If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: www.hecfblog.com - Hacking Exposed Computer Foren.

site address: hecfblog.com redirected to: www.hecfblog.com

site title: Hacking Exposed Computer Forensics Blog

Our opinion (on Tuesday 25 August 2026 2:47:36 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:
description=A hacking exposed blog about computer and digital forensics and techniques, exposed dfir incident response file systems journaling by David Cowen;
description=A hacking exposed blog about computer and digital forensics and techniques, exposed dfir incident response file systems journaling by David Cowen;
description=A hacking exposed blog about computer and digital forensics and techniques, exposed dfir incident response file systems journaling by David Cowen;

Headings (most frequently used words):

aws, daily, blog, testing, log, latency, test, event, results, coming, up, posts, solution, saturday, series, sunday, funday, 25, createuser, createaccesskey, consolelogin, this, week, trending, forensic, lunch, the, most, recent, articles, 815, missed, day, 814, 20, 813, 19, 812, removing, users, from, groups, 811, modifying, user, permissions, 810, 809, 808, top, right, now, about, follow, us, popular, contact, form, fifth, removeuserfromgroup, fourth, addusertogroup, third, second, first,

Text of the page (most frequently used words):
the (83), and (33), for (30), event (28), aws (28), blog (22), this (20), log (19), iam (19), you (18), test (17), that (16), east (15), daily (14), cloudtrail (14), are (13), user (13), just (13), more (12), post (12), #testing (12), than (11), time (11), minute (11), region (11), but (9), innerhtml (8), read (8), delay (8), events (8), sla (8), after (8), hello (8), reader (8), permissions (8), which (8), your (8), faster (7), consolelogin (7), was (7), when (7), with (7), will (7), from (7), group (7), windows (6), artifacts (6), tomorrow (6), results (6), first (6), logs (6), appear (6), series (6), sunday (6), funday (6), would (6), posts (5), forensic (5), day (5), stay (5), tuned (5), coming (5), not (5), new (5), latency (5), like (5), createaccesskey (5), global (5), yesterday (5), today (5), tests (5), all (5), ogmini (5), back (4), files (4), missed (4), critical (4), delivery (4), within (4), once (4), minutes (4), logged (4), where (4), eng (4), cloud (4), changing (4), account (4), goal (4), sure (4), appeared (4), another (4), speed (4), well (4), createuser (4), action (4), addusertogroup (4), their (4), removeuserfromgroup (4), https (4), github (4), 2025 (4), html (4), browser (4), answer (4), challenge (4), week (4), saturday (4), email (3), forensics (3), computer (3), lunch (3), key (3), again (3), sign (3), seconds (3), stopwatch (3), since (3), specific (3), into (3), chris (3), starting (3), activity (3), service (3), continuing (3), access (3), removing (3), such (3), them (3), keep (3), take (3), password (3), try (3), they (3), system (3), tools (3), solution (3), entry (3), must (3), prize (3), anonymous (3), win (3), posting (3), everyone (3), name (2), 440 (2), notifications (2), database (2), basics (2), dvd (2), basic (2), etw (2), tracing (2), etl (2), understanding (2), lnk (2), popular (2), hacking (2), exposed (2), david (2), cowen (2), about (2), 815 (2), api (2), only (2), also (2), quicker (2), out (2), confirming (2), login (2), url (2), showed (2), knew (2), something (2), off (2), switched (2), realized (2), ran (2), want (2), see (2), expected (2), console (2), didn (2), google (2), recent (2), mean (2), has (2), enough (2), mainly (2), because (2), means (2), created (2), continue (2), creating (2), official (2), triggered (2), our (2), prior (2), question (2), involved (2), common (2), grant (2), show (2), related (2), continues (2), hackbrowserdata (2), fat32 (2), have (2), two (2), timestamps (2), allowed (2), please (2), one (2), wins (2), most (2), mistakes (2), make (2), reading (2), copyright, hecfblog, message, contact, form, follow, digital, research, dfir, programming, wirrten, author, powered, blogger, top, right, now, subscribe, atom, home, older, creation, targeted, logging, monitored, clicking, button, hit, without, any, even, though, provides, search, immediately, found, needed, redo, unknowingly, through, searching, led, confusion, whether, using, history, view, checking, bucket, stored, need, ensure, looking, correct, initial, focused, captures, successfully, signs, web, did, solid, job, documenting, behavior, cover, kicks, digging, delays, those, platforms, then, moving, azure, discussion, asked, across, major, providers, takes, provider, audit, occurred, actual, 808, target, suspicion, had, theory, always, listed, list, regions, between, during, wasn, unlike, there, endpoint, clearly, indicates, land, second, occurs, 809, timing, insights, timer, approximately, slightly, longer, still, timelines, going, often, default, appears, lists, thorough, checked, case, third, examining, 810, next, performance, holds, slower, other, looked, result, consistent, demonstrates, initiating, exactly, later, previous, raised, documents, regardless, call, originates, scenario, adding, way, via, policies, added, fourth, focuses, generated, modify, assigning, additional, 811, modifying, little, can, find, attaching, inline, policy, close, deliver, expectations, should, run, confirm, initiated, started, removed, existing, typically, immediate, change, permission, set, actions, remained, how, long, fifth, welcome, installment, focus, shifts, opposite, revoke, 812, users, groups, webbrowserpassview, lazagne, extraction, winning, becoming, thing, attacker, get, extract, saved, passwords, profile, extractor, detail, what, left, behind, reveal, usage, extra, points, multiple, viewing, macos, webbroweerpassview, come, gone, streak, unbroken, decide, ready, step, weeks, 813, does, store, stamp, dates, records, date, however, many, past, actually, treated, zero, real, adjusted, zones, favorite, ftk, imager, xways, axiom, encase, autopsy, choice, submit, least, correctly, handling, assistance, welcomed, deemed, entirely, written, qualify, order, winner, receive, give, release, entries, dlcowen, gmail, com, state, thoughtful, answers, too, similar, earlier, edit, complete, before, friday, 7pm, cst, gmt, rules, 100, amazon, giftcard, world, living, unless, course, put, courses, old, file, problem, some, utilities, 814, stride, realize, enjoy, life, don, let, minor, derail, making, goals, doing, pushing, myself, learning, researching, sharing, fact, here, makes, much, better, human, else, doesn, won, stop, mistake, happens, happened, traveling, lost, track, acknowledge, know, couple, things, woops, articles, trending, blogs, syscache, python, ctf, amcache, objectid, extended, mapi,


