<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress.com" -->
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd"><url><loc>https://dfir.ru/2026/01/26/windows-event-logs-were-cleared-but-resurrected-in-another-file/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2026/01/image-3.png</image:loc><image:title>image</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2026/01/image-2.png</image:loc><image:title>image</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2026/01/image.png</image:loc><image:title>image</image:title></image:image><lastmod>2026-01-26T17:37:17+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2025/05/08/disk-encryption-wide-block-modes-authentication-tags-arent-silver-bullets/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2025/04/bc_paper.png</image:loc><image:title>bc_paper</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2025/04/bc_inject.png</image:loc><image:title>bc_inject</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2025/04/bc_rawdata.png</image:loc><image:title>bc_rawdata</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2025/03/screenshot-from-2025-03-28-19-08-17.png</image:loc><image:title>Screenshot from 2025-03-28 19-08-17</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2025/03/image-2.png</image:loc><image:title>image</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2025/03/encryption_layouts-1.png</image:loc><image:title>encryption_layouts</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2025/03/fedora-boot.png</image:loc><image:title>fedora-boot</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2025/03/opensuse_boot.png</image:loc><image:title>opensuse_boot</image:title></image:image><lastmod>2025-10-24T12:19:22+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2024/12/09/multiple-vulnerabilities-in-ami-file-system-drivers/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/12/applyusa.png</image:loc><image:title>applyusa</image:title></image:image><lastmod>2025-10-14T21:23:06+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2025/02/23/symlink-attacks-without-code-execution/</loc><lastmod>2025-10-10T09:46:09+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2025/01/20/cve-2025-21210-aka-crashxts-a-practical-randomization-attack-against-bitlocker/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2025/01/image.png</image:loc><image:title>image</image:title></image:image><lastmod>2025-03-16T13:38:06+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2024/06/19/vulnerabilities-in-7-zip-and-ntfs3/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/06/kernel_680_cve_not_fixed_2.png</image:loc><image:title>kernel_680_cve_not_fixed_2</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/06/kernel_680_cve_not_fixed_1.png</image:loc><image:title>kernel_680_cve_not_fixed_1</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/06/image-2.png</image:loc><image:title>image</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/06/image-1.png</image:loc><image:title>image</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/06/image.png</image:loc><image:title>image</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/06/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2024-06-18-19-39-56.png</image:loc><image:title>d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2024-06-18-19-39-56</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/06/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2024-06-17-23-44-05.png</image:loc><image:title>d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2024-06-17-23-44-05</image:title></image:image><lastmod>2024-09-04T11:32:03+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2024/01/15/cve-2023-4001-a-vulnerability-in-the-downstream-grub-boot-manager/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/01/image.png</image:loc><image:title>image</image:title></image:image><lastmod>2024-08-14T20:49:23+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2021/10/15/the-uppercased-hell/</loc><lastmod>2024-07-18T12:26:39+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2021/06/28/shadow-copies-become-less-visible/</loc><lastmod>2024-07-18T12:26:18+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2024/04/09/operation-based-prefetching/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/04/pf_ntstatus.png</image:loc><image:title>pf_ntstatus</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/04/image-2.png</image:loc><image:title>image-2</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2024/04/op-prefetch.png</image:loc><image:title>op-prefetch</image:title></image:image><lastmod>2024-04-08T22:20:48+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2021/07/15/playing-with-case-insensitive-file-names/</loc><lastmod>2024-03-10T21:40:07+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2023/08/23/cve-2023-4273-a-vulnerability-in-the-linux-exfat-driver/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2023/08/image-2.png</image:loc><image:title>image-2</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