VQL Survival Guide

Velociraptor Query Language (VQL) survival guide for digital forensics, incident response (DFIR), and threat hunting. Mastering syntax, performance optimization, and log parsing.

Read More

Thread Injection - Windows Process Injection Technique

Learn about thread hijacking techniques in Windows process injection, a post-exploitation technique for evasion, privilege escalation, and persistence.

Read More

Evidence of Execution - Windows

Learn about Windows execution artifacts including Prefetch, Shim Cache, AM Cache, PCA, MUI Cache, User Assist, and SRUM for digital forensics.

Read More