Prefetch Deep Dive
1:04:33
Introduction to Windows Forensics
28:09
Windows MACB Timestamps (NTFS Forensics)
21:51
Let's Talk About Shimcache - The Most Misunderstood Artifact
15:56
The ABCs of WMI - Finding Evil in Plain Sight
48:50
SANS DFIR Webcast - Incident Response Event Log Analysis
39:13
Getting Started with Plaso and Log2Timeline - Forensic Timeline Creation
30:26
A File's Life - File Deletion and Recovery
23:24