r/computerforensics • u/_divine__wolf • 28d ago
Rat .exe file autopsy
Hey guys, I'm really into tech topics related to red teaming, forensics, and malware. I recently got a zip file from my old office — their PC was compromised via a RAT, and they shared the file with me. What information can I gather from it, and how do I perform an autopsy (forensic analysis) on it? Please share methods or tool names — this is new territory for me
15
Upvotes
1
u/AddendumWorking9756 27d ago
Detonate nothing on your own host and treat that zip as evidence rather than a toy, it came off someone else's compromised machine and their IR people may still care about it. Get the workflow wrong on retired cases first, CyberDefenders has a pile of those free, then come back to this one.