<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>forensicate.net</title><description>A personal DFIR blog by Andrew Prince. Notes, research, and lessons learned from a career spent chasing adversaries.</description><link>https://forensicate.net/</link><language>en</language><item><title>Rapidly Triage Indicators with IOC Recon</title><link>https://forensicate.net/posts/ioc-recon/</link><guid isPermaLink="true">https://forensicate.net/posts/ioc-recon/</guid><description>Triaging indicators usually means the same tedious loop: copy an IP, paste it into VirusTotal, copy it again, paste it into your next source, then do the same for each domain, hash, and URL you&apos;re chasing. IOC Recon collapses that loop into a single right-click.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate><author>Andrew Prince</author></item><item><title>Threat hunting is more than &quot;finding evil&quot;</title><link>https://forensicate.net/posts/more-than-finding-evil/</link><guid isPermaLink="true">https://forensicate.net/posts/more-than-finding-evil/</guid><description>A common misconception about threat hunting is that its purpose is to surface adversaries hiding in your environment. That&apos;s one possible outcome, and in a healthy program, it&apos;s the rarest of the three.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>threat-hunting</category><category>detection-engineering</category><category>soc</category><category>defense</category><author>Andrew Prince</author></item><item><title>CBS Forensic Toolkit</title><link>https://forensicate.net/posts/cbs-forensic-toolkit/</link><guid isPermaLink="true">https://forensicate.net/posts/cbs-forensic-toolkit/</guid><description>Parser for the Windows 11 Start Menu&apos;s CBS subsystem. Extracts forensic artifacts from the MicrosoftWindows.Client.CBS package: Start Menu search history, cached Bing queries, and application launch counts.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><author>Andrew Prince</author></item><item><title>PowerShell Incident Response Cheatsheet</title><link>https://forensicate.net/posts/powershell-incident-response-cheatsheet/</link><guid isPermaLink="true">https://forensicate.net/posts/powershell-incident-response-cheatsheet/</guid><description>Quick-reference PowerShell commands for triage and evidence collection during live-response investigations.</description><pubDate>Thu, 31 Jul 2025 00:00:00 GMT</pubDate><category>powershell</category><category>incident-response</category><category>cheatsheet</category><author>Andrew Prince</author></item><item><title>Windows Event IDs for Incident Response</title><link>https://forensicate.net/posts/windows-event-ids-for-incident-response/</link><guid isPermaLink="true">https://forensicate.net/posts/windows-event-ids-for-incident-response/</guid><description>A working reference of the Windows event IDs of interest during triage, grouped by the investigative question they answer.</description><pubDate>Mon, 17 Mar 2025 00:00:00 GMT</pubDate><category>windows</category><category>event-logs</category><category>incident-response</category><category>cheatsheet</category><author>Andrew Prince</author></item><item><title>Hello, world</title><link>https://forensicate.net/posts/hello-world/</link><guid isPermaLink="true">https://forensicate.net/posts/hello-world/</guid><description>Welcome. If you&apos;re reading this, I&apos;m online! I&apos;m Andrew Prince, and this is my corner of the internet for writing about digital forensics and incident response. I&apos;ve been meaning to stand up this blog for a while. Publishing notes privately…</description><pubDate>Mon, 03 Feb 2025 00:00:00 GMT</pubDate><category>meta</category><author>Andrew Prince</author></item></channel></rss>