1/ Windows Error Reporting (WER) can provide investigators with a wealth of data including:
• SHA1 hashes of crashed processes
• Snapshot of process trees at time of crash
• Loaded modules of crash
• Process minidumps #DFIR#Threathunting
See 🧵 for new #Velociraptor artefact 2/ WER files are found in the following locations which include a range of information to typically address an application crash, however we can use it for investigation!