dfir

Tools & Defense

Velociraptor for Endpoint DFIR at Scale

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Incident Response Fundamentals: The PICERL Lifecycle

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Linux auditd: Configuration and Threat Hunting

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Security Logging and Monitoring: What to Collect and Why

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Building a Detection Pipeline with the Elastic Stack

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

DNS-Based Threat Hunting

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Threat Hunting: Building and Testing Hypotheses

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Windows Event Log Analysis for Incident Responders

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Memory Forensics with Volatility 3

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

NTFS Forensics: The Master File Table (MFT)

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Windows Registry Forensics for DFIR

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Execution Artifacts: Prefetch, Shimcache, and Amcache

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Linux Forensics: Triage and Artifact Collection

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Email Header Analysis and Phishing Triage

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Deobfuscating Malicious PowerShell for Analysts

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

osquery: SQL-Powered Endpoint Visibility

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

Dynamic Malware Analysis in a Sandbox: A Practical Behavioral Workflow

A hands-on guide to dynamic malware analysis with Procmon, Process Hacker, and Wireshark, plus Blue Team detection.