🖥️
Windows DFIR
Ctrlk
  • Introduction
  • Windows Artifacts
    • Windows Quick Tips
    • Account Usage
    • Browser Usage
    • Processes
      • at.exe
      • explorer.exe
      • lsass.exe
      • lsaiso.exe
      • PuTTy.exe
      • runtimebroker.exe
      • services.exe
      • smss.exe
      • System
      • svchost.exe
      • winlogon.exe
      • wininit.exe
    • Cloud Storage
    • Deleted File or File Knowledge
    • File Download
    • Folder/File Opening/Creation
    • Persistence
    • Physical Location
    • Program Execution
    • Shadow Copies
    • USB Usage
    • Windows Services
    • System Information
    • Event IDs
  • Windows DFIR & MITTR
    • Initial Access
    • Execution
    • Persistence
    • Privilege Escalation
    • Defense Evasion
    • Credential Access
    • Discovery
    • Lateral Movement
    • Collection
    • Command and Control
    • Exfiltration
    • Impact
  • SOC Related
    • Cached Credentials
    • Domain Controller Password Spraying
Powered by GitBook
Page cover
On this page

Was this helpful?

  1. Windows Artifacts

Processes

at.exeexplorer.exelsass.exelsaiso.exePuTTy.exeruntimebroker.exeservices.exesmss.exeSystemsvchost.exewinlogon.exewininit.exe
PreviousBrowser History FinderNextat.exe

Last updated 1 year ago

Was this helpful?