DFIR
Windows Forensics
Trace Execution Files
Lateral Movement Capabilities
Url Zone Identifier
Reading, Writing, and Manipulating Metadata
Decode Infected Payload File