Forensic Lab: Artifact Deep Dives
The Forensic Lab is the technical core of the Hermes Codex. Here, we dissect the traces left by OS operations, user activities, and threat actors to build undeniable evidence timelines.
π§ Linux Forensics & Incident Response
Section titled βπ§ Linux Forensics & Incident ResponseβDeep dives into Unix-like artifacts for tracking intrusions, persistence, and lateral movement.
πͺ Windows: Event Logs & Telemetry
Section titled βπͺ Windows: Event Logs & TelemetryβCore OS logging mechanisms to trace attacker movement and configuration changes.
πͺ Windows: Execution Artifacts
Section titled βπͺ Windows: Execution ArtifactsβArtifacts used to prove that a specific binary executed on a system.
ποΈ Windows: File System & User Activity
Section titled βποΈ Windows: File System & User ActivityβArtifacts that reconstruct user navigation, intent, and data staging.
βοΈ Windows: Evasion & Lateral Movement
Section titled ββοΈ Windows: Evasion & Lateral MovementβTracking how attackers abuse native mechanisms to move and hide in memory.
π Network & Edge Appliances (Ivanti)
Section titled βπ Network & Edge Appliances (Ivanti)βForensic triage for proprietary perimeter devices.
πΎ Enterprise Backup & Recovery Infrastructure (Veeam)
Section titled βπΎ Enterprise Backup & Recovery Infrastructure (Veeam)βComprehensive architectural breakdown, vulnerability matrix, Linux Hardened Repository (LHR) engineering, and DFIR triage methodology for Veeam Backup & Replication.