top of page

Search Results

Search results for "forensic"

318 results found for "forensic"

  • In-Cloud IR — Memory, Containers, and the Metadata Service Attack

    article covers the advanced scenarios in AWS incident response — acquiring memory from cloud instances, forensicating The fundamental question in cloud IR: should you download evidence to an on-prem forensics lab, or do In-cloud analysis: No egress bandwidth costs, no waiting for terabytes to download, spin up forensic It's included in the AWS Forensics AMI reference implementations. Container forensics challenge: containers are ephemeral.

  • Using RADAR and MUICache for Evidence of Execution in Windows

    If you're into digital forensics, especially Windows forensic analysis, you've probably heard of MUICache Velociraptor  – A powerful tool for hunting and forensic analysis. That’s a red flag for forensic analysts! Why is This Useful for Forensics? Stay tuned for more forensic insights!

  • Moving Forward with Memory Analysis: From Volatility to MemProcFS : Part 2

    -2-0 Important: Enabling YARA scanning will delay the availability of forensic results. output: Primary results: M:\forensic\csv\findevil.csv Detailed YARA output: M:\forensic\csv\yara.csv When deeper analysis is required, memory forensics truly shines—allowing you to investigate far beyond Handling False Positives Like a Pro Memory forensics is never simple. Files M:\forensic\files <Cached Files> M:\forensic\ntfs <MFT> Registry,

  • Moving Forward with Memory Analysis: From Volatility to MemProcFS Part 1

    detail in the article: “Step-by-Step Guide to Uncovering Threats with Volatility: A Beginner’s Memory Forensics Volatility is one of my favorite memory forensics tools. It’s an excellent memory forensics framework that approaches investigations in a more interactive and An additional useful option is -forensic. file: M:\forensic\forensic_enable.txt It’s important to note that findevil only works on Windows 10

  • Uncovering Hidden Email Attachments in Outlook’s Secure Temp Folder

    This “Secure Temp Folder” is an important artifact in forensic investigations, as it can reveal previously -------------------------------------------------------------------------- Why Does This Matter for Forensics Before Outlook 2007, Forensic investigators could often recover multiple versions of the same file if artifacts like: $Logfile USNJournal Volume Shadow Copies Using forensic tools, investigators can often For forensic analysts, this folder remains a hidden goldmine of information that can provide crucial

  • Unlocking ShellBags Analysis with ShellBags Explorer (SBE) / SBECmd.exe

    ShellBags  can provide invaluable insights into a user’s activity— helping forensic analysts reconstruct ShellBags Explorer is a free, all-in-one forensic tool  designed to parse ShellBags artifacts effortlessly Suppose we have three folders under a parent folder, as seen in forensic tools like ShellBags Explorer Why This Matters in Forensics Understanding this timestamp limitation is crucial when reconstructing Correlating with other forensic artifacts is necessary .  

  • Understanding Filesystem Timestamps: A Practical Guide for Investigators

    In the digital forensics world, understanding how timestamps work is crucial. Various software and system activities can modify timestamps, sometimes in ways that obscure forensic Anti-Forensic & Malware Tools:  Attackers use file system APIs to modify timestamps, making malicious This has major implications for forensic investigations. Explore forensic tools like Plaso, Timesketch, and Velociraptor to take your timeline analysis skills

  • Metadata Recovery: Bringing Deleted Files Back to Life

    This opens a window for forensic experts to recover these "lost" files . What Is Metadata Recovery? Forensic tools can use this information to locate the file’s data and attempt to restore it. This means that forensic experts can recover the data if it hasn’t been overwritten yet. Forensic tools examine the metadata to find: Where the file was stored How big it is What type of file Autopsy : An open-source forensic suite with metadata recovery features.

  • Using KAPE to Collect Cloud Storage Artifacts

    If you've already read the complete cloud forensics guide — covering what artifacts to collect and how because today's article builds on it. https://www.cyberengage.org/courses-1/mastering-cloud-storage-forensics actually go about acquiring this data, what tools to use, what trips people up, and why cloud drive forensics When a file is cached locally it's physically in the OneDrive folder and a forensic image will capture And if you want to see the full cloud forensics guide covering what artifacts exist across Box, Google

  • Disk Imaging (Part 1) : Memory Acquisition & Encryption Checking

    Whether you’re working in digital forensics, IT, or just want to back up your system. Modern Forensic Acquisition Methods In the past, forensic specialists followed a “dead box” approach If it was a regular computer (not a server), forensics experts would unplug it directly. Include this information in your forensic reports for future reference. GUI Tools When performing live forensics, minimizing system impact is critical .

  • Tracking USB Activity Through Event Logs: Every Plug Tells a Story

    If you’re curious to learn even more, don’t forget to check out the full USB forensics series as well Event Logs for USB Activity https://www.cyberengage.org/post/windows-event-logs-for-usb-activity USB Forensic Series https://www.cyberengage.org/courses-1/usb-forensics ----------------------------------------- The Logging Ecosystem Before diving into specific events, it's worth understanding that USB forensics This is the capability that transforms USB forensics from "a device was plugged in" to "this user copied

  • String Searching with bstrings: Carving Files and Finding Hidden Data

    ------------------------------------------------------------------- Why String Searching Matters in Forensics String searching is one of the most versatile forensic techniques. Specialized forensic tools can decompress some file types, but coverage is incomplete, especially for I highly recommend checking out the article on Memory Forensics using Strings or Bstrings . It’s free, fast, and incredibly powerful—perfect for anyone looking to level up their forensic skills

bottom of page