2023/08/image.png</image:loc><image:title>image</image:title></image:image><lastmod>2024-01-13T14:57:06+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2023/11/01/bringing-unallocated-data-back-the-fat12-16-32-case/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2023/11/freebsd_msdosfs_extend-2089237877-e1698855810501.png</image:loc><image:title>freebsd_msdosfs_extend</image:title></image:image><lastmod>2023-11-01T21:12:04+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2023/11/01/cve-2023-45897-a-vulnerability-in-the-linux-exfat-userspace-tools/</loc><lastmod>2023-11-01T14:39:41+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2023/10/03/cve-2023-4692-cve-2023-4693-vulnerabilities-in-the-grub-boot-manager/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2023/10/grub_ntfs_ho_uefi_qemu_guest_errors.png</image:loc><image:title>grub_ntfs_ho_uefi_qemu_guest_errors</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2023/10/mokpwstore.png</image:loc><image:title>mokpwstore</image:title></image:image><lastmod>2023-10-04T09:49:49+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2022/12/18/do-researchers-handle-exfat-volumes-correctly/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2022/12/d0b8d0b7d0bed0b1d180d0b0d0b6d0b5d0bdd0b8d0b5-3.png</image:loc><image:title>d0b8d0b7d0bed0b1d180d0b0d0b6d0b5d0bdd0b8d0b5-3</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2022/12/d0b8d0b7d0bed0b1d180d0b0d0b6d0b5d0bdd0b8d0b5-2.png</image:loc><image:title>d0b8d0b7d0bed0b1d180d0b0d0b6d0b5d0bdd0b8d0b5-2</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2022/12/image-2.png</image:loc><image:title>image-2</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2022/12/image-1.png</image:loc><image:title>image-1</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2022/12/d0b8d0b7d0bed0b1d180d0b0d0b6d0b5d0bdd0b8d0b5-1.png</image:loc><image:title>d0b8d0b7d0bed0b1d180d0b0d0b6d0b5d0bdd0b8d0b5-1</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2022/12/d0b8d0b7d0bed0b1d180d0b0d0b6d0b5d0bdd0b8d0b5.png</image:loc><image:title>d0b8d0b7d0bed0b1d180d0b0d0b6d0b5d0bdd0b8d0b5</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2022/12/image.png</image:loc><image:title>image</image:title></image:image><lastmod>2023-04-19T11:40:27+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/me/</loc><lastmod>2022-12-19T10:20:48+00:00</lastmod><changefreq>weekly</changefreq><priority>0.6</priority></url><url><loc>https://dfir.ru/2021/12/08/things-you-probably-didnt-know-about-fat/</loc><lastmod>2022-08-22T10:50:33+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2022/02/11/exfat-orphan-file-name-entries/</loc><lastmod>2022-02-22T16:30:19+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/tools/</loc><lastmod>2022-01-29T13:02:33+00:00</lastmod><changefreq>weekly</changefreq><priority>0.6</priority></url><url><loc>https://dfir.ru/2022/01/15/macos-fat-directories/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2022/01/macos_stat.png</image:loc><image:title>macos_stat</image:title></image:image><lastmod>2022-01-15T12:30:58+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2018/07/21/a-live-forensic-distribution-executing-malicious-code-from-a-suspect-drive/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/07/grml-grub.png</image:loc><image:title>grml-grub</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/07/screenshot.png</image:loc><image:title>screenshot</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/07/altlinux-rescue.png</image:loc><image:title>altlinux-rescue</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/07/dmesg-sda.png</image:loc><image:title>dmesg-sda</image:title></image:image><lastmod>2021-12-29T09:12:43+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2019/01/19/ntfs-today/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/01/frs-flags-2.png</image:loc><image:title>frs-flags</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/01/lxattrb.png</image:loc><image:title>lxattrb</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/01/attr-ea.png</image:loc><image:title>attr-ea</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/01/attr-si-cs.png</image:loc><image:title>attr-si-cs</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/01/attr-si.png</image:loc><image:title>attr-si</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/01/volume-flags.png</image:loc><image:title>volume-flags</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/01/frs-sref.png</image:loc><image:title>frs-sref</image:title></image:image><lastmod>2023-07-25T08:46:03+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/06/12/trim-and-unallocated-space/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/06/samsung-trim-zeros.png</image:loc><image:title>Samsung-Trim-Zeros</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/06/samsung-trim.png</image:loc><image:title>Samsung-Trim</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/06/ssd-sd-asm.png</image:loc><image:title>ssd-sd-asm</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/06/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-06-10-01-24-38.png</image:loc><image:title>Снимок