Text of the page (random words):
hacking exposed computer forensics blog extended mapi objectid amcache ctf python syscache daily blogs saturday reading solution saturday forensic lunch sunday funday this week s trending posts solution saturday series sunday funday series forensic lunch the most recent articles woops daily blog 815 i missed a day i innerhtml l hello reader it happens to everyone and yesterday it happened to me i was traveling and lost track of the day and realized i didn t post a blog yesterday i just want to acknowledge it so you know a couple things 1 it s ok to make a mistake 2 just because i missed a day doesn t mean that i won t stop posting just means i missed a day 3 i m human just like everyone else so take your mistakes in stride and realize that everyone will make them enjoy your life and don t let minor mistakes derail you from making your goals i m doing this mainly to keep pushing myself to keep learning researching and sharing the fact that you all are here and reading this with me just makes it that much better read more timestamps daily blog 814 sunday funday 4 20 25 i innerhtml l hello reader it s an eng world and we are just living in it unless of course you take the time to put in an entry this week and win this week we are changing courses to an old file system problem with some utilities the prize 100 amazon giftcard the rules you must post your answer before friday 4 25 25 7pm cst gmt 6 the most complete answer wins you are allowed to edit your answer after posting if two answers are too similar for one to win the one with the earlier posting time wins be specific and be thoughtful anonymous entries are allowed please email them to dlcowen gmail com please state in your email if you would like to be anonymous or not if you win in order for an anonymous winner to receive a prize they must give their name to me but i will not release it in a blog post ai assistance is welcomed but if a post is deemed to be entirely ai written it will not qualify for a prize the challenge fat32 does not store a time stamp for access dates it only records the date however many tools have or have in the past actually treated the zero time entry as a real time entry and adjusted it for time zones test your favorite tools such as ftk imager xways axiom encase autopsy your choice but you must submit at least two and show if they are correctly handling fat32 timestamps read more sunday funday daily blog 813 solution saturday 4 19 25 i innerhtml l hello reader another week has come and gone but chris eng s streak continues unbroken it s up to all of you to decide if you are ready to step up to the challenge tomorrow for this weeks challenge the challenge it s becoming more common that the first thing an attacker will try to do if they get access to a user s system is extract all of the saved browser passwords profile a popular browser password extractor such as webbroweerpassview or hackbrowserdata and detail what artifacts are left behind that would reveal their usage on a windows 11 system extra points if you a try multiple browser password viewing tools b try macos as well as windows the winning answer chris eng ogmini blog https ogmini github io 2025 04 14 david cowen sunday funday browser password extraction html https ogmini github io 2025 04 15 lazagne artifacts html https ogmini github io 2025 04 16 webbrowserpassview artifacts html https ogmini github io 2025 04 18 hackbrowserdata artifacts html read more removeuserfromgroup daily blog 812 testing aws log latency removing users from groups i innerhtml l hello reader welcome back to another installment in the aws cloudtrail speed test series today s focus shifts to the opposite of yesterday s action removeuserfromgroup this event is triggered when you revoke permissions by removing an iam user from a group fifth test aws removeuserfromgroup event for this test i removed a user from an existing iam group which typically results in an immediate change to their permission set as with all iam actions the key question remained how long will it take for cloudtrail to log it and in which region since iam is a global service the event should appear in the us east 1 region just like all prior iam tests we ve run to confirm i initiated the action and started the stopwatch results sure enough the removeuserfromgroup event appeared in us east 1 after just 1 minute and 45 seconds once again cloudtrail continues to deliver iam related logs well within sla expectations faster than aws s 15 minute sla close to their 5 minute goal for critical events coming up in tomorrow s post i ll be testing something a little more involved creating and attaching an inline policy to a user can cloudtrail keep up we ll find out stay tuned read more log delay daily blog 811 testing aws log latency modifying user permissions i innerhtml l hello reader continuing our series on aws cloudtrail speed tests today s test focuses on a new iam related action addusertogroup this event is generated when you modify a user s permissions by assigning them to an iam group which would grant additional permissions fourth test aws addusertogroup event today s scenario involved changing account permissions by adding an iam user to a group this is a common way to grant new permissions via group policies once the user was added to the group the addusertogroup event was expected to show up in cloudtrail just like previous iam tests this raised the question which region would the event appear in