Practical Tips for Conducting Digital Forensics Investigations
ID: 74f0d762-8fec-5093-8131-f5659431a2c5
STIX ID: report--74f0d762-8fec-5093-8131-f5659431a2c5
Feed Name: Huntress Blog
This article provides practical tips for accelerating digital forensics investigations: narrow the time window to build a focused timeline; collect and correlate Windows artifacts such as Prefetch, PowerShell history, and SRUM; analyze key event logs (system, security, application, DNS, firewall, and RDP) with tools like Chainsaw; determine initial access via VPN/email/RDP evidence; and watch for repeated, lazy attacker patterns (e.g., executables in C:\programdata) to quickly assess persistence, data theft, and ensure full ejection and lessons learned.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
