<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://dfir.forge-work.com/</loc>
<changefreq>weekly</changefreq>
<priority>1</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/start</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/search</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/playbooks</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/quickstart</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/assessment</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/acquisition</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/downloads</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/triage-timeframe-bounding</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/triage-patient-zero</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/triage-initial-access-validation</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/contain-network-isolation</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/contain-account-lockdown</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/preserve-volatile-memory</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/preserve-log-snapshot</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/collect-edr-telemetry</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/collect-m365-uac</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/analyze-lateral-movement</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/analyze-data-staging</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/analyze-exfil-channels</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/contain-exfil-block</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/collect-dlp-alerts</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/triage-ransom-note-analysis</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/contain-ransomware-spread</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/analyze-encryption-scope</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/recover-decrypt-assessment</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/collect-azure-ad-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/analyze-oauth-abuse</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/contain-cloud-session-revoke</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/analyze-inbox-rules</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/collect-missing-log-fallback</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/preserve-chain-of-custody</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/collect-web-server-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/eradicate-malware-removal</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/eradicate-credential-reset</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/eradicate-patch-vuln</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/recover-system-rebuild</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/recover-service-restoration</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/recover-backup-validation</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/post-incident-lessons-learned</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/post-incident-detection-improvement</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/post-incident-report-generation</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/triage-bec-email-analysis</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/analyze-web-shell-detection</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/contain-insider-access-restriction</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/collect-third-party-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/analyze-credential-dumping</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/eradicate-persistence-hunt</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/eradicate-verification-checklist</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/eradicate-configuration-hardening</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/preserve-ransomware-artifacts</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/preserve-insider-covert-capture</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/preserve-phishing-email-evidence</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/preserve-cloud-tenant-snapshot</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/triage-phishing-indicators</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/contain-phishing-quarantine</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/collect-phishing-artifacts</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/analyze-phishing-campaign-scope</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/eradicate-phishing-remediation</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/post-incident-ransomware-resilience-review</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/post-incident-cloud-hardening-review</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/post-incident-data-disclosure-review</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/node/post-incident-webapp-root-cause-review</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-security-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-sysmon-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-powershell-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-sam-hive</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-system-hive</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-software-hive</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-ntuser-hive</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-amcache</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-mft</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-usnjrnl</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-prefetch</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-shimcache</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-bits-jobs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-scheduled-tasks</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-memory-dump</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-browser-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-jump-lists</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-wmi-persistence</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-rdp-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-defender-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-system-evtx-7045</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-task-scheduler-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-bits-client-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-wmi-activity-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-firewall-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-kerberos-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-usrclass-shellbags</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-bam-dam</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-srum</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-run-runonce</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-usb-device-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-ifeo</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-rdp-connection-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-lnk-files</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-recycle-bin</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-logfile</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-vss</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-zone-identifier</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-thumbcache</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-startup-folder</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-rdp-bitmap-cache</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-activitiescache</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-search-index</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-virtual-memory</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-defender-quarantine</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-etw-etl</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-wer</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-mplog</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-wlan-autoconfig-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-sdelete-evidence</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-rdp-shared-drives</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-com-hijack</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-applocker-wdac-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-group-policy-evtx</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-credential-guard-lsass</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-boot-config-repair</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-psreadline-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-powershell-transcripts</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-setupapi-install-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-security-hive-lsa</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/win-notifications-db</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-unified-audit-log</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-azure-ad-signin</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-azure-ad-audit</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-mailbox-audit</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-message-trace</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-azure-activity-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-azure-resource-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-conditional-access-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-sharepoint-onedrive-audit</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-entra-risk-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-inbox-rules-audit</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-ediscovery-results</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-defender-endpoint</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-defender-cloud-apps</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-keyvault-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-nsg-flow-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-storage-analytics</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-teams-audit</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-power-platform-audit</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-sentinel-analytics</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-service-principal-activity</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-intune-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-purview-dlp-insider</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-defender-identity</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-aks-activity-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-aks-kube-audit</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-aks-container-insights</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/m365-acr-audit-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-cloudtrail-management-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-iam-credential-report</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-sts-assumerole-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-vpc-flow-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-route53-resolver-query-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-guardduty-findings</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-ssm-session-manager-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-ec2-instance-ebs-metadata</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-eks-control-plane-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-eks-kubernetes-audit</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-eks-authenticator-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-eks-container-insights</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/aws-ecr-cloudtrail-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/google-workspace-admin-audit-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/google-workspace-user-login-audit-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/google-workspace-gmail-log-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/google-workspace-drive-log-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/google-workspace-oauth-token-log-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/google-workspace-saml-log-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/google-workspace-takeout-log-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/google-vault-search-export-evidence</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/gcp-cloud-audit-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/gcp-cloud-storage-audit-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/gcp-vpc-flow-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/gcp-cloud-dns-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/gke-kubernetes-audit-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/gke-control-plane-and-workload-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/okta-system-log</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/slack-audit-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/slack-access-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/github-enterprise-audit-log</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/github-enterprise-audit-log-stream</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-auth-log</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-syslog</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-bash-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-passwd-shadow</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-cron-jobs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-systemd-services</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-ssh-authorized-keys</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-proc-filesystem</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-tmp-suspicious</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-network-connections</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-auditd</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-wtmp-btmp</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-kern-log</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-package-manager-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-daemon-log</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-web-server-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-ssh-known-hosts</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-memory-dump</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-kernel-modules</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-ld-preload</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-selinux-apparmor</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-ext4-journal</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-trash-recently-used</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-docker-containers</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-docker-daemon-config</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-docker-json-file-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-containerd-runtime-state</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-kubernetes-api-audit</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-kubelet-pod-runtime-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-core-dumps</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-systemd-journal</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-group-sudoers</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-at-anacron</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-init-rc-local</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-iptables-nftables</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-systemd-timers</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-networkmanager-profiles</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-sshd-config-hostkeys</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-sssd-cache-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-dhcp-leases</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/linux-dns-resolver-state</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-pcap-files</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-netflow-sflow</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-firewall-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-vpn-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-dns-query-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-dns-sinkhole</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-proxy-web-filter</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-ids-ips-alerts</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-dhcp-leases</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-zeek-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-radius-tacacs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-wireless-controller</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-load-balancer-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-email-gateway</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-waf-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-nac-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-certificate-transparency</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-bgp-route-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-ntp-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-ssl-tls-inspection</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-snmp-syslog</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/net-arp-mac-tables</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-fsevents</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-spotlight</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-apfs-snapshots</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-timemachine</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-unified-log</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-tcc-db</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-system-log</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-gatekeeper-xprotect</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-network-preferences</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-mrt-xprotect-remediator</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-launch-agents</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-launch-daemons</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-login-items</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-cron-periodic</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-knowledgec</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-quarantine-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-safari-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-notification-center</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-recent-items</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-dock-plist</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-install-log</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-bash-zsh-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-crash-reports</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-keychain</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-sudo-authd</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-openbsm-audit</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-wifi-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-bluetooth</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-memory-dump</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-system-extensions</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-execpolicy-db</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-messages-chatdb</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-mail-envelope-index</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-file-provider-icloud-drive</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/macos-installhistory-plist</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-sms-db</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-call-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-addressbook</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-interactionc</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-voicemail</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-safari-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-safari-browserstate</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-safari-cache</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-routined-cache</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-locationd-clients</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-wifi-known-networks</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-health-location</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-knowledgec</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-biome</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-photos-sqlite</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-notes</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-calendar</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-springboard-state</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-powerlog</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-wifi-plist</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-cellular-provider</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-keychain</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-tcc</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-datausage</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-netusage</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-fseventsd</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-crash-reports</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-unified-logs</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-bluetooth-paired</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-mail-store</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-maps-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-file-provider-icloud-drive</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/ios-app-group-metadata</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-sms-mms</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-call-log</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-contacts</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-google-messages</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-user-dict</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-chrome-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-chrome-autofill</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-chrome-cookies</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-gmm-sync</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-cell-wifi-cache</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-gms-location</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-wifi-locations</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-usagestats</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-recent-tasks</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-media-store</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-downloads</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-reflection-gel</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-packages-xml</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-settings-db</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-accounts</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-frosting</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-keystore</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-locksettings</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-wifi-config</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-bluetooth-config</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-logcat</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-bugreport</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-batterystats</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-gmail-cache</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-appops</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-notification-history</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-networkstats</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-tombstones-anr-dropbox</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/artifacts/android-documentsui-recents</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/no-edr-deployed</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/logs-overwritten</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/encrypted-drives</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/no-network-captures</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/cloud-logs-expired</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/offline-systems</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/no-siem-coverage</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/third-party-dependency</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/legal-hold-conflict</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/ransomware-encrypted</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/credential-unknown-scope</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/anti-forensics-detected</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/vpn-masking-origin</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/insider-still-active</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/multi-tenant-cloud</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/no-memory-capture-window</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/compliance-reporting-deadline</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/insufficient-backup-validation</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/cloud-container-logging-gaps</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/saas-audit-not-enabled</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/knowledge/blockers/saas-retention-expired</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/lifecycle/triage</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/lifecycle/contain</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/lifecycle/preserve</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/lifecycle/collect</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/lifecycle/analyze</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/lifecycle/eradicate</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/lifecycle/recover</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/lifecycle/post-incident</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/playbooks/ransomware</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/playbooks/phishing</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/playbooks/data-exfiltration</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/playbooks/insider-threat</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/playbooks/web-app-compromise</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/playbooks/cloud-identity-compromise</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/playbooks/bec</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/playbooks/credential-theft</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/quickstart/ransomware</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/quickstart/phishing</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/quickstart/bec</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/quickstart/data-exfiltration</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/quickstart/insider-threat</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/quickstart/cloud-identity-compromise</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/quickstart/web-app-compromise</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/quickstart/credential-theft</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/assessment/ransomware</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/assessment/phishing</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/assessment/data-exfiltration</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/assessment/insider-threat</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/assessment/web-app-compromise</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/assessment/cloud-identity-compromise</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/assessment/bec</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://dfir.forge-work.com/assessment/credential-theft</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
</urlset>
