Zeroska
Ctrlk
  • 🐱Zeroska - The Bold
  • Computer/Cyber Security
    • ⭐Fresh off the boat - for new Blue Teamer/ SOC Analyst
    • 💀Necromancer (DFIR)
      • 🕵️DFIR and DFIR case
      • 📔My own DFIR notes
        • The Mark of The Web (MOTW)
        • LNK Shortcut
        • Prefetch, AmCache, ShimCache in Windows
        • Malicious Document (VBA, Office, PDF, ...)
        • SRUM (System Resource Usage Monitor)
        • Volatility notes
        • Understand Logon Session in Windows
        • "Very" Hidden sheets in Excel
        • Hidden Processes
      • 📔Notes
    • 🧙‍♂️Defense Witchcraft
    • 💙My Current Blue Team Operation
    • 🏭ICS/OT
    • 🥷Threat Intelligence
  • 😒Computer and Technology
    • My Home Lab Setup
    • 🐴ELK Stack
    • 🐧Linux
    • 📦Containers
    • 🪠Splunk Learning Experience
  • Threat Hunting
    • Hunting for Implant
    • Using STRIDE and DREAD
    • 🐳Predators and Preys (Computing)
    • 📦Network Packet Analysis
    • Grep | Powershell Search | Regex
    • Hunting Resources
  • 🎵In my remains
    • Choices
    • The Art of Facing Unknown Problems
    • Build the best DFIR team
    • Reverse Engineering - Đồ án hướng ngành A "Hụt" của tôi
Powered by GitBook
On this page
  1. Computer/Cyber Security
  2. 💀Necromancer (DFIR)

📔My own DFIR notes

The Mark of The Web (MOTW)LNK ShortcutPrefetch, AmCache, ShimCache in WindowsMalicious Document (VBA, Office, PDF, ...)SRUM (System Resource Usage Monitor)Volatility notesUnderstand Logon Session in Windows"Very" Hidden sheets in ExcelHidden Processes
PreviousMisconfiguration 0x01NextThe Mark of The Web (MOTW)

Last updated 2 years ago

Was this helpful?

Was this helpful?