Notes in Digitale Forensik

To Subscribe, use this Key


Status Last Update Fields
Removal Requested 11/13/2023 test
Published 01/18/2024 Forensic Soundness
Published 01/18/2024 Order of Volatality
Published 01/18/2024 Unterschied: Image | Logical Copy 
Published 01/18/2024 Host Prodected Area (HPA)
Published 01/18/2024 Device Configuration Overlay (DCO)
Published 01/18/2024 Unterschied: Volume | Partition
Published 01/18/2024 Volume Analysis
Published 01/18/2024 DOS Partitions / Master Boot Record (MBR) scheme
Published 01/18/2024 GUID Partitions (UEFI)
Published 01/18/2024 RAID
Published 01/18/2024 RAID 1
Published 01/18/2024 RAID 0
Published 01/18/2024 RAID 4
Published 01/18/2024 File Name Category
Published 01/18/2024 Metadata Category
Published 01/18/2024 Content Category
Published 01/18/2024 Application Category
Published 01/18/2024 File System Category
Published 01/18/2024 FAT File System
Published 01/18/2024 MAC / MACB Timestamps
Published 01/18/2024 Worauf ist bei der Analyse von Timestamps zu achten?
Published 01/18/2024 Was sind Fileslacks und wie enstehen sie?
Published 01/18/2024 Wie werden Dateien gespeichert, welche die Größe eines Sektors überschreiten?
Published 01/18/2024 Was ist ein Volume Slack
Published 01/18/2024 Was sind typische Sektorengrößen von HDDs?
Published 01/18/2024 Was sind typische page Größen von SSDs?
Published 01/18/2024 Was ist Header-to-Footer Carving?
Published 01/18/2024 Was ist Header-Embedded-Lenght Carving
Published 01/18/2024 Header-Maximum-Size Carving
Published 01/18/2024 Bifragment Gap Carving
Published 02/02/2024 Hash-based Carving
Published 01/18/2024 Probleme bei der Memory Acquisition
Published 01/18/2024 Sliding Window
Published 01/18/2024 Vorgehensweise zur Arbeitsspeichersicherung einer VM
Published 01/18/2024 Arbeitsspeichersicherrung wenn die VM nicht supendet werden kann
Published 01/18/2024 Hibernation
Published 01/18/2024 Live Memory Acquistion
Published 01/18/2024 Nachteile Unstructured Memory Analysis
Published 01/18/2024 Process Memory
Published 01/18/2024 Pagefile
Published 01/18/2024 DNS
Published 01/18/2024 HTTP
Published 01/18/2024 HTTP/2
Published 01/18/2024 TLS protocol
Published 01/18/2024 TLS Ablauf
Published 01/18/2024 Traffic Capture mit Taps
Published 01/18/2024 Mirror Port
Published 01/18/2024 promiscuous vs. monitor mode
Published 01/18/2024 Man-in-the-Middle mit Rogue Access Point
Published 01/18/2024 PCAP
Published 01/18/2024 PCAPNG
Published 01/18/2024 Net Flow
Published 01/18/2024 Berkeley Packet Filter
Published 01/18/2024 DNS Logs
Published 01/18/2024 Forensic Profile DNS
Published 01/18/2024 Forensic Profile: HTTP
Published 01/18/2024 Forensic Profile: IMF (Internet Message Format)
Published 01/18/2024 Forensic Profile: SMB
Published 01/18/2024 Forensic Profile: FTP
Published 01/18/2024 Forensic Profile: VoIP
Published 01/18/2024 Forensic Profile: TLS
Published 01/18/2024 Allgemeine Herangehensweise für trafffic analysis
Published 01/18/2024 Definition: Event
Published 01/18/2024 Definition: event field
Published 01/18/2024 Definition: event record
Published 01/18/2024 Definition: log
Published 01/18/2024 Log Structure, Nesting, Data Format
Published 01/18/2024 Key aspects of network-based log data transmission
Published 01/18/2024 Storage options for log data
Published 01/18/2024 Timestamps
Published 01/18/2024 Categories of Log-manipulation
Published 01/18/2024 syslog
Published 01/18/2024 Syslog - priority
Published 01/18/2024 Syslog anti und anti-anti-forensics
Published 01/18/2024 journald
Published 01/18/2024 Windows Event Log
Published 01/18/2024 anti/anti-anti Windows Event Log
Published 01/18/2024 Challenges arising without centralized logging
Published 01/18/2024 Maturity Levels
Published 01/18/2024 Security Information and Event Management (SIEM) Komponenten
Published 01/18/2024 anti/anti-anti Centralized Logging
Published 01/18/2024 Registry system hives
Published 01/18/2024 Registry user hives
Published 01/18/2024 Prefetch files
Published 02/04/2024 Amcache
Published 01/18/2024 SRUM
Published 01/18/2024 Shimcache
Published 01/18/2024 Trashinfo
Published 01/18/2024 Recent files
Published 01/18/2024 Bash History
Published 01/18/2024 user-specific vs. system-specific
Published 01/18/2024 Welche Arten von Dateien befinden sich im Windows Papierkorb?
Published 01/18/2024 LNK files bzw. WIndows shortcuts
Published 01/18/2024 LNK files: Was bedeutet es, wenn die creation time != modifiaction time
Published 01/18/2024 Shellbags (registry)
Published 01/18/2024 Thumbcache
Published 01/18/2024 Wo findet man Informationen über bescuhte URLs?
Published 01/18/2024 Wo findet man den Browser verlauf?
Published 01/18/2024 Wo findet man downloaded files?
Published 01/18/2024 Firefox logins
Published 01/23/2024 MSF files
Published 01/18/2024 MBOX files
Published 01/18/2024 Calender
Published 01/18/2024 Exif-Daten: Bilddatei
Published 01/18/2024 EXIF PDF-Datei
Published 01/18/2024 SQLite delete
Published 01/18/2024 MACB timelining problems
Published 01/18/2024 Timeline Analysis
Published 01/18/2024 MITRE ATT&CK
Published 01/18/2024 TTP
Published 01/18/2024 Pyramid of Pain
Published 01/18/2024 Detction Maturity Levels
Published 01/18/2024 Traffic Light Protocol
Published 01/22/2024 Memory Aquisition Tool für Linux/Windows
Published 01/24/2024 Welche Informationen enthalten HTTP Header?
Published 01/24/2024 Spoofing
Published 01/24/2024 PCAP and NetFlow
Published 01/25/2024 Whitelisting and Blacklisting
Published 01/25/2024 Triage: Risks and Benefits
Published 01/25/2024 Piecewise Hashing
Published 01/25/2024 Context-triggered Piecewise Hashing
Published 01/28/2024 CLF/ELF anti unt anti-anti
Published 02/02/2024 Attribution
Published 02/03/2024 Memory Acquisition (Methodenwahl)
Published 02/03/2024 Process Memory Acquisition
Published 02/03/2024 Automation Risks and Benefits
Published 02/03/2024 TLSH: SPHF
Status Last Update Fields