<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Forensics &#8211; Cerbero Blog</title>
	<atom:link href="https://blog.cerbero.io/tag/forensics/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.cerbero.io</link>
	<description></description>
	<lastBuildDate>Tue, 31 Mar 2026 09:48:48 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://blog.cerbero.io/wp-content/uploads/2023/09/cropped-pro_icon_512-32x32.png</url>
	<title>Forensics &#8211; Cerbero Blog</title>
	<link>https://blog.cerbero.io</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">184292133</site>	<item>
		<title>EVTX Format Package</title>
		<link>https://blog.cerbero.io/evtx-format-package/</link>
					<comments>https://blog.cerbero.io/evtx-format-package/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Tue, 31 Mar 2026 09:48:48 +0000</pubDate>
				<category><![CDATA[Package]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Log]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=3353</guid>

					<description><![CDATA[We are happy to announce support for the Windows Event Log (EVTX) format. The new EVTX Format package lets you inspect EVTX files directly within the application, with a familiar table-based event viewer and full XML detail pane. EVTX is the binary log format used by modern versions of Windows (Vista and later) to store &#8230; <a href="https://blog.cerbero.io/evtx-format-package/" class="more-link">Continue reading<span class="screen-reader-text"> "EVTX Format Package"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/evtx-format-package/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3353</post-id>	</item>
		<item>
		<title>Prototype Memory &#038; Services</title>
		<link>https://blog.cerbero.io/prototype-memory-services/</link>
					<comments>https://blog.cerbero.io/prototype-memory-services/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Mon, 05 May 2025 10:21:29 +0000</pubDate>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Package]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Dump]]></category>
		<category><![CDATA[Memory]]></category>
		<category><![CDATA[Snapshot]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=3139</guid>

					<description><![CDATA[We are excited to announce the release of version 0.3 of our Memory Analysis package, currently in beta. This update introduces two major features: support for prototype Page Table Entries (PTEs) and the ability to enumerate and display Windows services from memory captures. Prototype PTEs are a crucial aspect of Windows memory management. These entries &#8230; <a href="https://blog.cerbero.io/prototype-memory-services/" class="more-link">Continue reading<span class="screen-reader-text"> "Prototype Memory &#038; Services"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/prototype-memory-services/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3139</post-id>	</item>
		<item>
		<title>Memory Decompression &#038; Pagefiles</title>
		<link>https://blog.cerbero.io/memory-decompression-pagefiles/</link>
					<comments>https://blog.cerbero.io/memory-decompression-pagefiles/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Mon, 28 Apr 2025 15:04:47 +0000</pubDate>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Package]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Dump]]></category>
		<category><![CDATA[Memory]]></category>
		<category><![CDATA[Snapshot]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=3132</guid>

					<description><![CDATA[Windows 10 (version 1507) introduced memory compression, a feature that allows certain memory pages to be compressed and managed by the &#8220;MemCompression&#8221; process. As a result, in a memory snapshot, some pages may be unavailable because they reside in compressed memory. Memory compression in Windows is optional and can be disabled if desired, but it &#8230; <a href="https://blog.cerbero.io/memory-decompression-pagefiles/" class="more-link">Continue reading<span class="screen-reader-text"> "Memory Decompression &#038; Pagefiles"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/memory-decompression-pagefiles/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3132</post-id>	</item>
		<item>
		<title>Windows Crash Dump Format 2.1 Package</title>
		<link>https://blog.cerbero.io/windows-crash-dump-format-2-1-package/</link>
					<comments>https://blog.cerbero.io/windows-crash-dump-format-2-1-package/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Wed, 02 Apr 2025 08:50:35 +0000</pubDate>
				<category><![CDATA[Package]]></category>
		<category><![CDATA[Crash Dump]]></category>
		<category><![CDATA[Debug]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Memory]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=3122</guid>

