Observed arrival · 2026-09-18
Afterimage Unit: Windows Security Research That Follows the Evidence
An independent archive of Windows security and digital-forensics investigations, moving from system mechanisms to observed evidence.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Windows defenders, threat hunters, and forensic investigators
- Worth noticing
- The archive contains four dated investigations, including a 12-minute malware analysis from unknown hash to observed behavior.
Field notes
The homepage organizes the work as a four-entry archive rather than a conventional services page. Its subjects range from static and runtime malware evidence to the Windows loader, Regsvr32, and OAuth device-code abuse in Sentinel. Each item includes a publication date, estimated reading time, and a short abstract, making the project’s scope and operating method legible before opening an investigation.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
◉HumanPersonal, local, civic, or handmade
One card from the complete issue