since iam is a global service aws documents that such activity will be logged in the us east 1 region regardless of where the api call originates results after initiating the action and starting the stopwatch the addusertogroup event appeared in us east 1 exactly 2 minutes later this result is consistent with our prior iam tests and once again demonstrates that cloudtrail logs iam events well within the official aws sla faster than the 15 minute sla faster than the 5 minute goal for critical events but slower than the other events we ve looked at coming up in tomorrow s post i ll continue testing iam activity next up removing a user from a group stay tuned to see if the performance holds read more log delay daily blog 810 testing aws log latency createuser i innerhtml l hello reader continuing from yesterday s post it s time for another aws cloudtrail speed test today i m examining the createuser event which is triggered when a new iam user is created in an aws account third test aws createuser event going into this test i knew that iam events which are global are logged in us east 1 it s often the default region for global events and appears first in aws region lists to be thorough i also checked us east 2 just in case results after creating the user and starting a timer the createuser event appeared in us east 1 after approximately 2 minutes that s slightly longer than the consolelogin and createaccesskey tests but still well within aws s official timelines the delivery was faster than the 15 minute sla faster than the 5 minute goal coming up in tomorrow s blog post i ll continue this series by testing the log delay for changing account permissions stay tuned for more cloudtrail timing insights read more log delay daily blog 809 testing aws log latency createaccesskey i innerhtml l hello reader continuing from yesterday s post it s time for another aws cloudtrail speed test today we re testing the createaccesskey event which occurs when a new access key id is created for an iam user second test aws createaccesskey event when i first ran this test i wasn t sure which region the log would appear in unlike the console sign in url iam is a global service that means there s no region specific endpoint that clearly indicates where cloudtrail logs will land for iam activity i had a theory that the event would appear in us east 1 mainly because it s always listed first in aws s list of regions just to be sure i switched between us east 1 and us east 2 during testing results sure enough after just 90 seconds the createaccesskey event appeared in us east 1 confirming my suspicion just like with the consolelogin event the delivery was faster than the 15 minute sla quicker than aws s target goal of 5 minutes for critical events coming up in tomorrow s blog post i ll be testing the log delay for changing account permissions stay tuned read more testing daily blog 808 testing aws log latency consolelogin i innerhtml l hello reader in a recent sunday funday discussion i asked about the actual log delay across the major cloud providers by log delay i mean the time it takes for an event to appear in a cloud provider s audit log after it has occurred chris eng did a solid job documenting this behavior for azure but didn t cover aws or google cloud so this post kicks off a new blog series where i ll be digging into the log delays for those platforms starting with aws and then moving on to google cloud first test aws consolelogin event for this initial test i focused on the consolelogin event in aws this is a cloudtrail logged event that captures when a user successfully signs into the aws web console the first time i ran the test i unknowingly logged in through the us east 2 region but was searching for logs in us east 1 since cloudtrail logs are region specific this led to confusion whether you re using the event history view or checking the s3 bucket where logs are stored you need to ensure you re looking in the correct region if you want to see the expected log appear i knew something was off when my stopwatch hit 17 minutes without any sign of the login event even though aws provides a 15 minute sla for log delivery once i switched my search to us east 2 i immediately found the consolelogin event and realized i needed to redo the test results after logging out and back in confirming again that my login url showed us east 2 i monitored cloudtrail for the event the consolelogin event showed up within 90 seconds of clicking the sign in button that s not only faster than the 15 minute sla but also quicker than aws s targeted 5 minute delivery time for critical events coming up in tomorrow s blog post i ll test the log delay for api key creation stay tuned read more older posts home subscribe to posts atom top posts right now daily blog 52 understanding the artifacts lnk files etw event tracing for windows and etl files back to basics cd and dvd basic forensics daily blog 440 windows 10 notifications database daily blog 815 i missed a day powered by blogger about a blog on computer and digital forensic research dfir programming the forensic lunch and more wirrten by hacking exposed computer forensic author david cowen follow us popular posts daily blog 52 understanding the artifacts lnk files etw event tracing for windows and etl files back to basics cd and dvd basic forensics daily blog 440 windows 10 notifications database contact form name email message copyright hecfblog
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)

