Windows Forensics Part 11: Analyzing the MFT with KAPE and MFTECmd
Learn how to extract and analyze the NTFS MFT with KAPE and MFTECmd to recover file activity, deleted traces, and key timestamps.
Read the postLearn how to extract and analyze the NTFS MFT with KAPE and MFTECmd to recover file activity, deleted traces, and key timestamps.
Read the postDiscover SafeLine WAF, its semantic detection engine, anti-bot features, Docker Compose setup, and real-world attack testing.
Read the postLearn how to analyze the NTFS USN Journal with MFTECmd to recover file creation, renaming, moving, and deletion traces.
Read the postLearn how to harden Chrome, Edge, and Firefox with GPOs to block password leaks, sync abuse, risky extensions, and stolen sessions.
Read the postLearn how to check if your identity was used after state data breaches with official tools for FranceConnect, FICOBA, Banque de France and more.
Read the postLearn how the Windows Recycle Bin reveals deleted file paths, timestamps, and user SIDs with RBCmd in a forensic investigation.
Read the postDiscover why Windows logon, RDP, and VPN remain MFA blind spots under NIS 2, and how to secure Active Directory access without rebuilding infra.
Read the postDiscover Web-Check, the all-in-one OSINT tool to analyze DNS, TLS, headers, ports, and more. Learn how to use it or self-host it.
Read the postDiscover three free OSINT tools to find accounts linked to a username, email, or phone number. Install and use them with Docker today.
Read the postLearn how to scan an isolated network with Nmap over an SSH SOCKS tunnel using Proxychains, and validate your pivot in minutes.
Read the postLearn what a WAF does, how it blocks SQLi and XSS, and how to deploy one with ModSecurity and Docker in minutes.
Read the postLearn how to locate and analyze Windows ShellBags with SBECmd and ShellBags Explorer to trace folder browsing and renamed paths.
Read the postLearn how to analyze Windows LNK files with LECmd to uncover execution traces, paths, and user activity in digital forensics.
Read the postLearn how to analyze Windows icon and thumbnail caches with Thumbcache Viewer, recover traces, and correlate artifacts for forensics.
Read the postLearn why remote hiring and deepfakes expose IT onboarding, and discover how verified identity can secure first access.
Read the post