Blindspot Forensics

About Blindspot Forensics

A practitioner's blog covering NTFS analysis, memory forensics, incident response, and the tooling behind real digital investigations.

Digital forensics is full of blindspots — the artifact you didn't know existed, the timeline gap that breaks your case, the tool that silently gives you the wrong answer. This blog exists to close those gaps.

Every post here is written from hands-on experience: real file system structures, real memory images, real incident response timelines. Not marketing copy, not surface-level overviews — the kind of depth you need when it actually matters.

NTFS & File Systems

MFT attributes, $LogFile, USN Journal, carving techniques, and anti-forensics.

Memory Forensics

Volatility plugins, process injection, malware artifacts, and live response.

Incident Response

Triage workflows, artifact correlation, timeline analysis, and tooling.