
Search Results
307 results found for "forensic"
- SentinelOne(P9- Settings): A Practical Guide/An Practical Training
Licenses : See which features you have paid for, such as Remote Ops Forensic or Network Discovery .
- Understanding Scheduled Tasks in Windows
If an attacker sets up a malicious scheduled task, forensic investigators can analyze these locations
- Aurora Incident Response: A Powerful Open-Source Tool for Investigators
Estimate when triage or forensic results will be available for specific machines. This section aids investigators in ensuring that every system gets the attention it needs during the forensic
- Carbon Black (P3:Investigate): A Practical Guide/An Practical Training
It’s like a forensic magnifying glass, enabling SOC analysts to dig into both failed and successful operations
- PowerShell Logging: Making the Invisible Visible
Understanding PowerShell Logging PowerShell isn’t just powerful for attackers — it’s also a goldmine for forensic window into the attacker’s mind/ When properly logged, PowerShell becomes one of your most valuable forensic
- Understanding NTFS File System Metadata and System Files
Understanding these NTFS components is vital for forensic analysts, system administrators, and cybersecurity
- Ransomware Actors Access and Stage Data for Exfiltration
Forensic Analysis of File and Folder Access From a forensic perspective, identifying which files or folders These tools leave traces in the registry, which can be useful for forensic analysis: WinZip Registry
- Who’s Using a Proxy or VPN in Your M365 Environment — and Why It Matters
Login Method for laser-focused investigations This flexibility is what makes Petra such a powerful forensic
- Email Log Search in Google Workspace – What You Can (and Can’t) See
phishing response Powerful for mail flow analysis Extremely time-sensitive But it is not a mailbox forensics
- Where NetFlow Either Shines or Struggles
It allows: long-term retention forensic-grade investigations zero impact on production network tooling
- Part 1 : Security in DevSecOps
I come from the Incident response/Forensic side.
- The Core Principles of Successful Incident Response
On-demand visibility – Point-in-time forensic acquisitions triggered when needed.











