Skip to content
UPLINK
console portfolio/research
type security-research
ACTIVE

Security Research

digital-forensics · incident-response · red-teaming · lab-building

Articles
9
Categories
3

Article Index9 of 9 articles

Action1 RMM Forensics Artifacts for Windows
Jul 18, 2026Digital Forensics
Action1 RMM Forensics Artifacts for Windows

Forensic walkthrough of the Action1 agent on Windows: install artifacts under C:\Windows\Action1, the A1Agent service, TightVNC-based remote desktop, Run Script and Deploy Software behavior, libtorrent P2P distribution and its firewall tells, and which artifacts survive a remote uninstall.

Digital ForensicsRMMAction1Windows
Read Article
Browser Can Lie to You (Sometimes), Part 2: A Failed Security Check That Still Landed the File
Jul 6, 2026Digital Forensics
Browser Can Lie to You (Sometimes), Part 2: A Failed Security Check That Still Landed the File

Download interrupt reason 12 (Security Check Failed) marks a download as interrupted, but the file has already finished writing to disk. The failure is in the post-download Windows attachment scan, not the transfer, so the complete file remains, often without a Mark-of-the-Web.

Digital ForensicsBrowser ForensicsChromiumWindows
Read Article
Browser Can Lie to You (Sometimes): An Odd Finding About Download Interrupt Reason 41
Jul 6, 2026Digital Forensics
Browser Can Lie to You (Sometimes): An Odd Finding About Download Interrupt Reason 41

Interrupt reason 41 in Chromium download history is documented as browser shutdown, but in Chrome and Edge a Safe Browsing or SmartScreen block records the exact same value. Vanilla Chromium and Brave behave as controls.

Digital ForensicsBrowser ForensicsChromeEdgeWindows
Read Article
Investigating GotoHTTP on Windows: Behavior, Forensic Artifacts & Detection
Apr 15, 2026Digital Forensics
Investigating GotoHTTP on Windows: Behavior, Forensic Artifacts & Detection

Investigation guide for GotoHTTP forensics on Windows, covering binary metadata, SYSTEM-level service persistence, SuperTerminal artifacts, file transfer detection via USN Journal, DNS indicators, and child process anomalies.

Digital ForensicsRMMGotoHTTPWindows
Read Article
Chrome Remote Desktop RMM Investigation (Windows)
Mar 28, 2026Digital Forensics
Chrome Remote Desktop RMM Investigation (Windows)

Investigation guide for Chrome Remote Desktop (CRD) forensics on Windows, covering Remote Support and Remote Access modes, Windows Event Log artifacts (Event IDs 1, 2, 4, 5), process behavior, and file transfer detection.

Digital ForensicsRMMChrome Remote DesktopWindows
Read Article
Deep dive into RustDesk RMM Investigation & Forensics on Windows
Jan 29, 2026Digital Forensics
Deep dive into RustDesk RMM Investigation & Forensics on Windows

Deep dive into RustDesk forensic investigation on Windows, examining installation artifacts, logging behavior, connection analysis, file transfer detection, configuration encryption/decryption, and CLI functionality.

Digital ForensicsRMMRustDeskWindows
Read Article
Deep dive into AnyDesk Investigation & Forensics on Windows
Jan 10, 2026Digital Forensics
Deep dive into AnyDesk Investigation & Forensics on Windows

Comprehensive investigation guide for AnyDesk forensics on Windows, covering normal behavior, CLI usage, connection logging, file transfer artifacts, and unattended access investigation techniques.

Digital ForensicsRMMAnyDeskWindows
Read Article
Using Git Commits as a Persistence Mechanism
Jan 8, 2026Red Teaming
Using Git Commits as a Persistence Mechanism

Exploring how Git version control can be weaponized as a persistence mechanism, hiding malicious payloads in commit history, steganography techniques, multi-file payload splitting, and detection strategies for defenders.

Red TeamingPersistenceGit
Read Article
Design your first Windows Forensics Lab and make it decent!
Dec 17, 2025Lab Making
Design your first Windows Forensics Lab and make it decent!

Step-by-step guide to designing and building a Windows forensics lab environment, covering tool selection, VM configuration, network setup, and essential forensic software for defensive security content creation.

Digital ForensicsLab MakingWindows Forensics
Read Article
SOC · RESEARCH · CHICKEN0248 · ↩ OPERATOR.PROFILE