Let's Talk About Shimcache - The Most Misunderstood Artifact
Let's Talk About MUICache
Forensic Lunch Test Kitchen 1/3/19 Server 2019 Syscache SRUM Shimcache
Windows Artifact Series || ShimCache
ShimCache Artifact Parser 2 | ArtiFast | Forensafe
Shimcache Forensics
ShimCache and AmCache enterprise-wide hunting - SANS Threat Hunting Summit 2017
Tracking Potentially Malicious Files with Evidence of Execution
Let's Talk About NTFS Index Attributes
Getting Started with Plaso and Log2Timeline - Forensic Timeline Creation
AccessData Forensic Tools 7 4 2
Episode 40: What is best evidence?
Windows SRUM Forensics
EventTranscript.db Deep Dive - New Windows Forensic Artifact!
Windows Forensics Analysis: Memory Acquisition
AmCache Investigation - SANS Digital Forensics & Incident Response Summit 2019
Forensic Lunch Test Kitchen 1/4/19 Server 2019 Amcache
Forensic Lunch 2/1/19 Blanche Lagny Amcache DFIR Review
SANS SIFT - AmCache/RecentFileCache Parsing
eDFP V1 course System & Network Forensics Using Shellbags Explorer
What is <filename>:Zone.Identifier:$DATA?
DFIR in 120 seconds - RunMRU
How to Rebuild a Security Program Gone Wrong… - SANS DFIR Summit 2016
Has EDR Made Host Forensics Artifact Analysis Obsolete? How to Combine them Effectively
Forensic Live Response with PowerShell