Tiki.party.7z -

: Determining which user account created the archive and what their intent was based on the metadata found within the folder structures [1, 4].

: Researchers use this file to practice identifying Jump Lists , LNK files , and Shellbags , which reveal a user's recent file activity and folder navigation [4, 5]. Tiki.Party.7z

: The file is a core component of the Magnet Forensics Weekly CTF (Capture The Flag) challenge [1]. It was designed to simulate a real-world investigation involving a suspicious user account and potential data exfiltration [1, 3]. Technical Specifications : Format : .7z (7-Zip compressed archive). : Determining which user account created the archive

: In the context of the Tiki Party scenario, the archive often contains evidence of "Living off the Land" (LotL) techniques, where legitimate system tools are used for malicious purposes [3, 5]. It was designed to simulate a real-world investigation

: It serves as a "forensic image" of a specific set of user data, intended for practitioners to analyze using tools like Magnet AXIOM, Autopsy, or FTK Imager [2, 4]. Forensic Significance :