top of page

Search


From Chaos to Chronology: The Power of Forensic Timelines
In incident response, attackers leave behind thousands of artifacts but without context, they’re just scattered clues. Forensic timelines bring those events into order, helping investigators reconstruct the attack, identify gaps in the analysis, and understand the full story of a compromise.
Mar 99 min read


Utilizing QELP for Rapid ESXi Analysis
Learn how to use the QELP tool to quickly triage ESXi servers. Parse through the relevant logs quickly in order to investigate malicious activity.
Oct 31, 20256 min read


Evil on Schedule: Investigating Malicious Windows Scheduled Tasks
Discover how to detect and analyze malicious Windows Scheduled Tasks with real-world examples, event log artifacts, and forensics tips.
Aug 18, 202512 min read


AnyDesk - Investigating Threat Actors Favorite Tool
AnyDesk is a commonly abused, but legitimate RMM tool. Learn about the artifacts left behind and how to investigate AnyDesk abuse.
Mar 12, 20257 min read
bottom of page