The symbol ∃ means “there exists.”
Extracting Data from the Event Payload from .evtx Event Logs with X-Ways Forensics
Today I learned that quotation marks in the Event Log Events.txt file is not a good thing, and what text qualifiers are.
BitLocker and Connected Storage Devices
BitLocker use and related prefetch files for connected storage devices.
Selectively Hashing Files in X-Ways Forensics
Hashing file(s) with X-Ways Forensics.
Initialize $MFT Records… with WinHex
Using WinHex to initialize $MFT records.
Previous Versions of the X-Ways Forensics/WinHex Manual
Using Wayback Machine to look at previous versions of the X-Ways Forensics/WinHex user manual.
A Transition from Healthcare Compliance to Digital Forensics
Derek writes his first blog post about how he switched careers from healthcare compliance to digital forensics.