<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Forensics on SystemLog</title><link>https://systemlog.icu/tags/forensics/</link><description>Recent content in Forensics on SystemLog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 20 Nov 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://systemlog.icu/tags/forensics/index.xml" rel="self" type="application/rss+xml"/><item><title>Crypto OSINT &amp; Forensics Workflow – Practical Investigation Guide</title><link>https://systemlog.icu/blog/crypto_osint_and_forensic_workflow/</link><pubDate>Thu, 20 Nov 2025 00:00:00 +0000</pubDate><guid>https://systemlog.icu/blog/crypto_osint_and_forensic_workflow/</guid><description>A complete workflow for tracing cryptocurrency transactions, identifying entities, correlating blockchain data with OSINT sources, and preparing defensible forensic reports.</description></item><item><title>Digital Evidence Workflow – Tools &amp; Methods</title><link>https://systemlog.icu/blog/digital_evidence_workflow_extended/</link><pubDate>Thu, 20 Nov 2025 00:00:00 +0000</pubDate><guid>https://systemlog.icu/blog/digital_evidence_workflow_extended/</guid><description>A structured, practical overview of the tools and workflow used for digital evidence collection, triage and analysis in forensic and OSINT investigations.</description></item><item><title>Phishing Page Investigation – Complete OSINT &amp; Forensic Workflow</title><link>https://systemlog.icu/blog/phishing_page_investigation_workflow_tools/</link><pubDate>Thu, 20 Nov 2025 00:00:00 +0000</pubDate><guid>https://systemlog.icu/blog/phishing_page_investigation_workflow_tools/</guid><description>Full methodology for evidence collection, offline analysis, infrastructure mapping, technical recon, OSINT correlation, and reporting during phishing investigations.</description></item><item><title>Windows Remote-Access Incident Triage – Live Collection Script &amp; Workflow</title><link>https://systemlog.icu/blog/windows-remote-access-triage-script/</link><pubDate>Fri, 28 Feb 2025 00:00:00 +0000</pubDate><guid>https://systemlog.icu/blog/windows-remote-access-triage-script/</guid><description>Field-ready triage workflow and PowerShell script for cases where a Windows machine is suspected of remote-access compromise.</description></item><item><title>Forensic Imaging &amp; Analysis of a Laptop Drive – Anonymized Case Study</title><link>https://systemlog.icu/blog/forensics-imaging-case/</link><pubDate>Sat, 15 Feb 2025 00:00:00 +0000</pubDate><guid>https://systemlog.icu/blog/forensics-imaging-case/</guid><description>A fully anonymized walkthrough of creating a forensic disk image with dd, validating integrity, and preparing it for examination using Autopsy and QEMU.</description></item></channel></rss>