13Cubed
Digital Forensics. Hacking. Home Labs.
13Cubed AMA — отвечаем на ваши вопросы!
The Easy Way to Analyze Linux Memory
AI vs. Windows Forensics
Behind the Book: Threat Hunting macOS with Jaron Bradley
Windows Memory Forensics Challenge
New Course! Investigating macOS Endpoints
A New(ish) Way to Detect Process Hollowing
Getting Started with Fuji - The Logical Choice for Mac Imaging
RADAR Contact! An Obscure Evidence of Execution Artifact
Будьте добры, перемотайте назад... USN Journal
Повторное использование записи файла NTFS
13Cubed XINTRA: прохождение лаборатории
Linux Memory Forensics Challenge
Shimcache Execution Is Back - What You Need to Know!
Mounting Linux Disk Images in Windows
New Course! Investigating Linux Devices
The Weird Windows Feature You've Never Heard Of
The Ultimate Guide to Arsenal Image Mounter
Where's the 4624? - Logon Events vs. Account Logons
RDP Authentication vs. Authorization
Investigating Windows Courses
Hyper-V Memory Forensics - MemProcFS to the Rescue!
An Important Change to ShellBags - Windows 11 2023 Update!
VMware Memory Forensics - Don't Miss This Important Detail!
Старые команды MS-DOS для DFIR
Detecting PsExec Usage
A File's Life - File Deletion and Recovery
Two Thumbs Up - Thumbnail Forensics
Interview with Lesley Carhart (hacks4pancakes)
It's About Time - Timestamp Changes in Windows 11