Digital Forensics. Hacking. Home Labs.
15:34
The AI Conversation I've Been Avoiding
13Cubed
Shared 1 week ago
3.7K views
5:22
Mac Imaging Made Easy with Fuji
Shared 1 month ago
2.7K views
6:51
Tracking Program Execution with a Little Known Registry Key
Shared 2 months ago
2.5K views
8:38
The Truth About Windows Explorer Timestamps
2:04
Major Update to 13Cubed Courses: Chaos at Cobalt
3.6K views
16:34
13Cubed AMA - Answering Your Questions!
Shared 4 months ago
1.3K views
5:26
The Easy Way to Analyze Linux Memory
Shared 6 months ago
4.3K views
14:13
Will AI Replace Digital Forensics Experts?
Shared 7 months ago
5.6K views
25:19
Behind the Book: Threat Hunting macOS with Jaron Bradley
Shared 8 months ago
2.1K views
1:55
Windows Memory Forensics Challenge
Shared 9 months ago
3.8K views
1:29
New Course! Investigating macOS Endpoints
Shared 10 months ago
4.5K views
6:17
A New(ish) Way to Detect Process Hollowing
Shared 11 months ago
5.3K views
6:23
RADAR Contact! An Obscure Evidence of Execution Artifact
Shared 1 year ago
15:24
Be Kind, Rewind... The USN Journal
4.8K views
9:11
NTFS FILE Record Reuse
3.4K views
56:48
13Cubed XINTRA Lab Walkthrough
6.5K views
3:27
Linux Memory Forensics Challenge
20:53
Shimcache Execution Is Back - What You Need to Know!
7:20
Mounting Linux Disk Images in Windows
1:27
New Course! Investigating Linux Devices
9:52
The Weird Windows Feature You've Never Heard Of
54K views
28:43
The Ultimate Guide to Arsenal Image Mounter
Shared 2 years ago
5.9K views
6:37
Where's the 4624? - Logon Events vs. Account Logons
7.3K views
11:54
RDP Authentication vs. Authorization
2:52
Investigating Windows Courses
11K views
10:39
Hyper-V Memory Forensics - MemProcFS to the Rescue!
4.2K views
10:13
An Important Change to ShellBags - Windows 11 2023 Update!
5.4K views
8:07
VMware Memory Forensics - Don't Miss This Important Detail!
6.8K views
34:39
Old School MS-DOS Commands for DFIR
23:16
Detecting PsExec Usage
15K views
30:26
A File's Life - File Deletion and Recovery
9.2K views
15:13
Two Thumbs Up - Thumbnail Forensics
Shared 3 years ago
30:36
Interview with Lesley Carhart (hacks4pancakes)
2.6K views
15:56
It's About Time - Timestamp Changes in Windows 11
5.2K views
28:06
EZ Tools Manuals Interview with Andrew Rathbun
3K views
13:00
A New Program Execution Artifact - Windows 11 22H2 Update!
6.6K views
15:47
The Dissect Effect - An Open Source IR Framework
8.4K views
17:13
Let's Talk About MUICache
7.7K views
39:25
Impacket Impediments - Finding Evil in Event Logs
8.8K views
18:30
What's on My DFIR Box?
17:11
MemProcFS - This Changes Everything
25K views
11:45
Anatomy of an NTFS FILE Record - Windows File System Forensics
23K views
12:52
The Case of the Disappearing Scheduled Task
7.4K views
9:51
Windows Hibernation Files - A Look Back in Time
Shared 4 years ago
6.1K views
10:52
Let's Talk About NTFS Index Attributes
8.1K views
10:16
Puzzling RDP Cache - Putting the Pieces Together
6.4K views
8:41
Detecting NTDS.DIT Theft - ESENT Event Logs
7.1K views
45:36
EventTranscript.db Deep Dive - New Windows Forensic Artifact!
18:48
Event Log Chainsaw Massacre - Powerful Threat Detection
21K views
16:59
User Access Logging (UAL) Forensics
9.5K views
11:35
RDP Hashes - Event ID 1029 Explained
6.9K views
21:51
Let's Talk About Shimcache - The Most Misunderstood Artifact
16K views
22:02
Introduction to MFTECmd - NTFS MFT and Journal Forensics
9:53
Dumping Processes with Volatility 3
Shared 5 years ago
17K views
The ABCs of WMI - Finding Evil in Plain Sight
11:20
Profiling Network Activity with Volatility 3 - GeoIP from Memory
16:02
Hashcat for Forensics - How Did They Get In?
8.6K views
20:08
Plaso and WSL 2 - The WSL Adventures Continue...
6.2K views
16:56
Volatility 3 and WSL 2 - Linux DFIR Tools in Windows?
8.3K views
39:13
Getting Started with Plaso and Log2Timeline - Forensic Timeline Creation
37K views