JK Kim

2.3K posts

JK Kim

JK Kim

@pr0neer

DFIR, cyber warfare, digital profiling, CEO & Founder PLAINBIT Co., Ltd. https://t.co/7APlFR4HQN

Seongnam-si, Republic of Korea Katılım Şubat 2010
717 Takip Edilen1K Takipçiler
JK Kim
JK Kim@pr0neer·
DFC2022 has started this year as well. Let's go solve the problem! dfchallenge.org
English
0
0
0
0
JK Kim
JK Kim@pr0neer·
DFC(Digital Forensics Challenge)2021 started. Great experience, valuable time and improvement of my level dfchallenge.org #DFC2021
English
0
10
16
0
JK Kim
JK Kim@pr0neer·
@Forensicator4 Hi, Forensicator, I watched your DFC 2020 write-up well. However, since DFC 2020 is currently in progress, evaluation is getting difficult with the write-up you posted. If possible, post a write-up after the competition.
English
0
0
1
0
Forensicator
Forensicator@Forensicator4·
Blog time! This one's a write-up of a CTF that had me digging through NTFS artefacts I don't use every day. It was a real challenge and very enjoyable, made all the more interesting by not having most of my usual tools available bit.ly/31khFIy
English
1
0
1
0
JK Kim
JK Kim@pr0neer·
Check the following registry key for the folder id of Windows Timeline. NTUSER.DAT\Software\Microsoft\Office\<version>\Common\Identity\Identities
English
0
0
2
0
JK Kim
JK Kim@pr0neer·
Why does winprefetchview still parse format version 26? Please update to support Windows 10 (format version 30). PECmd is great, but it's hard to lose the GUI's comfort. github.com/libyal/libscca…
English
1
1
1
0
JK Kim
JK Kim@pr0neer·
The boot prefetch is no longer visible in Windows 10. It seems to be the effect of fast startup. Now let's look at bootckcl.etl.
English
0
0
0
0
JK Kim
JK Kim@pr0neer·
The Superfetch service is no longer visible. This service has been replaced by SysMain. The EnablePrefetcher registry value is no longer meaningful.
English
1
0
3
0