We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 6e6dd5d commit a969284Copy full SHA for a969284
extras/cheat-sheets.md
@@ -0,0 +1,26 @@
1
+# DFIR Cheat Sheets
2
+
3
+A collection of quick-reference materials for analysts.
4
5
+## Categories
6
+### 🔹 Windows Forensics
7
+- Event ID cheat sheet
8
+- Registry key artifacts
9
+- Common persistence locations
10
11
+### 🔹 Linux Forensics
12
+- Log file locations
13
+- Bash history patterns
14
+- Rootkit indicators
15
16
+### 🔹 Network Forensics
17
+- Common ports & protocols
18
+- PCAP filtering expressions
19
+- TLS fingerprinting
20
21
+### 🔹 Malware Analysis
22
+- PE file structure
23
+- Sandbox behavior indicators
24
25
+## Format
26
+Cheat sheets are concise and optimized for fast incident response work.
0 commit comments