Back to Playbooks
CTF
ctf-forensics-windows
CTF Windows forensics. Event log parsing (evtx), registry analysis, SAM hash extraction, MFT/USN journal analysis, wmiexec.py artifact detection, PowerShell history timeline, RDP event IDs, Windows Defender MPLog, anti-forensics detection.
Slug
ctf-forensics-windows
Category
CTF
Run Playbook
/gitest ctf-forensics-windows