Acquire evidence
Inventory executables, timestamps, version resources, installers, DLL/COM dependencies, configuration, registry, logs and database connection details. Image old media where appropriate and record hashes and provenance.
Observe the runtime
- Trace processes and loaded modules.
- Record files and registry keys read or written.
- Capture bounded network, serial or hardware activity.
- Compare known-good and failing workflows.
- Distinguish observation from inference.
The result is an evidence-led environment and event model, not a generic decompilation exercise.
Use executable analysis, dependency mapping, behavior analysis and the pillar.