<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Digital-Forensics on krash.dev</title><link>https://krash.dev/tags/digital-forensics/</link><description>Recent content in Digital-Forensics on krash.dev</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 14 Aug 2026 08:29:09 +0530</lastBuildDate><atom:link href="https://krash.dev/tags/digital-forensics/rss.xml" rel="self" type="application/rss+xml"/><item><title>Zone Identifier - Is your file downloaded from the internet?</title><link>https://krash.dev/posts/zone-identifier/</link><pubDate>Thu, 06 Oct 2022 00:00:00 +0000</pubDate><guid>https://krash.dev/posts/zone-identifier/</guid><description>&lt;p&gt;Have you ever wondered, why your file is not working after downloading it from the internet? How does system know if the file is downloaded from the internet?&lt;/p&gt;
&lt;p&gt;The answers to this is &lt;strong&gt;Zone.Identifiers&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id="what-are-zone-identifiers"&gt;What are Zone Identifiers?&lt;a class="heading-anchor" href="#what-are-zone-identifiers" aria-label="Link to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Zone Identifiers is an alternate data stream that points, from where the file came on the users&amp;rsquo; computer.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Alternate Data Streams are included with files on WIndows. This is typically the case with downloaded and blocked files.&lt;/p&gt;</description></item><item><title>Anonymous Challenge Write-Up: WinjaCTF c0c0n 2021</title><link>https://krash.dev/posts/winja-anonymous-challenge-writeup/</link><pubDate>Mon, 15 Nov 2021 00:00:00 +0000</pubDate><guid>https://krash.dev/posts/winja-anonymous-challenge-writeup/</guid><description>&lt;p&gt;WinjaCTF at c0c0n [2021]: I developed an easy challenge - called &amp;ldquo;Anonymous&amp;rdquo; - the challenge was based upon browser forensics.&lt;/p&gt;
&lt;h2 id="tldr"&gt;TL;DR&lt;a class="heading-anchor" href="#tldr" aria-label="Link to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Intended Way&lt;/strong&gt; - Download the zip &amp;gt; Extract it &amp;gt; Navigate the Linux directory structure &amp;gt; To find a directory called &lt;code&gt;.config&lt;/code&gt; &amp;gt; google-chrome &amp;gt; Default &amp;gt; Open the History File in SQL Browser &amp;gt; Search for URLs and upon up the URL to get a file with the name - formatted like flag.&lt;/p&gt;</description></item></channel></rss>