@cybersecdyl: You can see almost every activity a user has taken on their device. But the thing is, most of these artifacts aren’t readable by default because they weren’t meant to be valuable for the end user. These artifacts function as pieces of the windows operating system, but forensic investigators figured out that inside the metadata for the file, the hex holds key information. Parsing this data manually sucks but using open source tools that can parse it makes it fast and easy. Kape parses the artifacts and puts them in a csv or json format for easy analysis or ingestion Event logs, MFT, registry, databases and more are all parseable #cybersecurity #digitalforensics
Jn what type of cybersecurity is this? like Blue teaming SOC Analyst? or Forensic Investor?
2026-06-04 22:19:17
1
jon_ob2 :
Get a pop filter ong
2026-04-18 17:37:02
7
Djinn313 :
Gkape was one of the nicest tools ive found to pull artifacts from e01s
2026-04-26 18:37:55
1
b1tw1$3_ :
thank you for this. what's the job market for DFIR? thank you
2026-04-21 23:27:32
1
name expired, 😂 :
you know, that's the issue with journaling filesystems. using a none journaling filesystem with hw and sw encryption, is probably a better choice for everyone.
2026-04-21 08:30:14
1
exalluffas :
do you use hashcat?
2026-04-21 13:05:01
1
strk_194 :
🔝
2026-05-19 06:48:20
1
To see more videos from user @cybersecdyl, please go to the Tikwm
homepage.