Talk With an Expert

ESE Analyst

Last updated: 17 Jun, 2025
Created by:
Mark Baggett
Mark Baggett

A command line based tool that dumps and analyzes databases used on Windows systems that stores various forensics information. Plugins are used to dump different types of data.

Author

Mark Baggett
Mark Baggett

Mark Baggett

Fellow

SANS Faculty Fellow Mark Baggett authored SEC573, SEC673, and SEC406, leads as CTO of the SANS Internet Storm Center, and empowers defenders to automate security through practical, real-world application.

Read more about Mark Baggett