Account usage can tell us a lot about a users activity while using a computer. This can include everything from when the user last logged in to when they last changed their password or used a remote access tool. When conducting a forensic or incident response, we look look for a range of evidence related …
Program Execution
User activity will almost always leave behind a trace. As most files require the launching of a ‘program’ to view the contents, it is useful to examine computer systems for artefacts of program execution. This type of artefact is increasingly proving to be useful when responding to cyber attacks, as each cybercriminal group tends to …
File Download
In both incident response and forensic investigations, artifacts related to downloaded files can be a valuable source of evidence. In both cases, we often find key evidence including: The name and size of downloaded filesThe website from which the files were downloadedWhen downloaded files are attachments to an email, the tool used for sending the …
External Device Usage
There are many different types of external storage devices that can be connected to a computer system, but based on our extensive experience of conducting forensic examinations, by far the most common type of device is the common Universal Serial Bus (USB) drive. Coming in many shapes and sizes, you can purchase a USB device …
