KAPE: Few Use Cases for Incident Responders
Understanding and Managing Thumbnail Cache in Windows: Tools thumbcache_viewer_64
Streamlining USB Device Identification with a Single Script
USB MSC Device Forensics: A Quick Guide for Windows
Optional: If EMDMgmt Key Present (Finding Your USB's Volume Serial Number)
Event Logging for Removable Device Activity
Drive Letter Identification and Volume GUID and User Mapping
Tracking USB Key Temporal Data on Windows Systems
USB Key analysis: Volume Names, GUID
Windows Common Artifacts Paths for Forensics
USB Key Analysis: USBSTOR and USB
Streamlining Incident analysis: An All-in-One PowerShell Script
USB Artifacts: What Gets Left Behind and Where to Find It
USB Devices: What You Need to Know for Quick Investigations
Enterprise-Wide Incident Response: Leveraging Logs and Data for Effective Threat Detection
Effective Incident Response: Containment and Eradication
NirSoft Network Usage View (NUV): Streamlining SRUM Analysis
Examining SRUM with ESEDatabaseView
Unpacking SRUM: The Digital Forensics Goldmine in Windows
SRUM: The Digital Detective in Windows