<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Windows Forensics Artifacts on Ahmad Massd — DFIR Blog</title><link>https://p0peye-blog.pages.dev/categories/windows-forensics-artifacts/</link><description>Recent content in Windows Forensics Artifacts on Ahmad Massd — DFIR Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>ahmad.massad.ir@gmail.com (Ahmad Massad)</managingEditor><webMaster>ahmad.massad.ir@gmail.com (Ahmad Massad)</webMaster><copyright>© 2026 Ahmad Massad</copyright><lastBuildDate>Sun, 28 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://p0peye-blog.pages.dev/categories/windows-forensics-artifacts/index.xml" rel="self" type="application/rss+xml"/><item><title>Post-Exploitation Visibility Using PowerShell Transcription</title><link>https://p0peye-blog.pages.dev/posts/post-exploitation-visibility-using-powershell-transcription/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><author>ahmad.massad.ir@gmail.com (Ahmad Massad)</author><guid>https://p0peye-blog.pages.dev/posts/post-exploitation-visibility-using-powershell-transcription/</guid><description>&lt;p&gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt=""
 src="https://miro.medium.com/v2/resize:fit:700/1*tgDeJqNBwD_5T-oNUtGKKQ.png"
 &gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;PowerShell remains a primary vector for post-exploitation and lateral movement. Threat actors rely heavily on Living-off-the-Land (LotL) techniques to execute fileless malware, manipulate Active Directory, and exfiltrate data. While investigators often look straight to Event Logs — specifically Script Block Logging (EID 4104) and Module Logging (EID 4103) — PowerShell Transcription offers a distinct, and sometimes superior, forensic advantage.&lt;/p&gt;
&lt;p&gt;This article breaks down the mechanics of PowerShell transcription and why it is a critical artifact for threat hunting and incident response.&lt;/p&gt;</description></item></channel></rss>