dfircheatsheet.github.io

File Format

Windows Event Logs IDs

Analysis Tools

Automation (Sigma & Yara rules)

Manual analysis