Anti-Forensic
Destroying or falsifying evidence after the fact — timestomping, event-log clearing, USN journal and prefetch wiping.
Anti-Forensicintermediate
Multi-pass overwriting destroys payload contents to defeat file carving, but metadata, slack, and journal residue often survive to prove a file existed.
windowslinux
Anti-Forensicbeginner
Attackers clear browser history, cache, and cookies to hide payload downloads and C2 visits, but SQLite WAL and disk slack retain the records.
windowslinuxmacos
Anti-Forensicadvanced
Embedding a null byte in a key name via the native API makes a registry entry invisible to regedit while it still runs at boot.
windows
Anti-Forensicbeginner
Attackers delete Prefetch files, Recent items, and Jump Lists to hide which programs ran, but execution evidence survives in many parallel artifacts.
windows
Anti-Forensicintermediate
Intruders delete or truncate /var/log and journald files to hide activity, but sequence numbers, forwarders, and inodes expose the cut.
linux
Anti-Forensicintermediate
Deleting the NTFS change journal erases a record of file activity, but it is recoverable from the MFT, $LogFile, and shadow copies.
windows
Anti-Forensicintermediate
Hiding a payload in a file's named ADS keeps it off a normal directory listing, but the stream is fully indexed in the MFT.
windows
Anti-Forensicadvanced
Attackers delete or forge Amcache and Shimcache entries to erase execution evidence, but the two artifacts and their backups rarely agree.
windows
Anti-Forensicintermediate
Malware rewrites a file's MACB timestamps to defeat timeline analysis, but the forged values rarely survive a full NTFS examination.
windowslinux
Anti-Forensicbeginner
Attackers unset HISTFILE or shred .bash_history to hide commands, but the shell, kernel, and disk all retain copies the wipe never reaches.
linuxmacos
Anti-Forensicbeginner
Attackers wipe Windows event logs to destroy evidence, but the clearing itself is logged and leaves recoverable gaps and residue.
windows
Anti-Forensicbeginner
Wiping shadow copies blocks rollback before ransomware encryption, but the deletion is loud and the snapshots are often recoverable.
windows