<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Seth Enoka – DFIR</title><link>https://sethenoka.com/</link><description>Cybersecurity and Technology</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 20 Jul 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://sethenoka.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns</title><link>https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/</link><pubDate>Mon, 20 Jul 2026 12:00:00 +0000</pubDate><guid>https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/</guid><description>A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.</description></item><item><title>GCFE vs GCFA: What Actually Changes (and When You’re Ready)</title><link>https://sethenoka.com/gcfe-vs-gcfa-what-actually-changes/</link><pubDate>Mon, 13 Jul 2026 20:00:00 +0000</pubDate><guid>https://sethenoka.com/gcfe-vs-gcfa-what-actually-changes/</guid><description>A practical breakdown of what actually changes between GCFE-level and GCFA-level work, including how investigative thinking, scope, and decision-making evolve in real-world DFIR.</description></item><item><title>Shimcache and Amcache Forensics: Execution Evidence Without Certainty</title><link>https://sethenoka.com/shimcache-and-amcache-program-execution-without-certainty/</link><pubDate>Sun, 14 Jun 2026 18:00:00 +0000</pubDate><guid>https://sethenoka.com/shimcache-and-amcache-program-execution-without-certainty/</guid><description>Windows Shimcache and Amcache forensics guide explaining whether these artefacts prove program execution, what they can show, and how to corroborate execution claims.</description></item><item><title>Windows Prefetch Forensics: Execution Evidence and Its Limits</title><link>https://sethenoka.com/prefetch-execution-evidence-and-its-limits/</link><pubDate>Mon, 11 May 2026 10:00:00 +0000</pubDate><guid>https://sethenoka.com/prefetch-execution-evidence-and-its-limits/</guid><description>Windows Prefetch forensics guide explaining whether Prefetch proves execution, what `.pf` files show, and how Digital Forensics and Incident Response (DFIR) analysts should corroborate Prefetch evidence.</description></item><item><title>Recent Files, Jump Lists, and Application-Level Context</title><link>https://sethenoka.com/recent-files-jump-lists-and-application-level-context/</link><pubDate>Mon, 13 Apr 2026 23:00:00 +0000</pubDate><guid>https://sethenoka.com/recent-files-jump-lists-and-application-level-context/</guid><description>This series is deliberately slow. It's trying to build an instinct, not a checklist.
In the first article, we framed Windows artefacts as partial, contextual evidence rather than deterministic indicators. In the ShellBags post, we applied that framing to a common mistake: treating shell navigation as proof of file access or intent. ShellBags are a record of what File Explorer remembers about where a user navigated and how those folders were rendered. That's valuable. It's also easy to over-interpret.</description></item><item><title>From SOC Analyst to Incident Responder: What Actually Changes</title><link>https://sethenoka.com/soc-analyst-to-incident-responder/</link><pubDate>Mon, 06 Apr 2026 20:00:00 +0000</pubDate><guid>https://sethenoka.com/soc-analyst-to-incident-responder/</guid><description>What actually changes when moving from SOC analyst to incident responder? A practical breakdown of skills, mindset, and decision-making in real-world DFIR roles.</description></item><item><title>ShellBags Forensics: Windows User Navigation Evidence</title><link>https://sethenoka.com/shellbags-and-user-navigation-what-windows-remembers-about-exploration/</link><pubDate>Wed, 25 Mar 2026 20:00:00 +0000</pubDate><guid>https://sethenoka.com/shellbags-and-user-navigation-what-windows-remembers-about-exploration/</guid><description>ShellBags forensics guide explaining what Windows ShellBag artefacts record, what they prove about folder navigation, and why they do not prove file access or execution.</description></item><item><title>Windows Recycle Bin Forensics: $I/$R Files and Deleted File Metadata</title><link>https://sethenoka.com/windows-recycle-bin-forensics-on-windows-10-and-11/</link><pubDate>Mon, 16 Feb 2026 22:00:00 +0000</pubDate><guid>https://sethenoka.com/windows-recycle-bin-forensics-on-windows-10-and-11/</guid><description>Windows Recycle Bin forensics guide to $I/$R files, deleted-file metadata, deletion timestamps, and what Recycle Bin artefacts prove on Windows 10 and 11.