<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Incident Response on SystemLog</title><link>https://systemlog.icu/tags/incident-response/</link><description>Recent content in Incident Response on SystemLog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 28 Feb 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://systemlog.icu/tags/incident-response/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Remote-Access Incident Triage – Live Collection Script &amp; Workflow</title><link>https://systemlog.icu/blog/windows-remote-access-triage-script/</link><pubDate>Fri, 28 Feb 2025 00:00:00 +0000</pubDate><guid>https://systemlog.icu/blog/windows-remote-access-triage-script/</guid><description>Field-ready triage workflow and PowerShell script for cases where a Windows machine is suspected of remote-access compromise.</description></item><item><title>Forensic Imaging &amp; Analysis of a Laptop Drive – Anonymized Case Study</title><link>https://systemlog.icu/blog/forensics-imaging-case/</link><pubDate>Sat, 15 Feb 2025 00:00:00 +0000</pubDate><guid>https://systemlog.icu/blog/forensics-imaging-case/</guid><description>A fully anonymized walkthrough of creating a forensic disk image with dd, validating integrity, and preparing it for examination using Autopsy and QEMU.</description></item></channel></rss>