Skip to content

Endpoint Forensics

Collecting and analyzing evidence from Windows and Linux systems: what to collect, where it lives, and the tools that parse it.

Reference Pages

Page Description
Evidence Handling Order of volatility, integrity, and chain of custody
Forensic Workstation Setting up an analysis environment
File Systems FAT, exFAT, NTFS, and EXT, and the structures useful in investigations
File Metadata Timestamps, properties, and embedded metadata
File Hashing Hashing for integrity and threat intel lookups
Windows Artifacts Prefetch, LNK files, jump lists, Recycle Bin, and live response commands
Linux Artifacts Accounts, logs, history, and persistence locations
Memory Artifacts Memory capture, pagefile, swap, and hibernation files

Tools

Category Tools
Acquisition and triage FTK Imager, KAPE
Analysis platforms Autopsy, SIFT Workstation
Memory Volatility
Windows artifacts PECmd, JumpList Explorer, Windows File Analyzer, Sysinternals
Browser Browser History Capturer, Browser History Viewer
Files and data recovery ExifTool, Scalpel, Steghide, John the Ripper
Other Other Tools