</description></item><item><title>Understanding Windows Artefacts as Evidence, Not Indicators</title><link>https://sethenoka.com/understanding-windows-artefacts-as-evidence-not-indicators/</link><pubDate>Mon, 19 Jan 2026 23:00:00 +0000</pubDate><guid>https://sethenoka.com/understanding-windows-artefacts-as-evidence-not-indicators/</guid><description>Windows forensic artefacts are one of the core evidence sources used in DFIR investigations, but investigations often fail not because analysts cannot extract artefacts, but because they over-interpret them. This article explains how to treat Windows artefacts as evidence, not indicators, and how to reason about them defensibly.</description></item><item><title>SANS Certification Roadmap for DFIR and SOC Analysts</title><link>https://sethenoka.com/a-roadmap-to-earning-your-first-or-next-sans-certification/</link><pubDate>Sat, 25 Mar 2023 10:50:00 +0000</pubDate><guid>https://sethenoka.com/a-roadmap-to-earning-your-first-or-next-sans-certification/</guid><description>A practical SANS/GIAC certification roadmap for SOC analysts, incident responders, and DFIR practitioners choosing GSEC, GCIH, GCFE, GCFA, GRID, or SANS Work-Study.</description></item><item><title>Unlocking the DFIR Job Market: Strategies for Landing Your Dream Role</title><link>https://sethenoka.com/unlocking-the-dfir-job-market-strategies-for-landing-your-dream-role/</link><pubDate>Sat, 18 Mar 2023 20:54:00 +0000</pubDate><guid>https://sethenoka.com/unlocking-the-dfir-job-market-strategies-for-landing-your-dream-role/</guid><description>It can be difficult when there are so many different roles and job titles and little standardisation. The requirements for a role can differ vastly depending on the hiring manager and the HR team (not to call anyone out, it's a fast moving field and it's hard to keep up). There's no shortage of advice like this; I realise of course that a quick Google search brings up a multitude of similar blogs, but if people are still asking 'where do I start,' at least having written this I have somewhere to point them for a quick rundown of my thoughts.</description></item><item><title>What Is an Alternate Data Stream? NTFS ADS Forensics</title><link>https://sethenoka.com/alternate-data-streams/</link><pubDate>Sat, 18 Mar 2023 03:38:00 +0000</pubDate><guid>https://sethenoka.com/alternate-data-streams/</guid><description>A practical explanation of NTFS Alternate Data Streams (ADS), why they matter in Windows forensics, how to find them with dir /r, and what investigators should and should not infer.</description></item><item><title>Create a Personal Forensics Lab Part 6: The CentOS Workstation</title><link>https://sethenoka.com/create-a-personal-forensics-lab-part-6-the-centos-workstation/</link><pubDate>Fri, 03 May 2019 08:00:00 +0000</pubDate><guid>https://sethenoka.com/create-a-personal-forensics-lab-part-6-the-centos-workstation/</guid><description>This (for now anyway) will be the last post in this series, in which we'll add a CentOS 7 x64 workstation to our lab.</description></item><item><title>Create a Personal Forensics Lab Part 5: The Windows 7 Workstations</title><link>https://sethenoka.com/create-a-personal-forensics-lab-part-5-the-windows-7-workstations/</link><pubDate>Fri, 26 Apr 2019 08:00:00 +0000</pubDate><guid>https://sethenoka.com/create-a-personal-forensics-lab-part-5-the-windows-7-workstations/</guid><description>As the title suggests, it's time to install the Windows 7 workstation(s).</description></item><item><title>Create a Personal Forensics Lab Part 4: The Windows 8.1 Workstation</title><link>https://sethenoka.com/create-a-personal-forensics-lab-part-4-the-windows-8-1-workstation/</link><pubDate>Fri, 19 Apr 2019 08:00:00 +0000</pubDate><guid>https://sethenoka.com/create-a-personal-forensics-lab-part-4-the-windows-8-1-workstation/</guid><description>In this instalment, it's time to add the Windows 8.1 workstation to the environment. The issue with this ISO when compared to all the others is that Windows 8.1 doesn't allow the OS to be installed without a licence key. As a result, some finagling is required (read: an extra step to get the ISO ready before attempting to install the OS).</description></item><item><title>Create a Personal Forensics Lab Part 3: The Windows 10 Workstation</title><link>https://sethenoka.com/create-a-personal-forensics-lab-part-3-the-windows-10-workstation/</link><pubDate>Fri, 12 Apr 2019 08:00:00 +0000</pubDate><guid>https://sethenoka.com/create-a-personal-forensics-lab-part-3-the-windows-10-workstation/</guid><description>If you haven't already, complete parts one and two of this guide on building a personal forensics lab in the cloud, which cover creating the Windows Server 2016 primary domain controller (DC), DHCP and DNS server, and the Windows Server 2012 R2 secondary DC.