<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>My Technician Security Labs</title>
    <link>https://www.mytechnician.tech/labs/</link>
    <description>Windows 11 security labs from My Technician: forensic artifacts, event log analysis, persistence, and detection.</description>
    <language>en-us</language>
    <lastBuildDate>Sat, 08 Aug 2026 16:39:12 GMT</lastBuildDate>
    <atom:link href="https://www.mytechnician.tech/labs/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Windows 11 Forensic Artifacts: Where Evidence of Program Execution Lives</title>
      <link>https://www.mytechnician.tech/labs/windows-11-forensic-artifacts-program-execution/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/windows-11-forensic-artifacts-program-execution/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>Windows records that a program ran in at least six separate places, and they do not agree with each other. Here is what each artifact actually proves on Windows 11, and which one to trust.</description>
    </item>
    <item>
      <title>USB Device History on Windows 11: What the Registry Proves</title>
      <link>https://www.mytechnician.tech/labs/usb-device-history-windows-11-registry-setupapi/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/usb-device-history-windows-11-registry-setupapi/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>Windows keeps a permanent record of every USB storage device ever attached, including serial numbers and first-connect times. Here is where it lives on Windows 11 and how to read it.</description>
    </item>
    <item>
      <title>Triage a Suspected-Compromised Windows 11 PC in 30 Minutes</title>
      <link>https://www.mytechnician.tech/labs/triage-compromised-windows-11-pc-30-minutes/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/triage-compromised-windows-11-pc-30-minutes/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>A fast, ordered pass over a Windows 11 machine you think is compromised, using only free tools. What to check, in what sequence, and how to tell a real finding from normal noise.</description>
    </item>
    <item>
      <title>SRUM on Windows 11: Reconstructing App, Network and Power Use</title>
      <link>https://www.mytechnician.tech/labs/srum-srudb-dat-windows-11-forensics/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/srum-srudb-dat-windows-11-forensics/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>SRUDB.dat records how much data each application sent and received, hour by hour, for around 30 days. It is the only standard Windows artifact that ties a program to network volume.</description>
    </item>
    <item>
      <title>ShimCache vs Amcache vs Prefetch: Which One Proves Execution?</title>
      <link>https://www.mytechnician.tech/labs/shimcache-vs-amcache-vs-prefetch-execution-evidence/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/shimcache-vs-amcache-vs-prefetch-execution-evidence/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>Three Windows artifacts get treated as interchangeable evidence that a program ran. Only one of them actually proves it. Here is what each records on Windows 11 and how to read them together.</description>
    </item>
    <item>
      <title>Reading the Windows Firewall Log (pfirewall.log) on Windows 11</title>
      <link>https://www.mytechnician.tech/labs/read-windows-firewall-log-pfirewall-windows-11/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/read-windows-firewall-log-pfirewall-windows-11/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>Windows Firewall can log every allowed and dropped connection, but the logging is off by default. Here is how to turn it on, read the format, and find outbound traffic that should not be there.</description>
    </item>
    <item>
      <title>Prefetch Files on Windows 11: Proving a Program Ran, and When</title>
      <link>https://www.mytechnician.tech/labs/prefetch-files-windows-11-proving-execution/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/prefetch-files-windows-11-proving-execution/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>A .pf file records how many times a program ran and the last eight times it happened. Here is how to read Prefetch on Windows 11, and the three ways the evidence misleads you.</description>
    </item>
    <item>
      <title>Event IDs 7045 and 4698: Spotting Persistence on Windows 11</title>
      <link>https://www.mytechnician.tech/labs/event-ids-7045-4698-service-scheduled-task-persistence/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/event-ids-7045-4698-service-scheduled-task-persistence/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>A new service and a new scheduled task are the two most common ways malware survives a reboot on Windows. Both are logged. Here is how to read those events and separate them from normal software installs.</description>
    </item>
    <item>
      <title>Event ID 4624 and Logon Types: Who Signed In to a Windows PC</title>
      <link>https://www.mytechnician.tech/labs/event-id-4624-logon-types-windows/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/event-id-4624-logon-types-windows/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>Security event 4624 records every successful logon, but the Logon Type field is what makes it useful. Here is what each type means on Windows 11 and which ones should make you look twice.</description>
    </item>
    <item>
      <title>Scheduled Task Persistence on Windows 11: The Attack and Its Artifacts</title>
      <link>https://www.mytechnician.tech/labs/detect-scheduled-task-persistence-windows-11/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/detect-scheduled-task-persistence-windows-11/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>How a persistent scheduled task is planted on Windows 11, demonstrated in an isolated lab, and the exact registry keys, XML files, and event IDs it leaves behind for a defender to find.</description>
    </item>
    <item>
      <title>How to Tell If a Windows 11 PC Was Remotely Accessed</title>
      <link>https://www.mytechnician.tech/labs/detect-remote-access-windows-11-rdp-teamviewer-anydesk/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/detect-remote-access-windows-11-rdp-teamviewer-anydesk/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>RDP, TeamViewer and AnyDesk each leave a different trail on Windows 11. Here are the exact event IDs, log files and registry keys that show who connected, when, and from where.</description>
    </item>
    <item>
      <title>Build an Isolated Malware Analysis Lab on Windows 11 with Hyper-V</title>
      <link>https://www.mytechnician.tech/labs/build-malware-analysis-lab-windows-11-hyper-v/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/build-malware-analysis-lab-windows-11-hyper-v/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>A safe Windows 11 analysis VM with no route to your network or the internet, using Hyper-V that is already on your machine. No second PC and no paid software required.</description>
    </item>
    <item>
      <title>Amcache.hve on Windows 11: What It Records and How to Read It</title>
      <link>https://www.mytechnician.tech/labs/amcache-hve-windows-11-forensics/</link>
      <guid isPermaLink="true">https://www.mytechnician.tech/labs/amcache-hve-windows-11-forensics/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>Amcache stores the SHA-1 of executables Windows has encountered — including ones already deleted. Here is how to parse it on Windows 11 and what its entries do and do not prove.</description>
    </item>
  </channel>
</rss>