Endpoint Forensics
Collecting and analyzing evidence from Windows and Linux systems: what to collect, where it lives, and the tools that parse it.
Reference Pages
| Page |
Description |
| Evidence Handling |
Order of volatility, integrity, and chain of custody |
| Forensic Workstation |
Setting up an analysis environment |
| File Systems |
FAT, exFAT, NTFS, and EXT, and the structures useful in investigations |
| File Metadata |
Timestamps, properties, and embedded metadata |
| File Hashing |
Hashing for integrity and threat intel lookups |
| Windows Artifacts |
Prefetch, LNK files, jump lists, Recycle Bin, and live response commands |
| Linux Artifacts |
Accounts, logs, history, and persistence locations |
| Memory Artifacts |
Memory capture, pagefile, swap, and hibernation files |