dfir 10
- Speaking at NCCC 2024
- Memory Forensics – RansomCare Investigation Case 1
- Challenge #9 – Encrypt Them All Case
- Challenge #8 – NTFS File System Case
- Challenge #7 – SysInternals Case
- Investigating USB Drives using Mount Points Not Drive Letters
- No Drive Letter, No USB Evidence? Think Again!
- Howto Setup and use the CuckooVM v2
- Investigating Windows Systems (Book Review)
- Forensic Acquisitions over Netcat