🖥️
Windows DFIR
⌘Ctrlk
🖥️
Windows DFIR
  • Introduction
    • Windows Quick Tips
    • Account Usage
      • Authentications SAM Artifacts
      • Authentications (Windows Event Log)
      • Group Membership
      • RDP
      • SSH
      • Rouge Local Accounts
      • CrowdStrike Searches
    • Browser Usage
    • Processes
    • Cloud Storage
    • Deleted File or File Knowledge
    • File Download
    • Folder/File Opening/Creation
    • Persistence
    • Physical Location
    • Program Execution
    • Shadow Copies
    • USB Usage
    • Windows Services
    • System Information
    • Event IDs
    • Initial Access
    • Execution
    • Persistence
    • Privilege Escalation
    • Defense Evasion
    • Credential Access
    • Discovery
    • Lateral Movement
    • Collection
    • Command and Control
    • Exfiltration
    • Impact
    • Cached Credentials
    • Domain Controller Password Spraying
Powered by GitBook
Page cover
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. Windows Artifacts

Account Usage

Authentications SAM ArtifactsAuthentications (Windows Event Log)Group MembershipRDPSSHRouge Local AccountsCrowdStrike Searches
PreviousServer File/Folder LocationsNextAuthentications SAM Artifacts

Last updated 2 years ago