Incident Response

Tools & Defense

Velociraptor for Endpoint DFIR at Scale

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Incident Response Fundamentals: The PICERL Lifecycle

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Security Logging and Monitoring: What to Collect and Why

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Windows Event Log Analysis for Incident Responders

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Memory Forensics with Volatility 3

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

NTFS Forensics: The Master File Table (MFT)

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Windows Registry Forensics for DFIR

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Execution Artifacts: Prefetch, Shimcache, and Amcache

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Linux Forensics: Triage and Artifact Collection

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Email Header Analysis and Phishing Triage

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...