Zach Profile picture
Everything DFIR @TheDFIRReport | @CuratedIntel | @CyberCX | @XintraOrg https://t.co/ggakuKBS0S
Jul 23, 2022 9 tweets 7 min read
1/ Windows Error Reporting (WER) can provide investigators with a wealth of data including:
• SHA1 hashes of crashed processes
• Snapshot of process trees at time of crash
• Loaded modules of crash
• Process minidumps
#DFIR #Threathunting
See 🧵 for new #Velociraptor artefact 2/ WER files are found in the following locations which include a range of information to typically address an application crash, however we can use it for investigation!

C:/Users/*/AppData/Local/Microsoft/Windows/WER
C:/ProgramData/Microsoft/Windows/WER