logo

Protecting the Evidence in Real-Time with KQL Queries

ID: 14aa548b-9327-5bf5-88e6-165a873f9e4e

STIX ID: report--14aa548b-9327-5bf5-88e6-165a873f9e4e

Feed Name: Detect FYI

Date Published: 2025-07-28

Date Updated: 2026-04-19

Author: Sergio Albea

...
...

Guidance article on preserving Windows forensic evidence using KQL, emphasizing detection of attacker anti-forensic behavior during ransomware’s final stages. It explains that automatic RegBack backups are disabled by default in modern Windows, weighs the benefits of re-enabling RegBack for recovery, and recommends monitoring related registry keys to detect potential tampering early.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.