If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: windowsir.blogspot.com - Windows Incident Response.

site address: windowsir.blogspot.com

site title: Windows Incident Response...

Our opinion (on Friday 07 August 2026 5:58:41 UTC):

website (probably) only for adults * website (probably) only for adults ! YELLOW status (not for everyone) - not for everyone
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

2026, monday, january, on, saturday, windows, june, 19, 10, thursday, december, 2025, windowsir, blog, lnk, files, in, incident, response, july, 04, 27, friday, tuesday, march, february, 02, 05, 01, 29, 11, pages, subscribe, to, list, archive, finding, initial, access, cti, rigor, threat, intel, consistency, timelines, links, devices, views, ai, the, anthropic, report, what, your, clipboard, questions, ve, been, asked, defender, support, logs, grab, bag, question, open, source, tools, perspectives, cybersecurity,

Text of the page (most frequently used words):
the (609), and (328), that (248), this (125), for (113), was (97), you (91), with (80), not (77), there (72), what (71), but (66), from (64), data (58), have (57), are (55), share (54), #threat (53), they (53), can (53), some (52), post (51), about (48), one (47), how (47), blog (43), time (42), when (41), been (41), files (40), windows (37), were (36), used (35), more (34), just (34), see (34), all (32), analysis (32), then (32), into (32), something (30), where (28), also (27), their (27), other (27), january (26), may (26), way (26), had (26), lnk (25), information (25), june (24), look (24), actor (24), december (23), march (23), why (23), even (23), which (23), available (23), seen (23), now (23), file (23), clipboard (23), february (22), july (22), october (22), because (22), than (22), use (22), found (22), analysts (22), comments (21), like (21), much (21), has (21), them (21), well (21), don (21), your (21), september (20), know (20), things (20), going (20), point (20), first (20), endpoint (20), devices (20), april (19), november (19), part (19), using (19), email (19), posted (19), out (19), system (19), while (19), work (19), take (19), across (19), would (19), write (19), process (19), august (18), example (18), question (18), tools (17), most (17), over (17), incident (17), based (17), systems (17), actors (17), recently (17), access (16), ago (16), these (16), need (16), analyst (16), attack (16), logs (16), those (16), same (16), shared (16), report (16), 2026 (15), pinterest (15), facebook (15), blogthis (15), carvey (15), response (15), team (15), different (15), get (15), ransomware (15), any (15), tool (15), registry (15), back (14), will (14), during (14), run (14), saw (14), however (14), say (14), means (14), only (14), did (14), server (14), usb (14), finding (13), initial (13), running (13), lot (13), doing (13), able (13), another (13), here (13), does (13), provide (13), doesn (13), linkedin (13), very (13), someone (13), bit (13), such (13), connected (13), figure (13), login (13), find (12), defenders (12), times (12), etc (12), path (12), off (12), often (12), soc (12), could (12), our (12), via (12), regripper (12), published (12), specific (12), really (12), image (12), sources (12), application (11), engagement (11), multiple (11), got (11), engagements (11), cases (11), tooling (11), own (11), intel (10), timelines (10), many (10), years (10), before (10), simply (10), few (10), default (10), being (10), said (10), his (10), sharing (10), looking (10), web (10), attempts (10), rather (10), after (10), little (10), reading (10), successful (10), develop (10), might (10), artifacts (10), goals (10), claude (10), findings (10), metadata (10), source (9), malware (9), who (9), applications (9), installed (9), sure (9), together (9), every (9), sometimes (9), issues (9), worked (9), yes (9), started (9), less (9), nor (9), attacks (9), consulting (9), incidents (9), through (9), new (9), easy (9), timeline (9), support (9), within (9), include (9), log (9), year (8), case (8), technical (8), fact (8), understand (8), along (8), endpoints (8), two (8), event (8), working (8), good (8), infrastructure (8), seeing (8), following (8), regarding (8), various (8), great (8), article (8), down (8), aware (8), effort (8), forensics (8), parsing (8), history (8), key (8), investigation (8), provided (8), understanding (8), forensic (8), 2025 (7), months (7), command (7), posts (7), albeit (7), content (7), remember (7), received (7), detection (7), overall (7), services (7), both (7), having (7), format (7), later (7), against (7), make (7), indications (7), clear (7), answer (7), company (7), anything (7), organizations (7), igor (7), events (7), output (7), better (7), cybersecurity (7), described (7), last (7), interesting (7), previous (7), contents (7), read (7), activity (7), anthropic (7), investigations (7), provides (7), developed (7), consistency (7), failed (7), 2016 (6), 2018 (6), dfir (6), comes (6), alert (6), assumption (6), surface (6), security (6), clearly (6), isn (6), asked (6), specifically (6), drive (6), ran (6), including (6), field (6), without (6), add (6), recent (6), spent (6), let (6), yrs (6), providing (6), around (6), approach (6), limited (6), want (6), plugins (6), mean (6), aspects (6), document (6), deal (6), right (6), end (6), full (6), parse (6), triage (6), entire (6), customer (6), fig (6), thought (6), address (6), malicious (6), side (6), became (6), value (6), step (6), 2008 (5), rigor (5), cti (5), show (5), brett (5), line (5), open (5), list (5), books (5), podcast (5), context (5), organization (5), folks (5), each (5), should (5), goes (5), hard (5), again (5), aperture (5), statement (5), historically (5), best (5), call (5), role (5), copy (5), knowledge (5), others (5), perspective (5), moved (5), persistence (5), nothing (5), think (5), defender (5), level (5), career (5), start (5), vulnerability (5), next (5), link (5), workstation (5), writing (5), plugin (5), already (5), everything (5), online (5), upon (5), since (5), early (5), days (5), help (5), useful (5), memory (5), developing (5), didn (5), long (5), themselves (5), links (5), keep (5), microsoft (5), images (5), real (5), collection (5), still (5), particularly (5), given (5), disabled (5), almost (5), bad (5), whatever (5), needed (5), place (5), parsed (5), faster (5), likely (5), excerpt (5), summary (5), observed (5), aren (5), addresses (5), research (5), digital (5), try (5), affiliates (5), similar (5), written (5), steps (5), archives (5), 2022 (4), training (4), windowsir (4), home (4), basis (4), either (4), thinking (4), points (4), eco (4), environment (4), reduction (4), mssql (4), required (4), entirely (4), admin (4), asking (4), instead (4), thumb (4), complete (4), view (4), jensen (4), difficult (4), actual (4), evidence (4), corporate (4), important (4), global (4), between (4), target (4), starting (4), known (4), leave (4), tend (4), updates (4), created (4), called (4), describing (4), yara (4), topic (4), pretty (4), addition (4), monday (4), comment (4), book (4), experiences (4), true (4), pdfs (4), thoughts (4), exe (4), creating (4), user (4), valley (4), rat (4), grab (4), bag (4), dropping (4), day (4), okay (4), number (4), linux (4), encase (4), logging (4), depending (4), change (4), references (4), questions (4), social (4), media (4), consider (4), device (4), else (4), mention (4), locations (4), associated (4), clipboardhistorythief (4), dump (4), prior (4), settings (4), groups (4), pci (4), notice (4), blue (4), activities (4), state (4), reason (4), wmi (4), problem (4), prompts (4), techniques (4), result (4), left (4), intelligence (4), chain (4), learned (4), appear (4), documentation (4), depth (4), manually (4), raas (4), artifact (4), exploit (4), tag (4), done (4), automate (4), processes (4), members (4), transitioned (4), respond (4), 2006 (3), 2007 (3), 2023 (3), archive (3), names (3), private (3), sector (3), atom (3), pages (3), older (3), podcasts (3), style (3), regular (3), movie (3), cycles (3), impacted (3), generated (3), accurate (3), once (3), local (3), staff (3), consultant (3), ticket (3), text (3), went (3), addressing (3), copied (3), opened (3), three (3), evt (3), zero (3), editor (3), actively (3), makes (3), agree (3), domain (3), regularly (3), personal (3), decade (3), germany (3), concerned (3), theft (3), installations (3), appears (3), second (3), changes (3), high (3), made (3), military (3), began (3), assessments (3), haven (3), talk (3), notes (3), receive (3), came (3), capability (3), product (3), added (3), incorporate (3), keys (3), focus (3), always (3), seems (3), github (3), usually (3), articulate (3), enough (3), particular (3), changed (3), location (3), getting (3), info (3), leads (3), technique (3), reference (3), whole (3), hkcu (3), apparently (3), configuration (3), mentioned (3), actually (3), folder (3), parser (3), wondering (3), lists (3), vary (3), methodology (3), investigating (3), describes (3), searches (3), documented (3), above (3), exfiltrated (3), sync (3), enabled (3), descriptions (3), hit (3), page (3), collecting (3), weren (3), fascinating (3), saturday (3), repository (3), half (3), mechanisms (3), human (3), order (3), possible (3), sift (3), conduct (3), supported (3), logins (3), today (3), incorrect (3), chatgpt (3), hope (3), executive (3), whether (3), autonomously (3), individual (3), targeted (3), legal (3), environments (3), playbooks (3), monitoring (3), updated (3), under (3), note (3), protocols (3), presentations (3), computer (3), model (3), reporting (3), move (3), involved (3), capture (3), ways (3), issue (3), deleted (3), revision (3), led (3), indicators (3), wietze (3), detections (3), structure (3), timing (3), chris (3), week (3), enrichment (3), decoration (3), error (3), results (3), original (3), gaps (3), forget (3), common (3), consistent (3), description (3), internal (3), cross (3), pollination (3), confidence (3), iss (3), name (3), exfil (3), situational (3), awareness (3), comparison (3), timestamps (3), campaigns (3), exploited (3), sql (3), injection (3), theme (2), 2004 (2), 2005 (2), 2009 (2), 2013 (2), 2014 (2), 2020 (2), 2024 (2), evil (2), group (2), netbios (2), philosophy (2), month (2), comparing (2), subscribe (2), fan (2), mostly (2), movies (2), yeah (2), matter (2), gpu (2), receives (2), positive (2), subject (2), policy (2), terminal (2), installation (2), force (2), password (2), defend (2), presence (2), regardless (2), phone (2), direct (2), engage (2), him (2), understood (2), room (2), tried (2), bytes (2), size (2), toolset (2), transfer (2), admins (2), boots (2), ground (2), perhaps (2), civilian (2), knew (2), owner (2), servers (2), advantage (2), trying (2), mind (2), scoping (2), office (2), moving (2), deploy (2), built (2), asset (2), inventory (2), outside (2), closely (2), couldn (2), computationally (2), costly (2), respect (2), neither (2), discussion (2), task (2), protect (2), scale (2), pointing (2), current (2), beyond (2), volume (2), unique (2), challenges (2), sausage (2), making (2), familiar (2), background (2), trained (2), experience (2), war (2), dialing (2), listened (2), easily (2), accessible (2), wanted (2), views (2), stringent (2), focused (2), chatter (2), thursday (2), nuix (2), commercial (2), functionality (2), aug (2), values (2), describe (2), incorporating (2), simple (2), interest (2), especially (2), attention (2), itself (2), come (2), directed (2), beginning (2), ask (2), reg (2), update (2), mattis (2), remains (2), talked (2), thousands (2), ahead (2), campaign (2), coffee (2), saving (2), keeping (2), docs (2), wrote (2), interested (2), shellcode (2), 101 (2), authors (2), speaking (2), further (2), heard (2), account (2), paths (2), console (2), stored (2), stage (2), anyway (2), sort (2), dog (2), linking (2), mentions (2), strings (2), follow (2), disk (2), anywhere (2), live (2), put (2), noise (2), indicate (2), yesterday (2), idea (2), appeared (2), nature (2), generally (2), expanding (2), capabilities (2), alerts (2), publish (2), date (2), ups (2), cheat (2), cyber (2), brian (2), somewhat (2), moment (2), setting (2), auditing (2), item (2), gets (2), automated (2), code (2), paste (2), window (2), tracking (2), works (2), combo (2), hadn (2), opening (2), according (2), site (2), mitre (2), att (2), ish (2), showed (2), coding (2), addendum (2), jan (2), dozen (2), discussed (2), operated (2), manner (2), protocol (2), happens (2), hallucinates (2), record (2), chiara (2), rob (2), instance (2), concern (2), release (2), illustrates (2), finally (2), states (2), operational (2), errors (2), illustrate (2), says (2), set (2), offensive (2), estimated (2), tactical (2), operations (2), away (2), low (2), slow (2), matthew (2), maybe (2), iocs (2), employed (2), earlier (2), physically (2), impossible (2), request (2), rates (2), fields (2), misused (2), software (2), never (2), attempting (2), dealing (2), apply (2), valuable (2), elcomsoft (2), types (2), program (2), execution (2), directory (2), install (2), traditional (2), alternative (2), investigative (2), driverframeworks (2), usermode (2), recorded (2), must (2), includes (2), series (2), similarly (2), definitely (2), cory (2), quite (2), nicole (2), smartphones (2), unfortunately (2), her (2), pca (2), button (2), involves (2), platform (2), arun (2), deployed (2), feb (2), credit (2), card (2), structured (2), followed (2), managing (2), life (2), cycle (2), service (2), determining (2), samas (2), pst (2), screen (2), xstreader (2), docx (2), rsids (2), amcache (2), lines (2), word (2), modified (2), adding (2), stuff (2), engaging (2), thorough (2), machine (2), laid (2), control (2), efficacy (2), insight (2), sniper (2), power (2), huntress (2), sophos (2), included (2), dongles (2), items (2), automation (2), modicum (2), prone (2), lessons (2), lab (2), intake (2), acquired (2), laptops (2), wouldn (2), processing (2), bunch (2), missed (2), prefetch (2), extract (2), thing (2), everyone (2), assess (2), locate (2), kicking (2), took (2), levels (2), responsible (2), consistently (2), truly (2), framework (2), unknown (2), certified (2), visa (2), completing (2), easier (2), guesswork (2), meet (2), longer (2), ibm (2), equipment (2), fte (2), roles (2), stay (2), aggregated (2), logical (2), continue (2), accessed (2), requires (2), aggregate (2), review (2), 4th (2), disparate (2), patterns (2), accumulation (2), aggregation (2), observations (2), wiped (2), populated (2), mandiant (2), cozybear (2), embedded (2), thehackernews (2), reports (2), leading (2), commands (2), enterprise (2), awesome, inc, powered, blogger, 163, 118, 108, 166, 2010, 109, 2011, 2012, 2015, 2017, 2019, 2021, forensicitguy, inside, nsa, equation, ttps, china, lense, inversecos, xworm, static, cyberdefnerd, pivoting, clustering, apt, ure, introducing, huntable, studio, dfirtnt, wordpress, com, law, enforcement, forbidden, shavers, weeks, study, foss, conversational, listen, easter, eggs, marvel, conspiracies, speculation, upcoming, spoil, superhero, require, misinterprets, takes, wrong, action, deems, false, effects, snowball, rails, leaving, worse, position, expansive, dynamic, seem, realize, reality, belies, defending, lacks, map, vision, hence, realizing, coded, credentials, brute, guessing, magnitude, greeted, warmly, ambivalent, quietly, hostile, shrug, contractor, contact, advisor, export, nodded, handed, none, hex, immediately, indeed, exported, renamed, disappointed, bring, bear, happy, enthusiastic, sought, opposite, suspicious, shoulder, standing, mine, rubber, meets, road, coalface, higher, founder, ceo, vast, landscape, gov, cisa, agencies, therefore, effectively, recognized, workstations, critical, controllers, browse, lack, compartmentalization, connect, efforts, succeed, brings, manufacturing, offices, deploying, due, privacy, laws, establishing, stealing, artificiality, ignored, stop, course, possibly, simplest, operating, magical, intuition, mystical, abilities, discern, network, told, disparity, asymmetric, asymmetry, identify, deduct, convinced, internet, return, compromised, shells, challenge, status, speed, presents, game, defense, final, watching, myself, readers, college, communications, non, represents, google, 2000, quarter, century, responding, socs, mssps, currently, mdr, joe, rogan, guest, interview, synopsis, huang, tsyganskiy, video, preferences, big, gratuitous, small, hilarity, sit, ads, shoutz, sponsors, perspectives, extensions, paraben, provider, directly, basically, walking, spoke, inaugural, conference, json, version, industry, inordinate, mastering, freely, shiny, majority, articulation, forth, tease, usual, repo, publicly, anyone, googling, designed, extensible, assistance, turned, hour, choose, route, helps, hive, testing, win11, sustain, warfighters, endeavors, expand, taled, incumbent, sign, chaos, brought, consume, meeting, beer, adult, beverages, seemed, reach, youtube, channels, sponsored, courses, self, paced, blogging, entertaining, adversary, craft, viable, methodologies, ultimately, amounts, familiarity, explorer, valli, nayagam, chokkalingam, interestingly, linked, ntuser, man, deceptiq, dec, 1995, talking, ever, entries, tied, stand, d33f351a4aeea5e608853d1a56661059, downloaded, cloudsek, maintains, silver, fox, rolled, worry, expecting, flaming, poop, dropped, doorstep, rest, assured, explanation, behind, referred, diagnostic, though, kit, give, shot, deadpool, figured, opportunities, pull, popped, related, mplog_parser, mpwpptracing, yyyymmdd, hhmmss, 00000003, fffffffeffffffff, bin, naming, convention, programdata, unlikely, please, contrived, scenarios, ctfs, valid, love, free, expense, become, performing, alone, serving, greeter, church, firewall, examined, begin, xenix, unless, essential, decades, controller, versus, typical, significantly, sets, cheating, leveraging, stores, massive, amount, hoping, ton, urls, slide, explain, enrich, decorate, gathered, carrier, webinar, invited, routes, webinars, keeps, bubble, hint, rarely, tough, draw, bead, invaluable, insider, option, concerning, several, audits, staging, exfiltration, pasted, imagine, expands, guy, enables, dumps, clears, shipping, feed, consisting, exactly, emails, documents, swaths, redacting, inclusion, wow, searched, essentially, replica, whoa, navigate, stackoverflow, navigating, shown, named, app, decided, desktop, logo, examples, t1115, admit, batch, native, stick, rom, far, signs, interacting, infostealers, bitcoin, wallet, hopes, pastes, enabling, transaction, modifies, thomas, roccia, morning, worth, considering, assistants, blindly, sound, mentality, facing, emphatically, guys, front, middleware, wasn, supporting, fair, iteration, doppelpaymer, operators, relied, collections, acquiring, minimal, timely, acquire, hours, breach, megabytes, configured, performs, attribution, hallucination, retrieved, job, failure, simplifications, confusion, gallese, she, mit, lecturer, attempt, riemann, hypothesis, math, hasn, solved, 