Enhanced Windows Forensic Artifact Master List - 2025 Edition

A comprehensive deep dive into the most critical forensic artifacts in modern Windows environments, designed for intermediate-to-expert DFIR professionals.

[read more]

Correlating NTFS $LogFile and $UsnJrnl: A DFIR Practitioner’s Guide to Transactional Analysis

Advanced correlation methodology for fusing NTFS $LogFile and $UsnJrnl artifacts to create transaction-level proof of filesystem activity and defeat anti-forensics techniques.

[read more]