valuable forensic evidence. ------------------------------------------- Most Recently Used (MRU) Files When investigating macOS forensics Tools for Analyzing macOS On a macOS Analysis Host For analyzing extracted artifacts, forensic examiners With the right tools and techniques, forensic professionals can extract and interpret this information

  • SentinelOne (P8- SentinelOne Automation) :Guide / Training to Forensic Collection, KAPE Integration, Running Script and Incident Response

    Crucial forensic artifacts like $MFT , $J , Prefetch and more. Let’s explore the Forensic Profile  option first. Click on Actions , then Search for Forensic Collection . Choose the forensic profile you created earlier and hit Run Collection . It’s a game-changer for incident response and forensic investigations.

  • Investigating macOS Persistence :macOS stores extensive configuration data in: Key Artifacts, Launch Daemons, and Forensic Strategies"

    Executables : C onfirm if the executables are legitimate by checking their file hashes or running basic forensic

  • Moving Forward with Memory Analysis: From Volatility to MemProcFS : Part 3

    File_Objects through: their process handle table their Virtual Address Descriptor (VAD) tree Memory forensics Forensic File Reconstruction (M:\forensic\files) When MemProcFS is run with forensic options enabled, NTFS Forensics from Memory The M:\forensic\ntfs folder allows analysts to investigate the entire file : M:\forensic\csv\ The timeline_ntfs.csv  file contains file system events, while other timelines focus -1/mastering-memory-forensics%3A-in-depth-analysis-with-volatility-and-advanced-tools

  • The Registry's Dirty Little Secret: Transaction Logs

    You've loaded them into your forensic tool. You're feeling good. The part of Windows forensics that quietly humbles analysts who think grabbing the hive files is enough This process is called a hive flush , and it's the source of a genuinely important forensic blind spot But from a forensics standpoint? The gold standard tool for registry forensics — Registry Explorer  by Eric Zimmerman — does this right

  • Ransomware, Malware, and Intrusions: A Step-by-Step Analysis Methodology

    Artifacts: https://www.cyberengage.org/courses-1/windows-forensic-artifacts ------------------------ Series : https://www.cyberengage.org/courses-1/mastering-windows-registry-forensics%3A ------------- : https://www.cyberengage.org/courses-1/network-forensic -------------------------------------------- Internet History Critical for phishing & exfil evidence. 📌 Guide: Browser forensics series (open-source (indexing section): https://www.cyberengage.org/courses-1/windows-forensic-artifacts ---------------

  • The Registry Analyst's Toolkit: Choosing Your Weapon

    The forensic community has spent years building some genuinely excellent registry analysis tools. Forensic tools change. Vendors stop updating. Better options emerge. It's closer to a full forensic workstation for registry analysis. The Best way to use this find I have showed in USB Forensics Link below https://www.cyberengage.org/post /courses-1/usb-forensics ----------------------------------------------------------------------------

  • The Windows Registry: The Black Box Flight Recorder of Your PC

    That's basically what a forensic analyst does with the Windows Registry — except instead of a crime scene This is where forensics analysts basically strike gold. It means a forensic analyst can tell you that at exactly 01:39:35 UTC on January 30th, 2016 something You need specialized forensic tools to surface them. When you're doing live forensics on a running machine, you see these four root keys through regedit.

  • Event-Driven DFIR — Automating Your AWS Response

    environments where IR automation requires complex SOAR platforms, AWS has native services that can trigger forensic A typical forensic collection workflow might look like: (1) Receive GuardDuty finding → (2) Identify 4a) If yes: take snapshot → (4b) If no: isolate instance, then take snapshot → (5) Copy snapshot to forensic bucket Putting it all together — a complete automated forensic collection chain: (1) GuardDuty HIGH number and timestamp → (6) Step 3: Snapshot all attached EBS volumes → (7) Step 4: Copy snapshots to forensic

  • Cloud Incident Response: How to Acquire and Analyze a VM Disk Image in Azure

    the imaged disk, create a separate VM called the “Forensic VM” with adequate resources for your forensic Create OS Disk:  During setup, the Forensic VM will have its own OS disk where you can install forensic Step 4: Mount the Disk in the Forensic VM Once the Forensic VM is running, access the imaged disk by Step 5: Run Forensic Tools on the Forensic VM With the disk mounted, you can now use forensic tools to on the Forensic VM’s OS disk.

bottom of page