DFIR 20
- PhonePe Forensics in iOS What Your iPhone Stores and How Investigators Read It
- Amcache-ProgramID — The Orphan Dll Attribution
- How DNS Hides Inside HTTPS
- Absolute Persistance
- Inside The Registry
- RADAR – An Obscure Execution Artifact
- GUI Execution Artifact - Program Compatibility Assistant
- Dissecting RDP Activity
- MCAB - Changed Vs Modified
- Acquiring RAM Through Cooling Methods
- Amcache:The Most Misunderstood Artifact
- The Invisible Insider!
- LNK File Forensics — Experimental Case Study
- Linux Forensics Essentials
-
Windows Forensics Tools
-
Digital Forensics Tools
-
Ericzimmerman Tools | Windows Forensics -
CFReD | Nist | Hacking Case
- How NTFS Self-References Its $MFT
- Windows Artifacts