#windowsforensics
📢 Reminder: Our Windows Forensic Investigation webinar is almost here!

📅 When: Dec 4th, 12 PM ET
🔍 Explore Windows artifacts & forensic techniques.
👉🏻 Register now: bit.ly/c5w-webinar4
#C5W #CCDFA #DFIR #WindowsForensics
December 4, 2024 at 2:57 AM
NTUSER.DAT is a system file found in every user profile on a Windows system. It stores the user's Registry hive under HKEY_CURRENT_USER (HKCU).

🧠 Inside?

* Program settings
* Recent files
* User preferences
* Evidence of activity

#DFIR #LearningDFIR #WindowsForensics
June 16, 2025 at 10:20 PM
Preconfigured Windows VM for DFIR investigations with a pinned DFIR_Toolbar and Explorer right-click integrations for artifact and disk-image parsing. Inspired by SIFT Workstation. #DFIR #WindowsForensics #tool https://bit.ly/3J6cZQb
October 14, 2025 at 4:10 PM
Crow Eye: open-source Windows forensics engine with GUI for collecting, parsing, and correlating artifacts. Correlation engine links evidence across sources. GPL v3, single developer. #tool #DFIR #windowsforensics https://bit.ly/4fMpb6G
May 28, 2026 at 1:57 PM
Enjoy the new Forensic Impact blog by guest blogger Vamsi Krishna Chinta (lnkd.in/etzt7Ckm) where he goes into Windows Log analysis using open-source tools. bit.ly/4c6eh80 #DFIR #DigitalForensics #WindowsForensics
March 26, 2025 at 2:06 PM
Use Process Explorer and Sysmon to investigate orphaned Windows child processes, PPID spoofing, and process hollowing across enterprise IR workflows.

#solideinfo #MemoryForensics #DFIR #CyberCrime #cybersecurity #WindowsForensics
Windows Orphaned Child Processes Investigated with Process Explorer and Forensic Telemetry
Use Process Explorer and Sysmon to investigate orphaned Windows child processes, PPID spoofing, and process hollowing across enterprise IR workflows.
solideinfo.com
April 13, 2026 at 5:40 PM