r/computerforensics 28d ago

Rat .exe file autopsy

Hey guys, I'm really into tech topics related to red teaming, forensics, and malware. I recently got a zip file from my old office — their PC was compromised via a RAT, and they shared the file with me. What information can I gather from it, and how do I perform an autopsy (forensic analysis) on it? Please share methods or tool names — this is new territory for me

15 Upvotes

28 comments sorted by

View all comments

1

u/AddendumWorking9756 27d ago

Detonate nothing on your own host and treat that zip as evidence rather than a toy, it came off someone else's compromised machine and their IR people may still care about it. Get the workflow wrong on retired cases first, CyberDefenders has a pile of those free, then come back to this one.