Spyware forensic work has so far relied on incidental logs that were never designed for security analysis and are too often partial and short-lived. Now we have the possibility to detect advanced spyware, exploits and unauthorised physical access, even months after the fact.