Skip to content

aXR1.net

Learning something new every day

Menu
  • Home
  • About

Tag: MotW

DFIR

Alternate Data Streams, DFIR and Mark Of The Web

Enter the Rabbit Hole During an investigation, we came across Microsoft Defender correlating a file to a certain site. We did, however, not find any connections or telemetry that showed …

Recent Posts

  • WinRAR split archives – How much data was exfiltrated
  • Alternate Data Streams, DFIR and Mark Of The Web
  • Disabling legacy authentication in Exchange Online & M365
  • Mutexes (mutants) and incident response

Recent Comments

    Archives

    • February 2024
    • January 2024
    • October 2021
    • October 2020

    Categories

    • DFIR
    • M365
    Copyright © 2026 aXR1.net – OnePress theme by FameThemes