top of page

Search


Utilizing QELP for Rapid ESXi Analysis
Learn how to use the QELP tool to quickly triage ESXi servers. Parse through the relevant logs quickly in order to investigate malicious activity.
Oct 316 min read


Evil on Schedule: Investigating Malicious Windows Scheduled Tasks
Discover how to detect and analyze malicious Windows Scheduled Tasks with real-world examples, event log artifacts, and forensics tips.
Aug 1810 min read


AnyDesk - Investigating Threat Actors Favorite Tool
AnyDesk is a commonly abused, but legitimate RMM tool. Learn about the artifacts left behind and how to investigate AnyDesk abuse.
Mar 127 min read


A BITS of a Problem - Investigating BITS Jobs
Investigate BITS jobs and identify the event logs and database associated with this!
Jan 78 min read
bottom of page