Youssef Moukadem

Cybersecurity Enthusiast | Computer Science Graduate | Cloud Enthusiast | Lifelong Learner

View on GitHub

📝 Case Study: Secret Recipe (DFIR)

🔹 Overview

In this case study, I performed forensics on a Windows workstation to investigate insider activity and uncover sensitive information.
The goal was to reconstruct user behavior, identify suspicious accounts, track network and file activity, and locate sensitive files (e.g., the secret coffee recipe).

Skills demonstrated:


🔍 Key Activities & Highlights

1. Identify Computer Name

Computer Name Computer Name


2. Administrator Account Creation

Administrator Name Administrator Name

3. Administrator RID

Administrator Details


4. User Accounts & Suspicious Account

User Accounts


5. VPN Connections

vpn

6. First VPN Connection Timestamp


7. Shared Folders

Shared Folders Shared Folders


8. Last DHCP IP

DHCP IP


9. Secret Recipe File Access

Secret Recipe File


10. Commands & File Transfer Tool

User Commands


11. UserAssist Program Execution

UserAssist Analysis


✅ Conclusion

Lessons learned:


🔗 Navigation