160, stood, statements, users, prompt, light, unable, examination, lee, sans, fame, announced, integrated, mcp, visibility, usage, terms, hallucinations, freaking, handled, probably, fast, loud, increases, velocity, obvious, addressed, pros, taste, mouth, nitty, gritty, details, staple, genre, becomes, akin, commonly, ooda, loop, smaller, tighter, iterated, humanly, hopefully, fired, closer, chains, nation, execute, independently, espionage, title, table, starts, professional, appropriately, dev, term, slop, adopted, perfect, responder, cleared, conditions, recommendation, foremost, prove, disprove, maintain, implementations, edge, excellent, weber, resources, mar, landesk, suggest, granularity, shellbags, transversal, past, msiinstaller, illustrating, pursue, stated, versions, activation, powershell, activated, quick, garrett, moreau, removed, usbstor, category, eye, investigate, recommended, recommends, nirsoft, usbdeview, covering, expect, tracked, impact, gone, peer, reviewed, paper, timeframe, pursuant, violation, acceptable, policies, csam, production, cameras, cable, traditionally, validate, contains, pointers, precious, whenever, tremendous, identifies, camera, smart, distinction, couple, blogs, posting, articles, player, appx, universal, session, macos, dig, wmp, forward, yelp, aspect, rating, ride, driver, hospitals, affiliate, hits, hospital, brand, damaged, hacker, botherder, 0x80, usss, carder, planet, cybercrime, evolution, breaking, apart, compartmentalizing, monetization, opted, allowing, brokers, iabs, steal, profit, reportedly, assist, stolen, krebs, agreed, released, beercow, handle, larger, ost, personally, lately, extracting, forked, author, ross, plagiarism, thoroughly, shimcache, too, win, demonstrates, nuances, ole, storage, doc, retained, damning, slack, space, blair, 2003, caught, demonstration, save, identifiers, timestamp, correlated, demonstrate, whom, msword, launched, formats, draft, removing, weekly, monthly, fewer, intentional, check, combined, utilizing, purposes, rules, commentator, nice, overview, casual, viewing, properties, generating, identifying, deceptive, short, future, dude, bone, tuesday, virtual, overlays, mft, usn, journal, browser, drawing, armor, ironman, pieces, aligned, picture, powerful, fills, spreadsheet, incredible, spot, discussing, nod, pogue, brewer, micro, lindsey, records, separate, pivot, ripper, eventmap, secureworks, owned, attributed, muddywater, stripped, stamp, spacing, reduced, drafted, parts, sections, walk, create, tln, admitting, friday, boarding, headquarters, least, licenses, products, total, art, sat, walked, selecting, select, minutes, selected, profile, assume, extent, fancy, build, extend, external, intensive, heavy, lifting, efficient, frees, development, baking, learn, drives, sent, technician, care, connecting, extraction, inform, ready, mount, single, press, stone, immutable, baseline, deviate, justification, deviation, collected, boom, repeatable, repeatability, collect, looked, hve, restricting, taking, conducting, automating, virustotal, cpu, form, entry, automatically, manual, additional, ones, oversight, inconsistent, strategic, inefficient, mess, thankfully, cannot, replicated, operationalize, institutional, base, completion, accuracy, spend, chasing, rabbit, holes, quickly, answers, spackle, guesses, tickets, active, reported, message, expected, necessary, methods, bulk_extractor, volatility, returned, pandemic, lockdown, shy, tenure, amazing, director, large, highest, deeper, escalated, practices, dug, established, employing, edr, technology, drastically, reduce, 000, touched, hands, tidbit, researching, remained, marked, guaranteed, mix, benign, arbitrary, driving, mandatory, remove, giving, arose, troubleshoot, importantly, meant, obligations, timeliness, uncover, pertinent, requirements


Text of the page (random words):
d as of this writing has 3 articles up maybe more by the time i finally hit the publish button one involves forensic analysis of windows media player under the appx universal windows platform format and another involves session information on windows and macos take a look and see if you find anything useful there i m going to go back and dig in a bit more on the wmp article i m used the more traditional application and want to see if there s something from arun s research that can be added to my own process going forward elcomsoft has published a couple of interesting blogs recently one on usb connected device forensics and one more recently on file system artifacts under c windows i really like how the usb devices blog addresses and identifies that there are actually different types of devices that use different protocols that can be connected to a computer via usb this very often means that a thumb drive doesn t appear the same way doesn t leave the same artifacts as a digital camera or a smart phone this can be a very important distinction depending upon your analysis goals the windows artifacts article contains more than a few pointers to useful data sources within the file system but there s precious little information regarding how to incorporate them into an overall process for example whenever i see an incident report for a windows 11 endpoint i try to grab the pca files because i have an easy means for incorporating them into my overall analysis process one that has provided tremendous value during analysis posted by h carvey at 6 23 am no comments email this blogthis share to x share to facebook share to pinterest monday february 02 2026 devices something i learned very early on as a df ir consultant was that you re likely never going to run into a perfect environment as an on call responder in fact the best you can hope for is an environment with the default logging for the os and applications and that the logs haven t been cleared even then those two conditions aren t always the case even today in 2026 i regularly see environments where auditing of successful logins has been disabled so they don t appear in the security event log as such it s not only important to keep up with what s available from the default installation of an endpoint and what sources can be