
This blog has been running since 2011 and covers digital forensics, incident response, security management and practical risk reduction. This page is the map: the article series and evergreen content most worth your time, grouped by topic.
Windows Internals for DFIR
A series for incident responders who want to understand what Windows is doing under the bonnet, and how attackers abuse it.
- Understanding the Virtual Address Space in Windows – the foundation: how Windows abstracts physical memory.
- Understanding the Virtual Address Descriptor (VAD) – the kernel structure that tracks process memory, and how to inspect it.
- Reflective Code Injection Attacks – An Overview for Incident Responders – how attackers execute code from memory, and how to detect it.
Linux Internals for DFIR
The companion series for Linux systems.
- Virtual Memory Areas (VMAs): The Linux Equivalent of the Windows VAD – how Linux tracks process memory and where to hunt for injected code.
- Linux Memory Management: A High-Level Overview – paging, the page cache, swap and the OOM killer, and why each matters in an investigation.
Compliance and Frameworks
- NIST SP 800-53 Rev 5: What It Is and Why It Pays Off – an introduction to the control framework.
- NIST SP 800-53 self-assessment checklist – a free download to benchmark your controls.
- ISO 27001 compliance checklist – a long-standing favourite for gap analysis.
Free Downloads
We publish free checklists, templates and guides. The full collection is indexed on our resources page, with further material on the main site downloads section.
Work With Us
If the material here is useful, the consultancy behind it can help directly – from emergency incident response to threat hunting and vCISO advisory. See the services summary or get in touch.