Skip to content

Forensic Lab: Artifact Deep Dives

The Forensic Lab is the technical core of the Hermes Codex. Here, we dissect the traces left by OS operations, user activities, and threat actors to build undeniable evidence timelines.

Deep dives into Unix-like artifacts for tracking intrusions, persistence, and lateral movement.

Core OS logging mechanisms to trace attacker movement and configuration changes.

Artifacts used to prove that a specific binary executed on a system.

🗂️ Windows: File System & User Activity

Section titled “🗂️ Windows: File System & User Activity”

Artifacts that reconstruct user navigation, intent, and data staging.

⚔️ Windows: Evasion & Lateral Movement

Section titled “⚔️ Windows: Evasion & Lateral Movement”

Tracking how attackers abuse native mechanisms to move and hide in memory.

Forensic triage for proprietary perimeter devices.