AI Provider Settings
Keys are stored only for your session
Models are fetched from the selected provider after validating your API key.

Category: Artifacts

All posts in the "Artifacts" category

4n6Post Artifact, CTF Write ups and AI Tools

Dec 20
Artifacts Writeups AI Tools Docker Smelling Salts
Digital Forensics CTF Writeups

4N6Post Artifacts

Oct 14
Artifacts
Digital Forensics 4N6Post MFT Analysis

Registry - SAM

Oct 14 28 min read

SAM Database - Windows Security Account Manager Security Account Manager (SAM) database in short, is the critical components of Windows security …

Artifacts
windows forensics registry DFIR

MACB Timestamp Reference

Dec 16 11 min read

MACB Forensic Timestamp Reference I put together a nice little post here detailing the behavior of MACB timestamps (Modified, Accessed, Changed, …

Artifacts
4n6 digital forensics timestamps

MRU (Most Recently Used)

Oct 2 3 min read

The MRU (Most Recently Used) registry is a database in Microsoft Windows that stores information about recently opened files, URLs, and other items. …

Artifacts
4n6 digital forensics windows forensics

Amcache.hve

Oct 1 2 min read

Amcache.hve is a forensic artifact that can be used to uncover valuable information about a computer system, both in normal and malicious use cases. …

Artifacts
registry 4n6 digital forensics

TheHive - Security Incident Response Platform

Jan 15 1 min read

Ref: Strangebee - Installation TheHive is a scalable, open-source Security Incident Response Platform (SIRP) designed to assist security teams in …

Docker Artifacts
thehive security incident response sirp

Velociraptor - Endpoint Visibility & Digital Forensics

Jan 15 1 min read

Velociraptor is a web-based tool designed for endpoint visibility and management. It provides a user-friendly interface for monitoring and managing …

Docker Artifacts
velociraptor endpoint management digital forensics

ShellBags Registry

Jan 2 7 min read

Understanding ShellBags in the Windows Registry: A Deep Dive As my other posts likely portrais. The Windows operating system is a treasure of love and …

Artifacts
Digital Forensics registry windows

KAPE to SOF-ELK

Jan 1 4 min read

Resources and Help SOF-ELK from GitHub or VM from FOR572 Kroll - KAPE Direct Download SOF-ELK KAPE Support YouTube Video Guide by SystemForensics …

Artifacts
SOF-ELK KAPE Digital Forensics

Registry- SYSTEM Select

Jan 1 3 min read

Windows Registry SYSTEM Select Key Analysis The Windows Registry is a hierarchical database that stores configuration information for the operating …

Artifacts
4n6 digital forensics

Registry- Start, Shutdown, and Reboot

Oct 1 4 min read

Windows Registry: System Start, Shutdown, and Reboot Tracking The Windows registry is a hierarchical database that stores configuration settings for …

Artifacts
4n6 digital forensics windows forensics

ShimCache

Oct 1 7 min read

ShimCache - Windows Application Compatibility Cache for Digital Forensics Shimcache is a Windows artifact that stores information about programs that …

Artifacts
4n6 digital forensics windows forensics

Windows Install Date & Time

Jan 15 3 min read

The Windows registry is a central repository of configuration data for the Windows operating system and its applications. One important aspect of the …

Artifacts
4n6 digital forensics windows forensics

Ad Disabling Tailored Experience

Jan 1 2 min read

Customizing Windows: Ad Disabling and Tailored Experience In the realm of Windows customization, users often seek ways to tailor their experience to …

Artifacts
registry 4n6 digital forensics

Enable Windows BSOD Detail

Jan 1 2 min read

Introduction By default, Windows displays a simple emoticon (smiley face) when a Blue Screen of Death (BSOD) occurs. However, if you prefer to see …

Artifacts
registry 4n6 digital forensics

File and Folder Opening - Link Files (LNK)

Jan 1 6 min read

Windows users are likely familiar with .lnk files, also known as LNK Link files. These files are shortcuts that point to another file or folder on the …

Artifacts
4n6 digital forensics windows forensics

JumpList Forensics

Jan 1 5 min read

JumpList Forensics JumpList is a feature of Microsoft Windows operating systems that allows users to quickly access frequently used files, folders, …

Artifacts
4n6 digital forensics windows forensics

MFT

Jan 1 8 min read

MFT Analysis - Master File Table Forensics Guide The $MFT, or Master File Table, plays a crucial role in the NTFS (New Technology File System) …

Artifacts
4n6 digital forensics windows forensics

Prefetch

Jan 1 7 min read

Windows Prefetch Analysis - Digital Forensics Execution Tracking Windows Prefetch is a feature in the Windows operating system that was first …

Artifacts
4n6 digital forensics windows forensics

Recycling.Bin / Recycler

Jan 1 5 min read

The Recycling Bin is a well-known feature in Windows operating systems that acts as a temporary storage location for deleted files. However, what many …

Artifacts
4n6 digital forensics windows forensics

Registry- RunMRU

Jan 1 3 min read

Understanding the RunMRU Registry: Security Implications and Forensic Value The RunMRU (Most Recently Used) registry is a key component of the …

Artifacts
Digital Forensics windows registry

Registry- UserAssist

Jan 1 4 min read

UserAssist Registry Analysis - Windows Program Execution Tracking UserAssist is a feature of the Windows operating system that keeps track of the …

Artifacts
Windows Forensics

SysInternals Tools Registry Forensics

Jan 1 8 min read

SysInternals Tools - Registry Forensics and Analysis What is SysInternals? SysInternals is a suite of advanced system utilities for Microsoft Windows …

Artifacts
4n6 digital forensics windows forensics

TimeZone Information

Jan 1 4 min read

The Windows registry is a critical component of the Windows operating system. It stores important configuration data and settings that help the …

Artifacts
4n6 digital forensics windows forensics

TypedPath Registry

Jan 1 3 min read

Registry Section of TypedPath: Understanding Its Importance in Digital Forensics The registry is an important aspect of a computer’s operating …

Artifacts
4n6 digital forensics windows forensics

Windows Border Size Modification

Jan 1 3 min read

Exploring Windows Border Size Modification Welcome to our exploration of a subtle yet impactful customization in the Windows operating system. Today, …

Artifacts
4n6 digital forensics windows forensics

Windows Generic Installation Keys

Jan 1 4 min read

SOURCE: https://www.windowsafg.com/keys.html This is just a copy of the data from the source windowafg. I make a copy so that others can find it. …

Artifacts
4n6 digital forensics windows forensics

Windows USB Connection Analysis

Jan 1 4 min read

USB connections are a commonly used method for transferring data between computers and other electronic devices. In Windows, the use of USB …

Artifacts
4n6 digital forensics windows forensics

WMI Filter Query Consumer

Jan 1 5 min read

Windows Management Instrumentation (WMI) is a Microsoft technology that provides a unified way of managing Windows operating systems and applications. …

Artifacts
4n6 digital forensics windows forensics