Security Research
digital-forensics · incident-response · red-teaming · lab-building
Article Index

Forensic walkthrough of the Action1 agent on Windows: install artifacts under C:\Windows\Action1, the A1Agent service, TightVNC-based remote desktop, Run Script and Deploy Software behavior, libtorrent P2P distribution and its firewall tells, and which artifacts survive a remote uninstall.

Download interrupt reason 12 (Security Check Failed) marks a download as interrupted, but the file has already finished writing to disk. The failure is in the post-download Windows attachment scan, not the transfer, so the complete file remains, often without a Mark-of-the-Web.

Interrupt reason 41 in Chromium download history is documented as browser shutdown, but in Chrome and Edge a Safe Browsing or SmartScreen block records the exact same value. Vanilla Chromium and Brave behave as controls.

Investigation guide for GotoHTTP forensics on Windows, covering binary metadata, SYSTEM-level service persistence, SuperTerminal artifacts, file transfer detection via USN Journal, DNS indicators, and child process anomalies.

Investigation guide for Chrome Remote Desktop (CRD) forensics on Windows, covering Remote Support and Remote Access modes, Windows Event Log artifacts (Event IDs 1, 2, 4, 5), process behavior, and file transfer detection.

Deep dive into RustDesk forensic investigation on Windows, examining installation artifacts, logging behavior, connection analysis, file transfer detection, configuration encryption/decryption, and CLI functionality.

Comprehensive investigation guide for AnyDesk forensics on Windows, covering normal behavior, CLI usage, connection logging, file transfer artifacts, and unattended access investigation techniques.

Exploring how Git version control can be weaponized as a persistence mechanism, hiding malicious payloads in commit history, steganography techniques, multi-file payload splitting, and detection strategies for defenders.

Step-by-step guide to designing and building a Windows forensics lab environment, covering tool selection, VM configuration, network setup, and essential forensic software for defensive security content creation.