Get the Whitepaper called Hunting Red Team Activities with Forensics Artifacts.
You can download it from the following link: https://packetstormsecurity.com/files/download/157791/hunting-redteamactivities.pdf
Source: https://packetstormsecurity.com/files/157791/Hunting-Red-Team-Activities-With-Forensics-Artifacts.html

