MediumHARDEC
As part of an active incident or proactive threat hunting, analyzes NTFS artifacts ($MFT, journal, Prefetch, ShimCache, Amcache) offline or on a triage collection to reconstruct attacker activity and tool usage on a timeline.
28 steps·6 phases