Windows Forensics, Part 6: Analyzing Image Caches
Learn how to analyze Windows icon and thumbnail caches with Thumbcache Viewer, recover traces, and correlate artifacts for forensics.
Read the postLearn how to analyze Windows icon and thumbnail caches with Thumbcache Viewer, recover traces, and correlate artifacts for forensics.
Read the postLearn how to analyze BAM and DAM registry artifacts on Windows to trace recent program executions, user activity, and incident response evidence.
Read the postAudit Active Directory LAPS delegations, spot risky ACLs on computer objects, and secure passwords. Learn how to detect and fix the issue.
Read the postLearn how SuperFetch artifacts reveal Windows execution history, where to find them, and how to analyze them with SysMainView.
Read the postLearn how to verify Microsoft and Linux ISO authenticity with hashes, GPG, and CheckISO to reduce supply chain risk and avoid tampered images.
Read the postLearn how Prefetch reveals Windows program execution traces and how to analyze it with WinPrefetchView and PECmd for forensics.
Read the postLearn how to use Amcache in Windows forensics to uncover executed and deleted tools, device traces, and key metadata. Discover the limits too.
Read the postDetect and block brute force attacks on Windows Server with PowerShell scripts. Learn how to analyze logs, spot suspicious IPs, and automate blocking.
Read the postLearn how ShimCache helps uncover Windows activity traces, spot suspicious files, and kick off a fast forensic analysis.
Read the post