Welcome, Analyst
DFIR Lab is an independent research platform for digital forensics, incident response, and threat intelligence — built by practitioners, for practitioners. Here's what you'll find.
Security Research & Threat Intelligence
In-depth analysis of threats, hands-on lab testing, detection engineering, and security tooling — by a practitioner, for practitioners.
Subscribe to receive curated threat intelligence briefings — CVEs, malware trends, and MITRE ATT&CK insights delivered straight to your inbox.
A deep dive into the binary XML format used by modern Windows Event Logging, covering the .evtx file structure, storage locations, remote collection architecture, and the common fields analysts encounter in every Event ID.
Memory acquisition involves preserving volatile RAM contents to non-volatile storage for forensic analysis. Success depends on careful execution to prevent corruption and data loss from background processes or system reboots.
An introduction to memory forensics as an emerging discipline within digital forensics, exploring how investigators recover and analyze volatile memory evidence to uncover critical artifacts.
Understanding the critical role of Windows event logs in DFIR work and why proper logging configuration is no longer optional in modern enterprise environments.
Free tier · No credit card required