Recent Posts

PowerShell Cheat Sheet

1 minute read

Introduction Script blocks i find myself using in powershell all the time

Negative Decimal DWORD to Human Format

15 minute read

Introduction This blog aims to ELI5, how negative numbers are stored in the Windows Registry, or any other DWORD for that matter. Why you may ask? Well, some...

DFIR Playbook - Windows Forensics(WIP APR21)

5 minute read

Introduction note this post is incomplete, Oct 2021, this is quite a large playbook to replicate This post aims to replicate my physical playbook on windows....

Mobile Phone Codes

1 minute read

Introduction This post aims to consolidate a list of useful smartphone codes

DFIR Playbook - Network Forensics

2 minute read

Introduction This post aims to replicate my physical playbook on Networking and includes the following tools

DFIR Playbook - Memory Analysis

6 minute read

Introduction This post aims to replicate my physical playbook on Memory Analysis and includes the following tools