DFIR120 – RunMRU 2019-02-27 (2022-05-15) Mat Episode 06 covers the RunMRU artifact that is particularly useful when investigating RubberDucky attacks.
DFIR120 – Prefetch 2019-02-13 (2022-05-15) Mat This episode of DFIR in 120 seconds covers Windows Prefetch.
DFIR120 – Userassist 2019-01-21 (2022-05-15) Mat The UserAssist keys carry some value as they indicate the execution of GUI software.
DFIR120 – Shimcache 2019-01-08 (2022-05-15) Mat A very important artifact that can show you the name of malware that has long been gone.
DFIR120 – The power of Stacking 2018-12-29 (2022-05-15) Mat Stacking is one of the most powerfull hunting techniques. See a short primer below.