Blog

NTUSER.DAT Forensics Analysis 2025

Start Reading

Scope with Velociraptor. Analyze with Cyber Triage.

Start Reading

Windows Registry Forensics Cheat Sheet 2025

Start Reading

SOC Investigations 2025: Clues Are Key

Start Reading

3.14 Release Brings New UIs, Hayabusa, Baselining, and Much More

Start Reading

ShimCache and AmCache forensic analysis.

ShimCache and AmCache Forensic Analysis 2025

Start Reading

How to Find Evidence of Network Windows Registry.

How to Find Evidence of Network Windows Registry

Start Reading

How EDR evasion works.

How EDR Evasion Works: Attacker Tactics

Start Reading

UserAssist Forensics featured image.

UserAssist Forensics 2025

Start Reading

2025 Guide to Registry Forensics Tools

2025 Guide to Registry Forensics Tools

Start Reading

Shellbag Forensic Analysis 2025

Shellbags Forensic Analysis 2025

Start Reading

Alert Triage vs Endpoint Triage

Alert Triage vs Endpoint Triage: What SOCs Need to Know

Start Reading