Author Archives: 13Cubed

NTFS Journal Forensics

August 5th, 2019 📆 | 7841 Views ⚑

As a continuation of the “Introduction to Windows Forensics” series, this episode covers file system journaling in NTFS. From a

Tagged with:




RDP Event Log Forensics

June 18th, 2018 📆 | 7332 Views ⚑

As a continuation of the “Introduction to Windows Forensics” series, this episode takes a comprehensive look at the Windows event

Tagged with:




RDP Cache Forensics

February 12th, 2018 📆 | 2860 Views ⚑

As a continuation of the “Introduction to Windows Forensics” series, this video introduces Remote Desktop Protocol (RDP) Cache Forensics. Did

Tagged with:




Recycle Bin Forensics

January 22nd, 2018 📆 | 3091 Views ⚑

As a continuation of the “Introduction to Windows Forensics” series, this video introduces Recycle Bin Forensics. From Windows 95 to

Tagged with:




Shellbag Forensics

January 1st, 2018 📆 | 3397 Views ⚑

As a continuation of the “Introduction to Windows Forensics” series, this video introduces Shellbags. Have you ever customized the folder

Tagged with:




Windows SRUM Forensics

August 5th, 2017 📆 | 4852 Views ⚑

As a continuation of the “Introduction to Windows Forensics” series, this video introduces the System Resource Utilization Monitor (SRUM). This

Tagged with: