Beyond the Security Log: Uncovering Malware Through System, Application, WER, and Defender Artifacts
In the course of identifying indicators of malicious software execution, systematic examination o…
In the course of identifying indicators of malicious software execution, systematic examination o…
Once initial access has been established and privileges elevated, the lateral transfer of files a…
Privileged principals possess the capability to purge Windows event logs. This includes the local…
Windows Services constitute a near-ubiquitous control surface within the operating system's p…
Lateral movement techniques constitute a core component of sophisticated cyber-attack campaigns, …
In digital forensics and incident response, auditing account usage through Windows Security event…
Log2timeline was conceived by Kristinn Guðjónsson in conjunction with his GIAC Certified Forensic…