Skip to content

Commit a969284

Browse files
authored
Create cheat-sheets.md
1 parent 6e6dd5d commit a969284

File tree

1 file changed

+26
-0
lines changed

1 file changed

+26
-0
lines changed

extras/cheat-sheets.md

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
# DFIR Cheat Sheets
2+
3+
A collection of quick-reference materials for analysts.
4+
5+
## Categories
6+
### 🔹 Windows Forensics
7+
- Event ID cheat sheet
8+
- Registry key artifacts
9+
- Common persistence locations
10+
11+
### 🔹 Linux Forensics
12+
- Log file locations
13+
- Bash history patterns
14+
- Rootkit indicators
15+
16+
### 🔹 Network Forensics
17+
- Common ports & protocols
18+
- PCAP filtering expressions
19+
- TLS fingerprinting
20+
21+
### 🔹 Malware Analysis
22+
- PE file structure
23+
- Sandbox behavior indicators
24+
25+
## Format
26+
Cheat sheets are concise and optimized for fast incident response work.

0 commit comments

Comments
 (0)