windows 8
- Investigating USB Drives using Mount Points Not Drive Letters
- No Drive Letter, No USB Evidence? Think Again!
- Investigating Windows Systems (Book Review)
- Windows InstallTime vs InstallDate Registry Values
- Update: Hidden Prefetch Files Detection using New PECmd
- Creating a Hidden Prefetch File to Bypass Normal Forensic Analysis
- Forensic Analysis: Creating User GUI vs CLI
- الجزء السادس من محاضرات HTID