экрана от 2020-06-10 01-24-38</image:title></image:image><lastmod>2021-11-22T22:36:33+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2019/08/27/windows-forensics-open-research-topics/</loc><lastmod>2021-09-02T06:55:59+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2018/10/07/hiding-data-in-the-registry/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/10/reg_159.png</image:loc><image:title>reg_159</image:title></image:image><lastmod>2021-07-01T22:06:39+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2021/01/10/standard_information-vs-file_name/</loc><lastmod>2021-03-04T08:22:24+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/10/25/the-nt-kernel-can-ignore-your-hardware-clock-during-the-boot/</loc><lastmod>2020-10-25T15:43:55+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/10/03/exporting-registry-hives-from-a-live-system/</loc><lastmod>2020-10-03T13:39:22+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/08/15/containerized-registry-hives-in-windows/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/08/overlay.png</image:loc><image:title>overlay</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/08/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-08-15-15-14-42.png</image:loc><image:title>Снимок экрана от 2020-08-15 15-14-42</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/08/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-08-15-15-14-15.png</image:loc><image:title>Снимок экрана от 2020-08-15 15-14-15</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/08/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-08-15-15-09-41.png</image:loc><image:title>Снимок экрана от 2020-08-15 15-09-41</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/08/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-08-15-15-03-38.png</image:loc><image:title>Снимок экрана от 2020-08-15 15-03-38</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/08/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-08-15-14-51-42.png</image:loc><image:title>Снимок экрана от 2020-08-15 14-51-42</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/08/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-08-15-14-39-52.png</image:loc><image:title>Снимок экрана от 2020-08-15 14-39-52</image:title></image:image><lastmod>2020-08-17T13:45:50+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/07/14/offline-shadow-copies/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/07/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-07-14-00-03-26.png</image:loc><image:title>Снимок экрана от 2020-07-14 00-03-26</image:title></image:image><lastmod>2020-07-14T11:19:28+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/06/29/storage-reserve-blocks-some-tools-from-thoroughly-wiping-unallocated-space/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/06/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-06-29-02-12-51.png</image:loc><image:title>Снимок экрана от 2020-06-29 02-12-51</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/06/20h1-fill-free.png</image:loc><image:title>20h1-fill-free</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/06/81-fill-free.png</image:loc><image:title>81-fill-free</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/06/20h1-f.png</image:loc><image:title>20h1-f</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/06/81-f.png</image:loc><image:title>81-f</image:title></image:image><lastmod>2020-08-02T16:55:19+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/06/21/extracting-unallocated-clusters-from-a-shadow-copy/</loc><lastmod>2020-07-12T21:45:05+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/05/23/onedrive-and-ntfs-last-access-timestamps/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/05/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-05-22-15-15-14.png</image:loc><image:title>Снимок экрана от 2020-05-22 15-15-14</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/05/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-05-22-01-03-27.png</image:loc><image:title>Снимок экрана от 2020-05-22 01-03-27</image:title></image:image><lastmod>2020-06-03T23:42:31+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/05/18/deceptive-ntfs-short-file-names/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/05/svl-tsk.png</image:loc><image:title>svl-tsk</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/05/svl-ftki.png</image:loc><image:title>svl-ftki</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/05/svl-explorer.png</image:loc><image:title>svl-explorer</image:title></image:image><lastmod>2020-05-17T23:22:30+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/05/06/prepopulated-artifacts/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/05/regf-uninit.png</image:loc><image:title>regf-uninit</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/05/w81.png</image:loc><image:title>w81</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/05/w10ofrg.png</image:loc><image:title>w10ofrg</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/05/nk32b.png</image:loc><image:title>nk32b</image:title></image:image><lastmod>2020-05-07T11:33:30+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/04/08/bam-internals/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/04/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-04-08-02-56-36.png</image:loc><image:title>Снимок