</description></item><item><title>Create a Personal Forensics Lab Part 2: The Secondary Domain Controller</title><link>https://sethenoka.com/create-a-personal-forensics-lab-part-2-the-secondary-domain-controller/</link><pubDate>Fri, 05 Apr 2019 08:00:00 +0000</pubDate><guid>https://sethenoka.com/create-a-personal-forensics-lab-part-2-the-secondary-domain-controller/</guid><description>If you haven't already completed part one of this series, Creating the Primary Domain Controller, I suggest you visit that page first. If, on the other hand, you have at least the primary DC configured, including DHCP, DNS, and Remote Access (NAT), please continue.</description></item><item><title>Create a Personal Forensics Lab Part 1: The Primary Domain Controller</title><link>https://sethenoka.com/create-a-personal-forensics-lab-part-1-the-primary-domain-controller/</link><pubDate>Fri, 29 Mar 2019 08:00:00 +0000</pubDate><guid>https://sethenoka.com/create-a-personal-forensics-lab-part-1-the-primary-domain-controller/</guid><description>One of the major things I recommend to anyone working in DFIR – as well as network or systems administration – is to build a lab in which to test tools, techniques, theories, or anything else you might encounter in day‑to‑day work or personal research. This post is part one of a guide on building a very simple lab in a cloud environment. Readers earlier in their career will probably see more benefit from this series than those near the end, but the principles apply broadly to the industry.</description></item><item><title>Build Your Own Wireguard VPN Server with Pi-Hole for DNS Level Ad Blocking</title><link>https://sethenoka.com/build-your-own-wireguard-vpn-server-with-pi-hole-for-dns-level-ad-blocking/</link><pubDate>Fri, 22 Mar 2019 08:00:00 +0000</pubDate><guid>https://sethenoka.com/build-your-own-wireguard-vpn-server-with-pi-hole-for-dns-level-ad-blocking/</guid><description>Recently, a friend made me aware of an alternative to OpenVPN named [Wireguard](https://www.wireguard.com). It's designed to be extremely lightweight with a small source code footprint which makes it easily auditable. A whitepaper defining the protocol has been produced and is available [here](https://www.wireguard.com/papers/wireguard.pdf).</description></item><item><title>Build Your Own Forensics Go-Bag</title><link>https://sethenoka.com/build-your-own-forensics-go-bag/</link><pubDate>Tue, 12 Mar 2019 19:30:00 +0000</pubDate><guid>https://sethenoka.com/build-your-own-forensics-go-bag/</guid><description>Everyone has their own take on the components which make up a basic DFIR go-bag for when that inevitable call from a client comes. I always have a small collection of devices and boot USBs with me which I think are useful in most cases, mostly because I’ve found myself in situations where any of these things would have been really helpful to have at hand. For larger incidents, I’d recommend having a larger case with a few more critical pieces of hardware, but we’ll get to that below.</description></item><item><title>Vultr and Virtio Part 2 – Creating Your Custom VM</title><link>https://sethenoka.com/creating-your-custom-vm/</link><pubDate>Tue, 15 May 2018 09:06:00 +0000</pubDate><guid>https://sethenoka.com/creating-your-custom-vm/</guid><description>At this point, you've already created your custom Windows ISO and are now ready to use it to deploy a Windows virtual machine on Vultr.</description></item><item><title>Vultr and Virtio Part 1 – Creating a Custom Windows ISO</title><link>https://sethenoka.com/creating-a-custom-windows-iso/</link><pubDate>Mon, 14 May 2018 10:46:00 +0000</pubDate><guid>https://sethenoka.com/creating-a-custom-windows-iso/</guid><description>In the past, I've had difficulty creating Windows virtual machines with Vultr and other VPS providers that require a custom ISO with the VirtIO drivers. This is a how-to on the process so I can follow it again in the future. Hopefully, others will find this useful as well.
This will be the first in a two-part series and will cover creating and uploading the custom ISO. The following post will cover using that ISO to create a VM.</description></item></channel></rss>