Windows Forensics: Lateral Movement Adversary Tactics and Detection
Once initial access has been established and privileges elevated, the lateral transfer of files a…
Once initial access has been established and privileges elevated, the lateral transfer of files a…
Privileged principals possess the capability to purge Windows event logs. This includes the local…
Windows Services constitute a near-ubiquitous control surface within the operating system's p…
Lateral movement techniques constitute a core component of sophisticated cyber-attack campaigns, …
In digital forensics and incident response, auditing account usage through Windows Security event…
Log2timeline was conceived by Kristinn Guðjónsson in conjunction with his GIAC Certified Forensic…
The foundational and most prevalent modality of temporal reconstruction in digital forensics is t…