📘
DFIR
Ctrlk
  • Networking
    • Networking
  • Windows
    • Administration
    • Forensics
      • System Info
      • Memory
      • Network Logs
      • File System
      • Registry
      • Network Share
      • Exfiltration
      • Evidence of Execution
      • Hacktool Artifacts
      • Event Logs
      • 3rd Party Apps
        • IIS
        • Kubernetes
        • GitHub
        • Jenkins
        • Snowflake
        • Misc
        • "TA Tools"
        • Identity Apps
        • Microsoft
        • SysInternals
        • RMM
        • Zoom
        • Browser Forensics
      • Example Page
    • Cheat Sheet
    • Investigation
    • Internals
    • Active Directory
    • MISC
  • Linux
    • Forensics
    • SSH
    • Linux WebShells
    • Directories of Interest
    • Internals
  • Enterprise Architecture
    • CI/CD Pipline
    • Citrix
    • Web Applications
    • The Cloud
    • vSphere
    • Containers
    • Troubleshooting
  • Mac
    • Forensics
  • Attacker Information
    • Adversary Operations
    • Actor Playbooks
    • Abused Domains
  • IR Playbook
    • Activity from Unmanaged Host
    • Recommendations
  • Reverse Engineering
    • Python - Pyinstaller
Powered by GitBook
On this page
  • What Is?
  • Forensic Value:
  • File Location:
  • Parse Data:
  • Considerations:
  • Example:
  • Analysis Tips:
  • Anti-Forensics:
  1. Windows
  2. Forensics
  3. 3rd Party Apps

GitHub

LogoPage not found - HackTricks Cloudcloud.hacktricks.xyz
LogoBasic Github Information - HackTricks Cloudcloud.hacktricks.xyz
LogoSecurity log events - GitHub DocsGitHub Docs

LogoSecure use reference - GitHub DocsGitHub Docs

What Is?

Forensic Value:

File Location:

Parse Data:

Considerations:

Example:

Analysis Tips:

Anti-Forensics:

PreviousKubernetesNextJenkins

Last updated 1 year ago