Category: Labs

Making Sense of RDP Connection Event Logs

Investigating lateral movement activities involving remote desktop protocol (RDP) is a common aspect when responding to an incident where nefarious…

Read post
Window Forensics

Windows Forensics: Evidence of Execution

Ever wonder how forensic analysts and information security and incident response practitioners can recreate timelines demonstrating who ran which applications…

Read post