<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>forensicate.net</title><description>A personal DFIR blog by Andrew Prince. Notes, research, and lessons learned from a career spent chasing adversaries.</description><link>https://forensicate.net/</link><language>en</language><item><title>CBS Forensic Toolkit</title><link>https://forensicate.net/posts/cbs-forensic-toolkit/</link><guid isPermaLink="true">https://forensicate.net/posts/cbs-forensic-toolkit/</guid><description>Parser for the Windows 11 Start Menu&apos;s CBS subsystem. Extracts forensic artifacts from the MicrosoftWindows.Client.CBS package: Start Menu search history, cached Bing queries, and application launch counts.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><author>Andrew Prince</author></item><item><title>PowerShell Incident Response Cheatsheet</title><link>https://forensicate.net/posts/powershell-incident-response-cheatsheet/</link><guid isPermaLink="true">https://forensicate.net/posts/powershell-incident-response-cheatsheet/</guid><description>Quick-reference PowerShell commands for triage and evidence collection during live-response investigations.</description><pubDate>Thu, 31 Jul 2025 00:00:00 GMT</pubDate><category>powershell</category><category>incident-response</category><category>cheatsheet</category><author>Andrew Prince</author></item><item><title>Windows Event IDs for Incident Response</title><link>https://forensicate.net/posts/windows-event-ids-for-incident-response/</link><guid isPermaLink="true">https://forensicate.net/posts/windows-event-ids-for-incident-response/</guid><description>A working reference of the Windows event IDs of interest during triage, grouped by the investigative question they answer.</description><pubDate>Mon, 17 Mar 2025 00:00:00 GMT</pubDate><category>windows</category><category>event-logs</category><category>incident-response</category><category>cheatsheet</category><author>Andrew Prince</author></item><item><title>Hello, world</title><link>https://forensicate.net/posts/hello-world/</link><guid isPermaLink="true">https://forensicate.net/posts/hello-world/</guid><pubDate>Mon, 03 Feb 2025 00:00:00 GMT</pubDate><category>meta</category><author>Andrew Prince</author></item></channel></rss>