Youssef Moukadem

Cybersecurity Enthusiast | Computer Science Graduate | Cloud Enthusiast | Lifelong Learner

View on GitHub

πŸ“ Case Study: Unattended (DFIR)

πŸ”Ή Overview

In this case study, I investigated an incident where a workstation was left unattended and unlocked.
A suspicious janitor was observed leaving the office, raising concerns of unauthorized access and data exfiltration.

Skills demonstrated:


πŸ” Key Activities & Highlights

1. TypedPaths Registry Analysis

Findings:


2. Web Downloads (Autopsy)

Findings:


3. File Access – RecentDocs

Findings:


4. Jumplist Analysis

Findings:


5. Data Exfiltration – Pastebin

Findings:


βœ… Conclusion

Lessons learned:


πŸ”— Navigation