forensicate.net

notes from the trenches

UTC

CBS Forensic Toolkit

Parser for the Windows 11 Start Menu's CBS subsystem. Extracts forensic artifacts from the MicrosoftWindows.Client.CBS package: Start Menu search history, cached Bing queries, and application launch counts.

[ read more → ]

Hello, world

Welcome. If you're reading this, I'm online! I'm Andrew Prince, and this is my corner of the internet for writing about digital forensics and incident response. I've been meaning to stand up this blog for a while. Publishing notes privately…

[ read more → ]

Tags: meta