SavitarX
Ctrlk
LinkedinTryHackme
  • README
  • CERTIFICATIONS & notes
    • My Roadmap to Becoming a Penetration Tester & Red Team
    • Comp Network
    • Red Team
    • Blue Team
      • SOC Analyst
      • DFIR
        • Introduction to Digital Forensics
        • Investigating Windows Endpoints
          • Windows Event Logs
          • The Registry
          • Evidence of Execution
          • Persistence and Lateral Movement
          • Anatomy of NTFS
          • File Deletion and Recovery
          • LNK Files and Jump Lists
          • User Behavior Forensics
        • Investigating Windows Memory
        • Investigating Linux Devices
        • MacOS Forensics
    • Web Pentesting
  • Writeups
    • Tryhackme
    • HTB Sherlocks
  • Machines to pratice for
    • CPTS Preparation
    • CDSA Preparation
    • OSEP
  • The Computer Science and Engineering program
    • Read this
    • Computer Science
    • Security
Powered by GitBook
On this page
  1. CERTIFICATIONS & notes
  2. Blue Team
  3. DFIR

Investigating Windows Endpoints

Windows Event LogsThe RegistryEvidence of ExecutionPersistence and Lateral MovementAnatomy of NTFSFile Deletion and RecoveryLNK Files and Jump ListsUser Behavior Forensics
PreviousIntroduction to Digital ForensicsNextWindows Event Logs