top of page

Search Results

Search results for "forensic"

318 results found for "forensic"

  • UserAssist: The Registry Key That Watched Everything You Clicked, Application Execution

    And it was never designed for forensics. It was designed to make your Start Menu smarter. The fact that it became one of the most powerful execution-tracking artifacts in Windows forensics is ------------ Complete Series Below https://www.cyberengage.org/courses-1/mastering-windows-registry-forensics

  • Hidden in Plain Sight: How Attackers Weaponize Alternate Data Streams to Hide Malware

    The good news is there are several ways to detect ADS abuse, both on live systems and during forensic For forensic analysis , Sysinternals Streams.exe is the go-to tool for getting a clean list of non-standard The good news is that with the right tooling — Sysmon, EDR with command-line visibility, or forensic

  • Google Takeout: The Quiet Data Exit Nobody Talks About

    But from a security and forensics perspective, Takeout is a built-in data export mechanism  that works ----------------------------------------------------------------------------------------- Important Forensics This is one of the few highly forensically relevant logs that requires: Manual Admin Console access Or

  • Digital Evidence: Techniques for Data Recovery and Analysis

    In today's digital age, forensic investigators face the challenge of extracting valuable evidence from Tools like Magnet Forensics' Internet Evidence Finder (IEF) facilitate the process by scanning for fragments and provide clarity in complex litigation scenarios https://exiftool.org/ Recovering Deleted Files: Forensic Conclusion: By leveraging techniques such as datastream carving, file carving, and metadata parsing, forensic

  • Collecting Evidence from Google Workspace

    In reality, they behave quite differently—and those differences really matter during forensic analysis Collecting Logs via the Workspace Admin SDK (API) Now this is where things get really interesting for forensic Admin UI → great for quick checks and visual walkthroughs Admin SDK / API → best for fast, consistent, forensic‑grade

  • Effective Incident Response: Containment and Eradication

    Forensics Imaging: Critical Importance: A good forensic image is crucial. System Backups: Often, systems haven't been backed up in years, making forensic imaging vital for preserving

  • Part 3 Code Injection : How to detect it and Finding Evil in Memory with MemProcFS FindEvil Plugin

    ------------- Power of Volatility for Detection We can still catch these manipulations using memory forensics closer look at a potentially infected process, powershell.exe (PID: 5352) , using ldrmodules  in our forensic Because malware often avoids writing files to disk to evade antivirus detection and forensic analysis Using f orensic tools like malfind  (which detects injected memory sections) and ldrmodules  (which identifies If you’re serious about memory forensics, this tool should be in your arsenal!

  • Understanding VM Types and Azure Network for IR

    For incident response and forensic investigations, the focus is typically on virtual machines (VMs)   Forensics often involves snapshotting the OS disk  of a compromised VM, attaching that snapshot to a Outbound data transfers (when retrieving forensic data). ------------------------------------------------------------------------- Azure Storage: Central to Forensics highly versatile and commonly used for storing large amounts of unstructured data, such as logs during forensic

  • History of macOS and macOS File Structure

    macOS has its own Library directory  (~/Library/), which contains various subdirectories packed with forensic By examining these files, forensic analysts can uncover user settings, saved states, and even recent The ones that are not  links often contain the most valuable forensic data, such as app-specific databases --------------------------------------------------------------------------------------- Wrapping Up Forensic investigating user preferences, app data, cached files, or system logs, each directory has its own forensic

  • USB Device Profiling: How to Track Key Timestamps

    When it comes to USB key forensics, understanding the timeline of device connections and disconnections ----------------------------------- Conclusion: Tracking USB device activity is a powerful tool for forensic

  • Making Sense of $UsnJrnl and $LogFile : Why Journal Analysis is a Game Changer

    For more in-depth details, check out the presentation “NTFS Log Tracker”  from Forensic Insight—it’s -------------------------------- Wrapping Up By combining insights from both $UsnJrnl and $LogFile, forensic If you're looking to dive deeper into NTFS forensic analysis, checking out tools like istat for parsing So, the next time you're diving into forensic analysis, don’t just stop at the $MFT—dig into the journals

  • Understanding and Managing Thumbnail Cache in Windows: Tools thumbcache_viewer_64

    Practical Uses Forensics and Investigation For forensic investigators, examining thumbnail cache files

bottom of page