used to validate your findings but also note what s available depending upon the applications installed however what s most important are your analysis goals for example it s easy to say i want to see all usb devices connected to the endpoint and not provide a timeframe however to what are these devices pursuant ip theft violation of acceptable use policies what about csam production after all smartphones and digital cameras can be connected to a computer via a usb cable but use different protocols and information about the devices being connected can be found in other locations than those that we traditionally look to as a result of training we may receive when it comes to devices connected to a windows system things have definitely changed over time cory and i published a peer reviewed paper in 2005 covering usb artifacts on windows xp systems since then there s been quite a few changes to windows and as one would expect how devices connected to an endpoint are tracked nicole mentioned some time ago 2014 that different protocols used by different devices in this case smartphones have an impact on investigations unfortunately as time has gone on i ve had a hard time linking back to nicole s published research or even her presentations but one of her presentations can be found here this windowsir blog post describes the fact that some of the windows event log files we might look to in order to investigate usb devices connected to an endpoint have been seen to be disabled and recommended some alternative data sources similarly this nirsoft page for the usbdeview application similarly recommends data sources speaking of the windowsir blog here s a whole series of blog posts about just usb devices now as to why i m writing this blog post in the first place i recently ran across this linkedin post from garrett moreau which i thought was interesting he s right in that information about devices connected to removed from the endpoint is stored in the registry and not just in the usbstor key regripper for example includes multiple plugins within the devices category what s really eye opening is to read through the comments to the post one comment for example states the following quick note for defenders default logging settings don t provide much depth usb events are recorded under the applications and services logs microsoft windows driverframeworks usermode operational path but this log must be activated manually previous versions of windows required activation of these events using powershell while the statement is true this goes back to what i said earlier about traditional training and the need to not only keep playbooks up to date but to also pursue other alternative data sources a data source we re familiar with the microsoft windows driverframeworks usermode event log is now disabled by default and as stated doesn t provide much depth however if understanding the usb devices connected to an endpoint are part of your investigative goals then keeping playbooks updated is key some of the comments go one to suggest other data sources that might be used to add granularity or context to your investigations such as shellbags for directory transversal etc in the past i ve found the application event log and in particular msiinstaller events to be useful in illustrating attempts to install applications from a usb device my recommendation is this first and foremost understand your analysis goals what are you attempting to show to prove or disprove from there maintain playbooks associated with these goals and if you re in a role where you re dealing with different implementations and applications keep documentation on any new findings that apply to specific edge cases as you never know when you will see such things again an excellent example of this is when don weber worked a case where the landesk software monitoring application was installed on an endpoint and found that the application provided valuable information regarding program execution addendum 2 mar just yesterday i became aware of this usb devices article from elcomsoft which addresses different types of usb connected devices and resources for investigating them posted by h carvey at 2 07 pm 2 comments email this blogthis share to x share to facebook share to pinterest monday january 19 2026 views on ai the anthropic report there s been a lot of chatter over the use of ai in various fields and because it s my professional focus i m most interested in how it s used in cybersecurity now that doesn t mean that i m not aware of how it s used or more appropriately misused in other fields as well for example how it s been misused in the legal field has been around for more than 2 years now and just last year we saw the term ai slop be adopted in the software dev cybersecurity field something we also saw in 2025 was the release of the anthropic report regarding how ai was used by threat actors in a cyber espionage campaign the report is 14 pages long with the title page table of contents and a 2 pg executive summary the contents of the report itself starts on pg 6 the tl dr of the report if you need it is that nation state threat actors used claude to target 30 organizations and to execute 80 90 of tactical operations independently at physically impossible request rates that s right they used ai to run up to an estimated 90 of their attack chain autonomously so what does this mean it means that low and slow was out the window and that the attack chains were automated a physically impossible request rates that s it everything was faster reading through the report it becomes clear that tools and techniques employed were akin to those commonly observed in human operated attacks but the ooda loop was much smaller much tighter and iterated through much faster than humanly possible on the defender s side this means that artifacts were generated and hopefully alerts fired much closer together than what would ve been observed earlier in the year in response to the report matthew shared his thoughts in which he shared the following that report fascinating as it was also left some cybersecurity pros with a bad taste in their mouth specifically they wanted anthropic to share some real threat intelligence get into the iocs the specific prompts the real nitty gritty details that defenders can