@Forensicator4 Hi, Forensicator,
I watched your DFC 2020 write-up well. However, since DFC 2020 is currently in progress, evaluation is getting difficult with the write-up you posted. If possible, post a write-up after the competition.
Blog time! This one's a write-up of a CTF that had me digging through NTFS artefacts I don't use every day. It was a real challenge and very enjoyable, made all the more interesting by not having most of my usual tools available bit.ly/31khFIy
Why does winprefetchview still parse format version 26? Please update to support Windows 10 (format version 30). PECmd is great, but it's hard to lose the GUI's comfort. github.com/libyal/libscca…