    No Images


    Verified site has: 32 subpage(s). Do you want to verify them? Verify pages:

    1-5 6-10 11-15 16-20 21-25 26-30 31-32


    Top 50 hastags from of all verified websites.

    Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

    Header

    HTTP/1.1 301 Moved Permanently
    Location htt???/www.hecfblog.com
    Date Tue, 25 Aug 2026 02:47:35 GMT
    Content-Type text/html; charset=UTF-8
    Server ghs
    Content-Length 220
    X-XSS-Protection 0
    X-Frame-Options SAMEORIGIN
    Connection close
    HTTP/1.1 301 Moved Permanently
    Location htt????/www.hecfblog.com/
    Content-Type text/html; charset=UTF-8
    Content-Encoding gzip
    Date Tue, 25 Aug 2026 02:47:35 GMT
    Expires Tue, 25 Aug 2026 02:47:35 GMT
    Cache-Control private, max-age=0
    X-Content-Type-Options nosniff
    X-Frame-Options SAMEORIGIN
    Content-Security-Policy frame-ancestors self
    X-XSS-Protection 1; mode=block
    Content-Length 192
    Server GSE
    Connection close
    HTTP/2 200
    content-type text/html; charset=UTF-8
    expires Tue, 25 Aug 2026 02:47:36 GMT
    date Tue, 25 Aug 2026 02:47:36 GMT
    cache-control private, max-age=0
    last-modified Fri, 31 Jul 2026 10:40:20 GMT
    etag W/ 7402e4b8303681360bd2ee03fb899bb7d93c684d274633795f357d753c4990b0
    x-robots-tag all,noodp
    content-encoding gzip
    x-content-type-options nosniff
    x-xss-protection 1; mode=block
    content-length 46216
    server GSE

    Meta Tags

    title="Hacking Exposed Computer Forensics Blog"
    content="text/html;charset=UTF-8" http-equiv="Content-Type"
    content="IE=edge,chrome=1" http-equiv="X-UA-Compatible"
    content="text/html; charset=UTF-8" http-equiv="Content-Type"
    content="blogger" name="generator"
    content="A hacking exposed blog about computer and digital forensics and techniques, exposed dfir incident response file systems journaling by David Cowen" name="description"
    content="htt????/www.hecfblog.com/" property="og:url"
    content="Hacking Exposed Computer Forensics Blog" property="og:title"
    content="A hacking exposed blog about computer and digital forensics and techniques, exposed dfir incident response file systems journaling by David Cowen" property="og:description"
    content="QzHaIw1wSiO9aDUyKCdT-OC4fr8KFTTa6znAlvgWu8k" name="google-site-verification"
    charset="utf-8"
    content="width=device-width, initial-scale=1, maximum-scale=1" name="viewport"
    content="text/html; charset=UTF-8" http-equiv="Content-Type"
    content="blogger" name="generator"
    content="A hacking exposed blog about computer and digital forensics and techniques, exposed dfir incident response file systems journaling by David Cowen" name="description"
    content="htt????/www.hecfblog.com/" property="og:url"
    content="Hacking Exposed Computer Forensics Blog" property="og:title"
    content="A hacking exposed blog about computer and digital forensics and techniques, exposed dfir incident response file systems journaling by David Cowen" property="og:description"
    content="blogger" name="generator"
    content="Hacking Exposed Computer Forensics Blog" property="og:title"
    content="blog" property="og:type"
    content="A hacking exposed blog about computer and digital forensics and techniques, exposed dfir incident response file systems journaling by David Cowen" name="description"
    content="A hacking exposed blog about computer and digital forensics and techniques, exposed dfir incident response file systems journaling by David Cowen" property="og:description"
    content="htt????/www.hecfblog.com/" property="og:url"
    content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJdwCaOd2L-Dj6ZgAcWK9H_LyIHThJKgnIjLlHzwKOq60f_gGfMdRJFLwiiBzR93ojkhJH4I6x1UGBr3X_2smt-P2VOBrSuI08YlLzDztCqEQ9TIhAhTkB8C-MgKmOMSA1Nw-NB_2A0R4/s1600/Odd-Themes-Logo.png" property="og:image"
    content="300" property="og:image:width"
    content="200" property="og:image:height"
    content="facebook admins" property="fb:admins"
    content="facebook app id" property="fb:app_id"
    content="en_US" property="og:locale"
    content="en_GB" property="og:locale:alternate"
    content="hi_IN" property="og:locale:alternate"
    name="google-adsense-platform-account" content="ca-host-pub-1556223355139109"
    name="google-adsense-platform-domain" content="blogspot.com"

    Load Info

    page size46216
    load time (s)1.174691
    redirect count2
    speed download39366
    server IP 142.251.209.147
    * all occurrences of the string "http://" have been changed to "htt???/"