
Windows Event Log Forensics: What Each Event ID Actually Means
Windows event log forensics decoded — 4624, 4625, 4672, 4688, 4634, 7045, 1102 and how to read them in an investigation.
Posts

Windows event log forensics decoded — 4624, 4625, 4672, 4688, 4634, 7045, 1102 and how to read them in an investigation.

Chain of custody in digital forensics — what to document, the seven failure modes that get evidence thrown out, and the form fields a court actually requires.

Cisco AI Defense secures the AI lifecycle — discovery, validation, runtime protection, supply chain, and shadow-AI control. A solutions engineer's deep …

Forensic disk imaging compared — dd, FTK Imager, and Autopsy. When to use each, write-blocker requirements, hash verification, and court-admissible output.

Complete Cisco ISE BYOD onboarding guide — dual-SSID flow, internal CA, native supplicant provisioning, MyDevices portal, and lifecycle management.

CVE-2026-0263 and CVE-2026-0264 deliver RCE in PAN-OS VPN and DNS processing. FortiClient EMS CVE-2026-35616 exploited in the wild.

ShinyHunters breach Carnival for 5.9M records. Google unifies Mandiant, Wiz, and Gemini. JINX-0164 deploys macOS backdoors against crypto firms.

Complete Cisco ISE TACACS+ device admin guide — Device Admin persona, shell profiles, command sets, AD integration, and the safe AAA chain pattern.

Read-only Cisco ISE audit tool — 52 ERS / OpenAPI endpoints, 9 findings, 21 recommendations, HTML + PDF report in 30 seconds. Open source on GitHub.

How Cisco ISE Profiling classifies every endpoint automatically — probes, policy hierarchy, Certainty Factor, configuration walkthrough, and the gotchas.