JK Kim (@pr0neer) 's Twitter Profile
JK Kim

@pr0neer

DFIR, cyber warfare, digital profiling,
CEO & Founder PLAINBIT Co., Ltd.
plainbit.co.kr

ID: 110947486

linkhttp://forensic-proof.com calendar_today03-02-2010 09:06:46

2,2K Tweet

1,1K Takipçi

725 Takip Edilen

Eric Zimmerman (@ericrzimmerman) 's Twitter Profile Photo

Registry Explorer v1.5 coming soon! New stuff includes exporting selected bytes from hex viewer to a file, control updates, some fixes here and there, and showing all non-associated deleted values in a hive #DFIR

Registry Explorer v1.5 coming soon! New stuff includes exporting selected bytes from hex viewer to a file, control updates, some fixes here and there, and showing all non-associated deleted values in a hive #DFIR
JK Kim (@pr0neer) 's Twitter Profile Photo

The Superfetch service is no longer visible. This service has been replaced by SysMain. The EnablePrefetcher registry value is no longer meaningful.

JK Kim (@pr0neer) 's Twitter Profile Photo

The boot prefetch is no longer visible in Windows 10. It seems to be the effect of fast startup. Now let's look at bootckcl.etl.

JK Kim (@pr0neer) 's Twitter Profile Photo

Why does winprefetchview still parse format version 26? Please update to support Windows 10 (format version 30). PECmd is great, but it's hard to lose the GUI's comfort. github.com/libyal/libscca…

JK Kim (@pr0neer) 's Twitter Profile Photo

Check the following registry key for the folder id of Windows Timeline. NTUSER.DAT\Software\Microsoft\Office\<version>\Common\Identity\Identities

JK Kim (@pr0neer) 's Twitter Profile Photo

DFC(Digital Forensics Challenge)2021 started. Great experience, valuable time and improvement of my level dfchallenge.org #DFC2021