August 2026
Management Wants a Word: DPAPI All the Way Into a VeraCrypt Vault
Housekeeping found a guest laptop after an early checkout. Room 214, registered to vera. IT pulled a full KAPE triage before wiping it. The room is Forensics / Hard, and the whole thing is one long c…
Fileless WMI Persistence: Hunting a Hijacked CIM Class (TryHackMe: After Hours
Turned out to be a fileless persistence chain: a legit-looking WMI class carrying a Deflate-compressed .NET loader as a "static property", fired by an EventFilter / CommandLineEventConsumer pair with…
July 2026
DFIR Cheatsheet — Windows Registry & Filesystem Artifacts
Reference card for Windows forensics: where to find evidence of execution, staging and exfiltration. Based on the classic "kill chain" order: Execution → Persistence → Access → Collection → Exfiltration.