use that are a staple of the threat sharing genre i have to say and i did say in the comments that i m not sure that based on my aperture i agree with matthew for example i m not sure what value the prompts used by the threat actors would have for defenders while it s clear that using ai increases the velocity and volume of attacks there was nothing obvious shared in the anthropic report that says any of the tools or techniques used by the ai was any different from what a human would do only that it was faster anthropic has clearly addressed issues that they ve found as a result of their investigation and the prompts would be of little value to defenders and at this point maybe provide indications for the offensive side of what worked at one point in time with claude okay to level set we re at a place where ai has been used in offensive cybersecurity but let s be clear as to how it s been used rather than freaking out about we don t know what according to anthropic s report their product was used to attack 30 or so organizations with up to estimated 90 of the tactical operations handled autonomously by claude making the overall attacks much faster moving away from the low and slow that some of us are used to seeing what any individual targeted organization likely saw was probably fast and loud and before you go thinking that using ai to autonomously run attacks is all that figure 1 illustrates an excerpt from the report s executive summary fig 1 report excerpt now whether you call these hallucinations or coding errors it does illustrate issues with running with whatever ai says as others have found finally consider this threat actors used anthropic s claude which apparently is known to log prompts in the executive summary of the report it states while we only have visibility into claude usage i ll just leave that right there for you to consider in terms of operational security on the blue side so what does or would use of ai on the blue side during df soc or cti work look like on 15 jan 2026 i saw this linkedin post from rob lee of sans fame that announced the release of protocol sift described as claude code integrated with sift workstation using mcp figure 2 illustrates an excerpt of the linkedin post that describes how this all works together fig 2 linkedin post excerpt are users really going to use find evil as a prompt i hope not but i can also see that rob is likely being a bit light in this instance my concern would be that if you re unable to articulate the goals of your examination then how are you going to get claude to do it for you recently chiara gallese shared this post on linkedin in which she described an mit lecturer who used chatgpt in an attempt to understand the riemann hypothesis a math problem that hasn t been solved in 160 years i think what stood out to me most of all in chiara s post was the following two statements and in the end he did not understand the problem he just understood chatgpt s simplifications of his own confusion if we don t understand that problem how do we know if ai claude chatgpt whatever is doing a better job or just getting us to failure faster something soc and df ir analysts have moved to over the years is triage collections acquiring minimal data from endpoints in order to answer investigation goals in as timely a manner as possible after all why acquire a full image which can take hours when the data you need during a breach investigation is often limited to a few megabytes could you use something like protocol sift to conduct analysis sure but what happens if the ai hallucinates something not supported by the data such as an endpoint being configured to not record successful logins saw just such an endpoint today what happens if the ai hallucinates that source of the login activity and then performs attribution because you asked it to based on that hallucination how would you know that the findings provided are incorrect if you don t understand the goals of the investigation and the data retrieved to support that investigation about half a dozen years ago i was supporting a df ir team that was addressing a fair number of ransomware incidents when microsoft published their first iteration of the human operated ransomware attacks blog post in that blog post where the doppelpaymer ransomware is discussed the authors mention that the ransomware operators may have relied on wmi persistence mechanisms so i asked our team if they d seen any the response was no however while the front end data collection did include the wmi repository the middleware used to parse the data did not include a parser for the wmi repository so the question became how can you say no if the wmi repository wasn t parsed this may sound like a one off but i saw the same mentality years before and i ve seen it since then as well given everything else we re facing in 2026 i m going to state emphatically that using ai on the blue side for no other reason than that the bad guys are using it is not a good reason and that if you can t clearly articulate your analysis goals then ai should not be used at all look at it this way addendum 20 jan recently thomas roccia shared his thoughts on running ai claude coding assistants blindly i saw this just this morning but it appears to have been published 3 days ago it s worth a read when considering the use of ai and especially claude for blue side activities posted by h carvey at 1 28 pm no comments email this blogthis share to x share to facebook share to pinterest saturday january 10 2026 what s on your clipboard one of the fascinating aspects of windows systems from a df ir perspective for me has been the clipboard notice i said one of rather than the that s because there are a lot of fascinating aspects of windows systems when it comes to df ir work i include the clipboard in this mostly because there is various malware infostealers etc that will dump the contents of the clipboard as part of their functionality also there s malware that will place a malicious bitcoin wallet address on the clipboard in hopes that the user simply pastes that address when they re enabling a transaction i mention malware that modifies the clipboard in this 2008 blog post i ll admit that early on in my df ir career this isn t something that i thought about collecting as part of an ir eng...
