Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
Log → SplunkLog → Sentinel
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy CheckLog → SplunkLog → SentinelAPI Playground

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

← All Tags
TAG

Digital Forensics

6 posts
Windows Event Logsincident-responseLogging Configuration+2

Why Windows Event Logging Is Essential for Incident Response

Understanding the critical role of Windows event logs in DFIR work and why proper logging configuration is no longer optional in modern enterprise environments.

Jun 17, 20263 min read
Memory ForensicsVolatile MemoryDigital Forensics+2

Understanding Memory Forensics Fundamentals

An introduction to memory forensics as an emerging discipline within digital forensics, exploring how investigators recover and analyze volatile memory evidence to uncover critical artifacts.

Jun 21, 20263 min read
Memory ForensicsVolatile DataEvidence Acquisition+2

Memory Acquisition: Capturing Volatile Evidence

Memory acquisition involves preserving volatile RAM contents to non-volatile storage for forensic analysis. Success depends on careful execution to prevent corruption and data loss from background processes or system reboots.

Jun 26, 20263 min read
Windows Event LogsEVTX FormatLog Analysis+2

Understanding the Windows EVTX Format and Event Field Structure

A deep dive into the binary XML format used by modern Windows Event Logging, covering the .evtx file structure, storage locations, remote collection architecture, and the common fields analysts encounter in every Event ID.

Jun 29, 20265 min read
Memory ForensicsVolatility FrameworkWindows Forensics+3

Memory Analysis with the Volatility Framework

An introduction to analyzing memory dumps using the Volatility Memory Forensics Framework, including platform support and compatible dump formats for Windows forensic investigations.

Jul 23, 20262 min read
Memory ForensicsVolatile MemoryArtifact Analysis+2

Why Memory Acquisition Matters in Digital Forensics

Volatile memory captures reveal critical artifacts including active processes, network connections, cached credentials, and hidden malware that are essential for thorough incident response investigations.

Aug 9, 20263 min read