> For the complete documentation index, see [llms.txt](https://notes.m4lwhere.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.m4lwhere.org/defensive.md).

# Defensive

- [Defensive Notes](https://notes.m4lwhere.org/defensive/defensive-notes.md): Collection of defensive notes gathered throughout many years of CTFs and personal research
- [Windows Forensics](https://notes.m4lwhere.org/defensive/windows-forensics.md)
- [Program Execution Artifacts](https://notes.m4lwhere.org/defensive/windows-forensics/program-execution-artifacts.md)
- [ASEP Locations](https://notes.m4lwhere.org/defensive/windows-forensics/asep-locations.md)
- [Event Logs](https://notes.m4lwhere.org/defensive/windows-forensics/event-logs.md)
- [Linux Forensics](https://notes.m4lwhere.org/defensive/linux-forensics.md)
- [Network Forensics](https://notes.m4lwhere.org/defensive/network-forensics.md): Packet Capture (PCAP) files capture live network traffic to a file for deep analysis. PCAP files contain all bytes captured and can be used to reconstruct entire TCP, UDP, and other data streams.
- [tshark](https://notes.m4lwhere.org/defensive/network-forensics/tshark.md)
- [Wireshark Filters](https://notes.m4lwhere.org/defensive/network-forensics/wireshark-filters.md)
- [Memory Forensics](https://notes.m4lwhere.org/defensive/memory-forensics.md): Gathering and analyzing memory images
- [Stego](https://notes.m4lwhere.org/defensive/stego.md)
- [Malware Analysis](https://notes.m4lwhere.org/defensive/malware-analysis.md)
- [Volatility](https://notes.m4lwhere.org/defensive/volatility.md)