экрана от 2020-04-08 02-56-36</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/04/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-04-07-02-45-13.png</image:loc><image:title>Снимок экрана от 2020-04-07 02-45-13</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/04/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-04-07-00-55-23.png</image:loc><image:title>Снимок экрана от 2020-04-07 00-55-23</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/04/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-04-06-22-09-57.png</image:loc><image:title>Снимок экрана от 2020-04-06 22-09-57</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/04/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-04-06-19-39-38.png</image:loc><image:title>Снимок экрана от 2020-04-06 19-39-38</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/04/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-04-06-12-35-56.png</image:loc><image:title>Снимок экрана от 2020-04-06 12-35-56</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/04/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-04-06-12-30-55.png</image:loc><image:title>Снимок экрана от 2020-04-06 12-30-55</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/04/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-04-06-12-29-34.png</image:loc><image:title>Снимок экрана от 2020-04-06 12-29-34</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/04/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-04-06-02-29-20.png</image:loc><image:title>Снимок экрана от 2020-04-06 02-29-20</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/04/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-04-06-01-35-46.png</image:loc><image:title>Снимок экрана от 2020-04-06 01-35-46</image:title></image:image><lastmod>2020-04-09T12:00:24+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/03/21/the-extenddeleted-directory/</loc><lastmod>2022-12-08T19:51:03+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/ru/</loc><lastmod>2020-02-29T22:30:50+00:00</lastmod><changefreq>weekly</changefreq><priority>0.6</priority></url><url><loc>https://dfir.ru/2020/02/29/scoped-shadow-copies/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/02/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-02-29-17-47-17-1.png</image:loc><image:title>Снимок экрана от 2020-02-29 17-47-17</image:title></image:image><lastmod>2020-02-29T20:27:01+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/02/23/you-write-to-a-logical-drive-when-you-read-from-it/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/02/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-02-23-01-02-45.png</image:loc><image:title>Снимок экрана от 2020-02-23 01-02-45</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/02/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-02-22-22-03-43.png</image:loc><image:title>Снимок экрана от 2020-02-22 22-03-43</image:title></image:image><lastmod>2020-02-23T12:16:19+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2020/02/09/carving-file-control-blocks-from-memory-dumps/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/02/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-02-09-13-55-09.png</image:loc><image:title>Снимок экрана от 2020-02-09 13-55-09</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2020/02/d0a1d0bdd0b8d0bcd0bed0ba-d18dd0bad180d0b0d0bdd0b0-d0bed182-2020-02-09-13-43-07-e1581245758831.png</image:loc><image:title>Снимок экрана от 2020-02-09 13-43-07</image:title></image:image><lastmod>2020-02-10T16:47:32+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2018/12/08/the-last-access-updates-are-almost-back/</loc><lastmod>2019-10-09T10:08:57+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2019/07/29/things-you-probably-didnt-know-about-shadow-copies/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/07/vsc-offline-2.png</image:loc><image:title>vsc-offline-2</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/07/vsc-offline.png</image:loc><image:title>vsc-offline</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/07/pf-vss-bogus.png</image:loc><image:title>pf-vss-bogus</image:title></image:image><lastmod>2019-07-28T23:26:26+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2019/04/23/ntfs-large-clusters/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/04/format.png</image:loc><image:title>format</image:title></image:image><lastmod>2019-04-23T21:06:42+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2019/03/25/forensic-analysis-of-disclosed-uninitialized-kernel-memory/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/03/kl-file.png</image