Lateral Movement - Remote Desktop Protocol (RDP) Event Logs
Identify the important Windows Event logs to hunt RDP lateral movement, both from the source and target system.
Lateral Movement - Remote Desktop Protocol (RDP) Event Logs
RDP Bitmap Cache - Piece(s) of the Puzzle
Windows Defender MP Logs - A Story of Artifacts
SUM UAL - Investigating Server Access with User Access Logging
Linux Forensics - Collecting a Triage Image Using The UAC Tool
Respond and Investigate a Compromised Google Workspace User
Minimizing Malicious Script Execution
Evidence of Program Existence - Amcache
Evidence of Program Existence - Shimcache
Investigating a Compromised Web Server
Artifacts of Execution: Prefetch - Part One
Windows Artifacts For Intrusion Analysis: A Treasure Trove of Evidence
Cloud Incident Response: Investigating AWS Incidents
Sysmon: When Visibility is Key
A LNK To The Past: Utilizing LNK Files For Your Investigations