> For the complete documentation index, see [llms.txt](https://notes.qazeer.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.qazeer.io/dfir/windows/ttps_analysis.md).

# TTPs analysis

- [Accounts usage](https://notes.qazeer.io/dfir/windows/ttps_analysis/accounts_usage.md)
- [Local persistence](https://notes.qazeer.io/dfir/windows/ttps_analysis/local_persistence.md)
- [Lateral movement](https://notes.qazeer.io/dfir/windows/ttps_analysis/lateral_movement.md)
- [PowerShell activity](https://notes.qazeer.io/dfir/windows/ttps_analysis/powershell_activity.md)
- [Program execution](https://notes.qazeer.io/dfir/windows/ttps_analysis/program_execution.md)
- [Timestomping](https://notes.qazeer.io/dfir/windows/ttps_analysis/timestomping.md)
- [EVTX integrity](https://notes.qazeer.io/dfir/windows/ttps_analysis/evtx_integrity.md)
- [System uptime](https://notes.qazeer.io/dfir/windows/ttps_analysis/system_uptime.md)
- [ActiveDirectory replication metadata](https://notes.qazeer.io/dfir/windows/ttps_analysis/activedirectory_replication_metadata.md)
- [ActiveDirectory persistence](https://notes.qazeer.io/dfir/windows/ttps_analysis/activedirectory_persistence.md)