:loc><image:title>kl-file</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/03/kts2019_kmd.png</image:loc><image:title>kts2019_kmd</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/03/ntfs-slack.png</image:loc><image:title>ntfs-slack</image:title></image:image><lastmod>2019-03-24T23:44:15+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2019/02/28/ntfs-unallocated-data-marked-as-allocated/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/02/repair_verify.png</image:loc><image:title>repair_verify</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/02/repair_corrupt.png</image:loc><image:title>repair_corrupt</image:title></image:image><lastmod>2021-07-02T06:41:51+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2018/07/25/a-live-forensic-distribution-writing-to-a-suspect-drive/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/07/screenshot-ntfs.png</image:loc><image:title>screenshot-ntfs</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/07/screenshot-4.png</image:loc><image:title>screenshot-4</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/07/screenshot-3.png</image:loc><image:title>screenshot-3</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/07/screenshot-2.png</image:loc><image:title>screenshot-2</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/07/screenshot-1.png</image:loc><image:title>screenshot-1</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/07/ubuntu-dmesg.png</image:loc><image:title>ubuntu-dmesg</image:title></image:image><lastmod>2019-02-25T22:51:14+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2019/02/16/how-the-logfile-works/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/02/lfs-layout.png</image:loc><image:title>lfs-layout</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/02/lfs-infinite.png</image:loc><image:title>lfs-infinite</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/02/lfs-record-pages.png</image:loc><image:title>lfs-record-pages</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/02/lfs-record-page.png</image:loc><image:title>lfs-record-page</image:title></image:image><lastmod>2020-08-06T10:27:24+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2019/01/08/hibernation-and-ntfs/</loc><lastmod>2019-01-08T01:06:15+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2019/01/04/what-writes-to-the-syscache-hive/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/01/syscache-stack.png</image:loc><image:title>syscache-stack</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2019/01/amcache_trace.png</image:loc><image:title>amcache_trace</image:title></image:image><lastmod>2019-01-04T00:17:57+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2018/12/02/the-cit-database-and-the-syscache-hive/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/12/syscache-tsk.png</image:loc><image:title>syscache-tsk</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/12/syscache.png</image:loc><image:title>syscache</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/12/cit.png</image:loc><image:title>cit</image:title></image:image><lastmod>2018-12-18T18:57:58+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2018/12/16/the-inconsistency-of-last-access-timestamps/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/12/ntfs_ts_la_i30.png</image:loc><image:title>ntfs_ts_la_i30</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/12/ntfs_ts_la_mft.png</image:loc><image:title>ntfs_ts_la_mft</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/12/xp.png</image:loc><image:title>xp</image:title></image:image><lastmod>2021-03-05T07:47:17+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2018/11/19/exploring-intermediate-states-of-a-registry-hive-using-transaction-log-files/</loc><lastmod>2018-11-19T10:41:47+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2018/11/18/tools-that-recover-deleted-registry-data-dont-do-the-same-job/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/11/regdel.png</image:loc><image:title>regdel</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/11/reg_unalloc-1.png</image:loc><image:title>reg_unalloc-1</image:title></image:image><lastmod>2018-11-17T23:24:10+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2018/10/26/effects-of-running-an-offline-av-scan/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/10/krd-diff.png</image:loc><image:title>krd-diff</image:title></image:image><lastmod>2018-10-25T23:41:30+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru/2018/09/08/memory-compression-and-forensics/</loc><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/09/hbin-decompressed.png</image:loc><image:title>hbin-decompressed</image:title></image:image><image:image><image:loc>https://dfir.ru/wp-content/uploads/2018/09/hbin-compressed.png</image:loc><image:title>hbin-compressed</image:title></image:image><lastmod>2018-09-08T00:57:50+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://dfir.ru</loc><changefreq>daily</changefreq><priority>1.0</priority><lastmod>2026-01-26T17:37:17+00:00</lastmod></url></urlset>
