Category Forensics

Troubleshooting Log2timeline on Ubuntu

After recently earning the SANS 608 GIAC Enterprise Incident Response (GEIR) certification, I didn’t want to get complacent. The real world and real incidents won’t stop. Although the SANS FOR608 course provided a structured lab, I wanted to get better…

RDP Digital Forensics

Forensicating RDP: Remote Desktop Protocol (RDP) is an integral part of Windows OS, allowing users to connect remotely to other systems. However, its exposure to the internet can (and often has) lead to unauthorised access if not properly secured, making…