Thumbnail images (randomly selected): * Images may be subject to copyright.YELLOW status (not for everyone)website (probably) only for adults

Verified site has: 290 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-140 141-145 146-150
151-155 156-160 161-165 166-170 171-175 176-180 181-185 186-190 191-195 196-200
201-205 206-210 211-215 216-220 221-225 226-230 231-235 236-240 241-245 246-250
251-255 256-260 261-265 266-270 271-275 276-280 281-285 286-290


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 200 OK
Content-Type text/html; charset=UTF-8
Expires Fri, 07 Aug 2026 05:58:41 GMT
Date Fri, 07 Aug 2026 05:58:41 GMT
Cache-Control private, max-age=0
Last-Modified Mon, 03 Aug 2026 17:56:45 GMT
ETag W/ 71d9a678d1843a87730e06796d951d5cd1ee5f30dff448cf21170875dd305a2d
Content-Encoding gzip
X-Content-Type-Options nosniff
X-XSS-Protection 1; mode=block
Content-Length 54425
Server GSE
Connection close

Meta Tags

title="Windows Incident Response"
content="width=1100" name="viewport"
content="text/html; charset=UTF-8" http-equiv="Content-Type"
content="blogger" name="generator"
content="htt???/windowsir.blogspot.com/" property="og:url"
content="Windows Incident Response" property="og:title"
content='The Windows Incident Response Blog is dedicated to the myriad information surrounding and inherent to the topics of IR and digital analysis of Windows systems. This blog provides information in support of my books; "Windows Forensic Analysis" (1st thru 4th editions), "Windows Registry Forensics", as well as the book I co-authored with Cory Altheide, "Digital Forensics with Open Source Tools".' property="og:description"
name="google-adsense-platform-account" content="ca-host-pub-1556223355139109"
name="google-adsense-platform-domain" content="blogspot.com"
content="Windows Incident Response" itemprop="name"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgm0xiKw07soWdo_HmqJwXAcpzOdEGqlOq2qGx-ICCGpPHXztAY2VAld8BbAemABtJjP8LnPIx5sccbLc7jbD0-TWrUUl7tmKp_tdXqeYb8tpWPXPeigYGzQLod5ugIT5v_DvAVZjhL1xj4OkuvHR23nGFsjnFmMBx5nZ6PAdja2_rjCZ6IOg/s320/shultz.jpg" itemprop="image_url"
content="9518042" itemprop="blogId"
content="5004956787744397256" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/07/finding-initial-access.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh38F4DEIV6xfuSQ9Pvw3qHkZThjV6Bc3icp19dHwfZIPcFds27ihE5MQJUIK0ZR7ZW_Eq3P7pA7XHK079DjzqUx1t3yyKZHq5Pf-oNodGaooEmjPt7umwHwtmWCtiT-o8COaSn5D0lV6QGLIV7Y6B8uwoWwKUJRvg6BDfagcq1Cl3Z0At-5g/s320/lnk_hn.png" itemprop="image_url"
content="9518042" itemprop="blogId"
content="6614717430894291384" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/07/lnk-files-in-cti.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLbVeYZRiWavR8MOIj-aa2hzkfI1tx1kyUzgU9lbR1fFTK0OQKhlYUMCYDTq-I-rp_XF5HHX8NcKq_UCAd5IbS5Cz9uR3RBm5kOjZX26oBEV3BnuO8IAuV0VgUkqZlPNpPmOSQsnu4fR0YqD79OTYgHUaxvxRWeAeEjDL5mA8mBXED2ypJVw/s320/deadpool.jpg" itemprop="image_url"
content="9518042" itemprop="blogId"
content="3114531069952571006" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/07/rigor-in-threat-intel.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1qDMv1yivk28XrmjvxpTlULjK77T7FOfPPSWVnWb3CZo0LEfrPOE31KpBpH1maP1nmpRlW0JIpOFeG3ggZFImarYhl_PC6rKXqTdUKI4qTBR8JjAT3Xo3-pWCbtfQ7hhqqbEy2FWk8PE3jggE2CW3hQMbhjizRW-9Da2DJp91FgIYdhtaWQ/s320/consistency.jpg" itemprop="image_url"
content="9518042" itemprop="blogId"
content="8927453815434011287" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/06/consistency.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOfksuuRwrgJCYga65tTT2plp5VPrPRllH2yHnV9EiPV25RKs2BUZcv57z2IMWRjkKEMQpCI6-r8iZPI2rRDWRyx6j9LFZR92lQmskul3nkJDENlJRmjBkIIG1D9uNr9TVQeZY4naJGGs-n_DUFpi5w5jafJaYdSmGOGoDDWaMp3TCbW2qTQ/w136-h200/iron_man.jpg" itemprop="image_url"
content="9518042" itemprop="blogId"
content="8397599789600874797" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/06/timelines.html" itemprop="url"
