◆ DFIR Field Reference
Digital Forensics & Incident Response Notes
A vendor-agnostic reference for live investigations. Every doc follows the same shape — TL;DR → concepts → copy-paste commands → gotchas → see also. Browse the tree, search from the sidebar, or jump in below.
40
Sections
5,603
Notes
2,683
SPL / KQL queries
1,371
CyberChef recipes
Start here
🚨Work an active incident100+ incident scenarios → the exact doc.❓Find by question~350 questions → artifact → doc.🔎Query library2,500+ audited SPL / KQL queries.📖GlossaryDefinitions for unfamiliar terms.
Browse by section
01IR Process13 docs
Incident-response lifecycle — PICERL/NIST, triage, containment, eradication, legal/HR coordination.
02Windows Forensics103 docs
The largest domain — registry, execution, persistence, browsers, credentials, lateral movement, filesystem.
03Linux Forensics26 docs
Filesystem, journald/auditd, persistence, rootkits, SSH, supply-chain and fileless malware triage.
04macOS Forensics90 docs
Unified logs, FSEvents, TCC, KnowledgeC/Biome, plists, keychain, launchd and the plist deep-dive library.
05Memory Forensics22 docs
Acquisition, Volatility workflow, injection, credentials, and personal-artifact recovery from RAM.
06Network Forensics41 docs
PCAP, Zeek, NetFlow, DNS, TLS, C2/beaconing, protocol-specific and cloud/container network analysis.
07Log Analysis15 docs
Log sources, SIEM methodology, timeline building, auth logs, Windows event IDs, web-server logs.
08Cloud Forensics33 docs
AWS/Azure/GCP/M365 investigation, CloudTrail, OAuth abuse, SaaS acquisition — scenario + file indexes.
09Email Forensics17 docs
Headers, BEC, O365 investigation, PST/OST internals, Teams local artifacts.
10Mobile Forensics14 docs
iOS/Android acquisition, backups, app artifacts, version deltas.
11Malware Analysis14 docs
Triage, static/dynamic analysis, deobfuscation, unpacking, IOC extraction.
12Threat Hunting22 docs
Hypothesis-driven hunting, tooling, credential attacks, lateral-movement reconstruction.
13Insider Threat80 docs
Departing-employee, exfil, overemployment, messaging/desktop-app and memory-strings forensics.
14Anti-Forensics12 docs
Timestomping, log clearing, wiping detection and counter-anti-forensics.
15Evidence Handling14 docs
Chain of custody, imaging, hashing, key/credential recovery, triage vs full image.
16Tools Reference44 docs
Per-tool references (see also the root tools/ directory).
17Playbooks38 docs
End-to-end incident playbooks, including the legal/HR playbook library.
18Reporting25 docs
Report structure, evidence-claim grammar, Daubert/FRE 702, and 12 case-type templates.
19Threat Intel12 docs
IOC management, attribution, intel lifecycle.
20Attack Techniques34 docs
ATT&CK-aligned technique deep dives and the attack-to-artifact map.
21Timeline Explorer16 docs
Timeline building and analysis with Eric Zimmerman's Timeline Explorer.
22Splunk2697 docs
2,500+ audited SPL/KQL queries across O365, Zscaler, CrowdStrike, Sentinel/MDE, Okta, AWS and more.
23EnScripts1 docs
EnCase EnScript automation.
24Keyword Lists1 docs
AUP / investigation keyword lists for search and DLP.
25AI Forensics12 docs
Investigating AI-tool usage, LLM artifacts, and the new AI frontier of evidence.
26GuardDuty Playbooks28 docs
AWS GuardDuty finding-type response playbooks (subset of Cloud Forensics).
27Console Forensics21 docs
M365/Purview/admin-console investigation UIs.
28M365 Deep Dives12 docs
Token theft/PRT, UAL depth, and M365-specific investigation.
29Active Directory17 docs
ADCS, delegation, LAPS, DCShadow, NTDS.dit offline analysis — depth beyond Windows Forensics.
30Container Forensics12 docs
Docker host, container escape, Kubernetes RBAC/tokens, runtime investigation.
31Volatility Deep Dives15 docs
Plugin-level memory analysis and worked cases (depth beyond Memory Forensics).
32Messaging Apps13 docs
Signal, Slack, Discord and other desktop-messaging forensic internals.
33Nexthink135 docs
NQL query library for endpoint analytics and DEX telemetry.
34Singulr11 docs
AI-governance platform playbooks — shadow AI, data leakage, prompt injection.
35ExtraHop13 docs
NDR detection catalog and NIST-CSF response playbooks.
36CyberChef Recipes1382 docs
1,300+ paste-ready CyberChef recipes across crypto, encoding, malware, network and more.
37AWS Lambdas1 docs
IR-automation Lambda functions — enrichment, isolation, evidence collection, remediation.
38Wiz Playbooks23 docs
CNAPP finding-type response playbooks for cloud misconfig and attack paths.
39OSINT36 docs
Open-source intelligence tradecraft, sources and attribution pivots.
40Investigative Questions13 docs
~350 questions → artifact → the exact doc. A question-first router into the whole repo.
•Tools432 docs
KAPE targets/modules, per-tool guides, cracking, RTR, Axiom, EnCase — the working tools directory.
•Scripts35 docs
Working DFIR scripts by artifact type — memory, disk, browser, cloud, investigation workflow.
Static site generated by
build-site.py · offline-ready · 5,603 pages.