GITEST
Back to Playbooks
CTF

ctf-forensics-windows

CTF Windows forensics. Event log parsing (evtx), registry analysis, SAM hash extraction, MFT/USN journal analysis, wmiexec.py artifact detection, PowerShell history timeline, RDP event IDs, Windows Defender MPLog, anti-forensics detection.

Slug

ctf-forensics-windows

Category

CTF

Run Playbook

/gitest ctf-forensics-windows