top of page

Search Results

Search results for "forensic"

318 results found for "forensic"

  • Understanding, Collecting, Parsing, Analyzing the $MFT

    check out below article: https://www.cyberengage.org/courses-1/insights-into-file-systems-and-anti-forensics MFT using MFTExplorer/MFTECMD check out below https://www.cyberengage.org/post/mftecmd-mftexplorer-a-forensic-analyst-s-guide can learn more about Timestomping check out the article below: https://www.cyberengage.org/post/anti-forensics-timestomping

  • Breaking Down the $LogFile and How to Use LogFileParser

    When it comes to forensic analysis, the $LogFile is one of those artifacts that hasn’t received as much However, the $LogFile is packed with valuable forensic data, storing full details of changes to critical Even if you’re not purchasing the tool, TZWorks provides excellent documentation  explaining how forensic ------------ Final Thoughts Parsing the $LogFile isn’t always the first thing that comes to mind in forensic

  • Google Cloud Compute and Cloud Ops Agent — What Actually Matters for DFIR

    . 👉 From a forensic standpoint, this is gold. this article focuses here instead of on GKE or Cloud Functions: VMs are where you actually get to do forensics Forensics-wise: mixed — they often come with additional logins that a standard VM wouldn't have, which Attach it read-only to your forensic VM gcloud compute instances attach-disk forensic-vm \ --project Live Forensics in Google Cloud: Ops Agent Google Cloud provides a built-in way to collect live telemetry

  • Windows Environment Variables for Ransomware Analysis

    Windows environment variables are one such critical component that forensic analysts must be familiar Example: C:\ProgramData Why Environment Variables Matter in Forensics Environment variables are crucial in forensic investigations for several reasons: Tracing User Activity : By examining the paths pointed to by environment variables, forensic analysts can trace the activities of users on the system. Streamlining Analysis : Knowing how to reference environment variables can streamline the forensic analysis

  • Analyzing Recycle Bin Metadata with RBCmd and $I_Parse

    Artifacts with KAPE KAPE (Kroll Artifact Parser and Extractor) is a powerful tool that can collect forensic Output: Conclusion Analyzing Recycle Bin metadata is a crucial step in digital forensics. Additionally, KAPE  simplifies the collection of these artifacts, making your forensic workflow more

  • Understanding Chrome's Data Storage and Session Recovery : What Your Browser Remembers

    Chrome encrypts saved passwords using Windows DPAPI , but live forensics tools like NirSoft ChromePass When forensic analysts examine session recovery data, they can uncover: A list of open tabs from the Extracting and Analyzing Session Data for Investigation Forensic analysts can extract session recovery Understanding how Chrome stores and manages session data allows forensic analysts to reconstruct user -------------------------------------------------------- Stay with me we will continue about Google forensic

  • Theoretical Important notes for Memory Acquisition and Disk Encryption

    Introduction: In the world of digital forensics, thorough memory acquisition and disk encryption detection memory acquisition, tools used and the importance of considering disk encryption before proceeding with forensic Step 4: Capture Essential Forensic Data Collect critical artifacts such as $MFT, $Logfile, registry hives website) Conclusion: Memory acquisition and disk encryption detection are fundamental steps in Windows forensics

  • Understanding AutoStart Persistence in Windows: Key Locations and Detection Methods

    of these locations are found within the Windows Registry, offering a somewhat centralized place for forensic Detecting and Analyzing AutoStart Entries Given the wide range of ASEPs, forensic analysts and incident Understanding the most commonly exploited ASEPs and utilizing forensic tools to monitor them can significantly Whether you're an incident responder, a forensic analyst, or an enthusiast looking to improve your cybersecurity

  • System Configuration: Reading the Machine's Own Biography

    Think of system configuration forensics as writing the opening chapter of a case file. ---------- Time Zones: The Silent Killer of Case Timelines This is the part of system configuration forensics Shouldn't Skip There's one piece of advice buried in this topic that's worth repeating in bold: set your forensic --------------- Full Series Below: https://www.cyberengage.org/courses-1/mastering-windows-registry-forensics

  • The Run Dialog: Small Key, Loud Evidence

    -------------------------Dean-------------------------------------------------------- Full Registry forensic Series: https://www.cyberengage.org/courses-1/mastering-windows-registry-forensics%3A

  • Navigating the Email Clients, Features of Modern Email Clients, Corrupted Email Archives

    Forensic Analysis: Orphan .ICS files in temporary directories can offer evidence. Forensic Analysis: Importing these files into a forensic station can enable detailed analysis. Conclusion Understanding the intricacies of email client data storage is paramount for forensic investigators

  • How to Use SrumECmd to Parse and Analyze SRUDB.dat Files

    For forensic analysis, performance troubleshooting, and security auditing, parsing and analyzing this One underappreciated forensic advantage: SrumECmd can surface evidence of applications that no longer Use a forensic imager or live triage tool. Always work on copies, never originals. standalone or integrate it with KAPE for automated workflows, SrumECmd can significantly enhance your forensic

bottom of page