					<description><![CDATA[We&#8217;ve updated the Windows Crash Dump Format package to support inspecting kernel memory dumps through the Memory Analysis package.]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/windows-crash-dump-format-2-1-package/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3122</post-id>	</item>
		<item>
		<title>Memory Analysis Package</title>
		<link>https://blog.cerbero.io/memory-analysis-package/</link>
					<comments>https://blog.cerbero.io/memory-analysis-package/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Tue, 25 Mar 2025 08:46:58 +0000</pubDate>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Package]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Dump]]></category>
		<category><![CDATA[Memory]]></category>
		<category><![CDATA[Snapshot]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=3108</guid>

					<description><![CDATA[We&#8217;re excited to announce the release of the new Memory Analysis package, capable of analyzing memory dumps from all Windows versions, from XP to 11, both x86 and x64. The package will be available to all licenses of Cerbero Suite. Today we&#8217;re rolling out the beta for all commercial licenses, and it will be accessible &#8230; <a href="https://blog.cerbero.io/memory-analysis-package/" class="more-link">Continue reading<span class="screen-reader-text"> "Memory Analysis Package"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/memory-analysis-package/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3108</post-id>	</item>
		<item>
		<title>FLIR Format Package</title>
		<link>https://blog.cerbero.io/flir-format-package/</link>
					<comments>https://blog.cerbero.io/flir-format-package/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Fri, 22 Mar 2024 14:30:42 +0000</pubDate>
				<category><![CDATA[Package]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Image]]></category>
		<category><![CDATA[InfraRed]]></category>
		<category><![CDATA[JPEG]]></category>
		<category><![CDATA[Media]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=2943</guid>

					<description><![CDATA[We released the FLIR Format package for all licenses of Cerbero Suite. FLIR (Forward-Looking InfraRed) refers to thermal imaging data that is embedded within the JPEG file format. Unlike standard visual imagery, FLIR data represents heat emissions from objects, providing a thermal spectrum view that is invaluable for various applications, from surveillance and security to &#8230; <a href="https://blog.cerbero.io/flir-format-package/" class="more-link">Continue reading<span class="screen-reader-text"> "FLIR Format Package"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/flir-format-package/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2943</post-id>	</item>
		<item>
		<title>RegHive Format Package</title>
		<link>https://blog.cerbero.io/reghive-format-package/</link>
					<comments>https://blog.cerbero.io/reghive-format-package/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Fri, 17 Nov 2023 07:53:26 +0000</pubDate>
				<category><![CDATA[Package]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Registry]]></category>
		<category><![CDATA[We have released the DSStore Format package for all licenses of Cerbero Suite.]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=2863</guid>

					<description><![CDATA[We have released the RegHive Format package for all licenses of Cerbero Suite. This package offers enhanced functionality for exploring Windows Registry hives. It enables detailed inspection of keys and values, and importantly, provides additional insights by displaying the last modification date and time for each key. Moreover, it includes the ability to view security &#8230; <a href="https://blog.cerbero.io/reghive-format-package/" class="more-link">Continue reading<span class="screen-reader-text"> "RegHive Format Package"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/reghive-format-package/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2863</post-id>	</item>
		<item>
		<title>DSStore Format Package</title>
		<link>https://blog.cerbero.io/dsstore-format-package/</link>
					<comments>https://blog.cerbero.io/dsstore-format-package/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Tue, 14 Nov 2023 12:20:03 +0000</pubDate>
				<category><![CDATA[Package]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[macOS]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=2861</guid>

					<description><![CDATA[We have released the DSStore Format package for all licenses of Cerbero Suite. In Apple macOS, .DS_Store is a file that stores custom attributes of its containing folder, such as folder view options, icon positions, and other visual information. It is created and maintained by the Finder application in every folder and contains information that &#8230; <a href="https://blog.cerbero.io/dsstore-format-package/" class="more-link">Continue reading<span class="screen-reader-text"> "DSStore Format Package"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/dsstore-format-package/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2861</post-id>	</item>
	</channel>
</rss>
