home.social

#windowsforensics — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #windowsforensics, aggregated by home.social.

fetched live
  1. FortiGuard IR researchers have highlighted unexpected forensic value in the AutoLogger-Diagtrack-Listener.etl file on modern Windows systems.

    Despite low exploitation severity, the artefact has shown the ability to preserve historical process-execution data, including deleted binaries and command-line traces — helpful in ransomware investigations.

    What’s your view on ETW-based artefacts in DFIR workflows?

    Source: fortinet.com/blog/threat-resea

    Share your insights and follow us for more clear, unbiased analysis.

    #InfoSec #DFIR #ThreatIntel #WindowsForensics #ETW #Telemetry #CyberSecurity #IncidentResponse #SecurityResearch #ThreatAnalysis

  2. Deleted a folder? Shellbags is the accessory you need...

    They’re one of the most valuable forensic artifacts for tracing user activity in Windows, even if the folders are gone.

    This blog post by our Joseph Williams walks through how Shellbags work, how to analyse them with tools like ShellBags Explorer, and what they reveal about user navigation through local, external, and network locations.

    If you're in DFIR, this is one artifact you don't want to miss.

    📌 Read the blog: pentestpartners.com/security-b

    #DFIR #DigitalForensics #WindowsForensics #IncidentResponse #Shellbags #CyberSecurity #ForensicAnalysis

  3. Deleted a folder? Shellbags is the accessory you need...

    They’re one of the most valuable forensic artifacts for tracing user activity in Windows, even if the folders are gone.

    This blog post by our Joseph Williams walks through how Shellbags work, how to analyse them with tools like ShellBags Explorer, and what they reveal about user navigation through local, external, and network locations.

    If you're in DFIR, this is one artifact you don't want to miss.

    📌 Read the blog: pentestpartners.com/security-b

    #DFIR #DigitalForensics #WindowsForensics #IncidentResponse #Shellbags #CyberSecurity #ForensicAnalysis

  4. Handbook of windows forensic artifacts across multiple Windows version with interpretation tips with some examples: github.com/Psmths/windows-fore

    #WindowsForensics

  5. RT @[email protected]

    If you've been looking to learn more about Windows Forensics, the new Practical Windows Forensics course on TCM Academy is a great introduction course to get you started.

    Learn more here: academy.tcm-sec.com/p/practica

    #forensics #windows #microsoft #windowsforensics #cybersecurity

    🐦🔗: twitter.com/TCMSecurity/status