📜 Artefacts DB

Host Artefacts

ðŸ—ģ Evidence Collection And Preservation

This section is under question. We probably need to sort all between different artefacts. Hard to use currently.

Network Artefacts

ðŸŠĩ Logs

In order to detect and response to the incidents in a short time, there are playbooks which are basically guidelines. Some IR frameworks have these included in order to ease the process.

⛅ïļ Cloud Storage

Windows For OneDrive the most useful artifacts are stored locally. If you get access to the account online - may see the deleted items and their versions.

Remote Connections

This is about … .