Zeroska
search
⌘Ctrlk
Zeroska
  • 🐱Zeroska - The Bold
  • Computer/Cyber Security
    • ⭐Fresh off the boat - for new Blue Teamer/ SOC Analyst
    • 💀Necromancer (DFIR)
      • 🕵️DFIR and DFIR case
      • 📔My own DFIR notes
        • The Mark of The Web (MOTW)
        • LNK Shortcut
        • Prefetch, AmCache, ShimCache in Windows
        • Malicious Document (VBA, Office, PDF, ...)
        • SRUM (System Resource Usage Monitor)
        • Volatility notes
        • Understand Logon Session in Windows
        • "Very" Hidden sheets in Excel
        • Hidden Processes
      • 📔Notes
    • 🧙‍♂️Defense Witchcraft
    • 💙My Current Blue Team Operation
    • 🏭ICS/OT
    • 🥷Threat Intelligence
  • 😒Computer and Technology
    • My Home Lab Setup
    • 🐴ELK Stack
    • 🐧Linux
    • 📦Containers
    • 🪠Splunk Learning Experience
  • Threat Hunting
    • Hunting for Implant
    • Using STRIDE and DREAD
    • 🐳Predators and Preys (Computing)
    • 📦Network Packet Analysis
    • Grep | Powershell Search | Regex
    • Hunting Resources
  • 🎵In my remains
    • Choices
    • The Art of Facing Unknown Problems
    • Build the best DFIR team
    • Reverse Engineering - Đồ án hướng ngành A "Hụt" của tôi
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Computer/Cyber Securitychevron-right
  2. 💀Necromancer (DFIR)

📔My own DFIR notes

The Mark of The Web (MOTW)chevron-rightLNK Shortcutchevron-rightPrefetch, AmCache, ShimCache in Windowschevron-rightMalicious Document (VBA, Office, PDF, ...)chevron-rightSRUM (System Resource Usage Monitor)chevron-rightVolatility noteschevron-rightUnderstand Logon Session in Windowschevron-right"Very" Hidden sheets in Excelchevron-rightHidden Processeschevron-right
PreviousMisconfiguration 0x01chevron-leftNextThe Mark of The Web (MOTW)chevron-right

Last updated 3 years ago