A collection of small queries I created during my investigations. I hope they help you as they did with me.
Well, forensic tools do not always parse properly the artifacts. Sometimes, the artifacts of interest are not properly parsed/decoded and you have to manually go through them. This is exactly where you may find these queries useful. It is literally the reason why I assembled them.
CAUTION: As ALWAYS, please validate the results of any query you use. They can misoperate or even break at any time.
Do share with your colleagues, as sharing is what makes our DFIR family great. Cheers!