content="9518042" itemprop="blogId"
content="7135022385882028844" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/03/lnk-files.html" itemprop="url"
content="9518042" itemprop="blogId"
content="8343764610145344736" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/03/links.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFZH2qOM-ULwURJnI2mKhldA4nND9ifyRoY-V1s10biJ5bYtPrsfLv4HNXOwG5c5fdlMEsv8kUsowm2CzbBw8X1_1nYXkR_P3NnPt-p88ajRdUs_Ig2rcmgAixxtKPnQi_sLlcPW-yhY4iVQnPJnnCwcvN6U-XpEfz5T4zeeEzl68leRpyBg/w200-h144/usb.jpg" itemprop="image_url"
content="9518042" itemprop="blogId"
content="5916884153999590450" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/02/devices.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjontwlFXb6dqaJpjwA0CdQ4zrxxQWNbfkmii2GaKgQkffuMXJcBqHdnUTeMlc8geklORsOLaXCWukA6j7rHPv6E8X90ozHbnGEkgpahcQ46oZxpeVV_bfo7SbZipzqOd7nCfhw_Dbb2kNtBQzzqPhroj2dsHakwjPPNhtH3hag74NXe_JuGg/w400-h91/claude.png" itemprop="image_url"
content="9518042" itemprop="blogId"
content="3728643323533814989" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/01/views-on-ai-anthropic-report.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3z-sFzsDeBPNx4Ejw3nbHboVtrLRwdZfAK17KYeX18e2rRioL9P-P1ipQboqNBC5wKw8WXchPrJSGoYsXGPqXFjSf-ZBDsbGscaNXlIrS4lEGS8I27MCKlZSyhyphenhyphenVGKYG-Z0T6fE1BTM8zmf_IlYRwwTQgWZniw12PqmujqvVM0mgns_BQMA/w151-h200/clipbd.png" itemprop="image_url"
content="9518042" itemprop="blogId"
content="709604896824530679" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/01/whats-on-your-clipboard.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1fN7L58SG87ZOy6fNPlEL69Nxo3YiZw-CnzGhJCGvktiwRSFohxiiKnaUdixP9CkofgeQ04bUNqhg5ysNdGc3yBrO-sl4cmU8PU5SMb4gL42VKPzJ5S_7IbfbaL5rotaAUq-K5rjwQ4cB1TXtLrdZK6rmfif5Vq3lF_qp5_zCOm7VA2x-5g/w133-h200/iws.png" itemprop="image_url"
content="9518042" itemprop="blogId"
content="6932037433189647956" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/01/questions-ive-been-asked.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzyRwUxPEantdmo-SFGZlgs7qzCYQ3tjcWH3LZ3G89tJa_QGZ31QsAzxXlBNlGE-wOww1iVBOhsO3B_z-y-3bVcGdYLH8hFSb3MHQMURJky_DqrsrnSyaImf_X3YrrZrGGWMmGTh_99GC2oZ4VteVdtSdpfbwaojnD43B9ANxzCytJIZOjkA/s320/deadpool_looking.gif" itemprop="image_url"
content="9518042" itemprop="blogId"
content="3174436426110080058" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/01/windows-defender-support-logs.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8_gaXK07lgQ0mklYLiqoNcRhlP0kTHgaW3JR7bw12V0GQkna6J4PqzFBB_MTyQo3KY7Hn6jKE_71BXmtjpriEW6OX9gmmWkQeoMsFavYfbGd11sUakZv4Mv0WpOUTbUboEL3F4_ETuH8pceehDZpxS4DqvFQRwqkETdx7YACIPs89MgCKoA/w200-h200/bag.jpg" itemprop="image_url"
content="9518042" itemprop="blogId"
content="4277362555799002517" itemprop="postId"
content="htt???/windowsir.blogspot.com/2026/01/grab-bag.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYhcuV312oaHMXkcwKd5K3paosMvd0C2rWOywnjPFDKMQBWCblf4GQb7jXbH3f4wDCGa5zcUVb_ZU9o7BnQaX4hrMF602xg4bhi5lGp9p7_7kEjY9qAGXBGJENTJKSInisp-5SuZVPqvKpSIoxIEGFj2kOcFESPwiD5hYDQBnmR0NXO1kBQQ/w200-h199/question.jpg" itemprop="image_url"
content="9518042" itemprop="blogId"
content="1871815266610597454" itemprop="postId"
content="htt???/windowsir.blogspot.com/2025/12/question-on-open-source-tools.html" itemprop="url"
content="htt????/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1vmz4yL9_Rdf2xcJrKxMLrAS9NgP-b82pHgJNSFTs5fp6VBZtSVpHs13IH2K7-HNA3jSdY5neBMvXsMJOqEt66sFf-mPC7qhQJpASfFuo_Ni-pY2kCLimL_H29aOdPmCRbL5yvOQy_YOvk27R_eMlXy_aeSj7Y7tex9T4igG2g41nB999Kg/w200-h160/podcast.jpeg" itemprop="image_url"
content="9518042" itemprop="blogId"
content="7970379017264002023" itemprop="postId"
content="htt???/windowsir.blogspot.com/2025/12/perspectives-on-cybersecurity.html" itemprop="url"

Load Info

page size54425
load time (s)0.47436
redirect count0
speed download114820
server IP 142.251.39.193
* all occurrences of the string "http://" have been changed to "htt???/"