Skip to content
  • About
  • Contact
  • Find Me
  • Posts
  • LinkedIn
  • Twitter
  • GitHub
  • This Week In 4n6
Search
Close

ThinkDFIR

random musings on DFIR topics

Tag: documentation

Documenting my work

October 16, 2017December 11, 2017 Phill Moore8 Comments

TLDR: This is a post about how I document my examinations. I create a word document with a brain dump of my findings which includes a narrative that allows me to read through it in a way that gets me back into the mindset I was in when I completed the examination.

Read More »

Recent Posts

  • Timestamps in INDX Entries
  • Tracking screenshots with LNK files
  • I can see and hear you seeing and hearing me!
  • Introducing Awesome BEC
  • You want me to deal with how many VMDKs!?
  • Metaspike CTF – Week 6 – “HODL onto your timestamps”
  • Metaspike CTF – Week 5 – “Spot the DFIRence”
  • Metaspike CTF – Week 4 – “IM APparently making this harder than it was meant to be”
  • Metaspike CTF – Week 3 – “PS(s)T, Can you keep a secret message?”
  • Metaspike CTF – Week 2 – “As per my previous email”

Enter your email address to follow this blog and receive notifications of new posts by email.

Archives

logo

RSS SANS Teaching

  • An error has occurred; the feed is probably down. Try again later.
Website Powered by WordPress.com.
Back to top
  • Follow Following
    • ThinkDFIR
    • Join 71 other followers
    • Already have a WordPress.com account? Log in now.
    • ThinkDFIR
    • Customize
    • Follow Following
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar