Sinopsis
Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.
Episodios
-
DFSP # 255 - The Worship of Intelligence in Tech
05/01/2021 Duración: 25minThis week I interview author Shawn Livermore about the myth of the "tech-genius."
-
DFSP # 254 - Network Triage Part 3
29/12/2020 Duración: 16minThis week is the third part of the Network-Fast-Triage mini-series. In this installation I cover triage techniques for Windows event logs that record network port-binding.
-
DFSP # 253 - Network Triage Part 2
22/12/2020 Duración: 15minThis week is the second part of the Network-Fast-Triage mini-series. In this installation I cover triage techniques for Windows event logs that record network connections.
-
DFSP # 252 - Werfault
15/12/2020 Duración: 14minThis week I cover triage techniques for werfault.exe. The process does not have the best documentation which makes it a challenge to triage.
-
DFSP # 251 - The Rise of Crypto SIM Swapping
08/12/2020 Duración: 32minThis week I interview Haseeb Awan, CEO of EFANI, about the rise of SIM swapping attacks. Haseeb explains the attack, how attackers carry it out, and provides some mitigation strategies.
-
DFSP # 250 - Network Triage Part 1
01/12/2020 Duración: 14minThis week is the first part of the Network-Fast-Triage mini-series. The first installation is the network investigation primer.
-
DFSP # 249 - Linux Fileless Attacks
24/11/2020 Duración: 15minThis week I go over a method to detect fileless malware on Linux systems.
-
DFSP # 248 - Searchsploit
17/11/2020 Duración: 18minThis week I talk utilizing the ExploitDB for DFIR investigations. Searchsploit is a command line search tool for Exploit-DB that allows you the power to perform detailed off-line searches through your locally checked-out copy of the repository. This capability is particularly useful for security assessments on segregated or air-gapped networks without Internet access.
-
DFSP # 247 - Startup Locations
10/11/2020 Duración: 14minThis week is the last part of the Persistence-Fast-Triage mini-series. The final installation covers Windows startup locations.
-
DFSP # 246 - Investigation Lifecycle
03/11/2020 Duración: 17minThis week I talk about the IR Investigation Lifecycle, or, the elements included within the incident handling process to ensure a complete investigation.
-
DFSP # 245 - Fetch and Execute
27/10/2020 Duración: 16minThis week I talk about the use of RUNDLL32 to exploit information files (.INF) to "fetch and execute" malware.
-
DFSP # 244 - Registry Persistence Part 3
20/10/2020 Duración: 20minThis week is part 3 of examining the Windows Registry for evidence of persistence and the focus is on Windows Registry Modification Event Records.
-
DFSP # 243 - Stomping the Clock
13/10/2020 Duración: 15minThis week I talk about detecting time stomping on Windows and Linux systems.
-
DFSP # 242 - Registry Persistence Part 2
06/10/2020 Duración: 19minThis week I talk about examining the Windows Registry for evidence of persistence.
-
DFSP # 241 - Forensic Hardware
29/09/2020 Duración: 27minThis week I interview JASON ROSLEWICZ of SUMURI about the hardware that drives your forensics system.
-
-
DFSP # 239 - Registry Persistence Part 1
15/09/2020 Duración: 17minThis week I talk about examining the Windows Registry for evidence of persistence.
-
DFSP # 238 - Bash Attacks
08/09/2020 Duración: 15minThis week I talk about the use of Bash commands in crypto-mining attacks.
-
DFSP # 237 - Attack Shimming
01/09/2020 Duración: 12minThis week I talk about detecting persistence via Attack Shimming artifacts.
-
DFSP # 236 - Apple FSEvents
25/08/2020 Duración: 22minThis week I interview Steve Whalen of SUMURI about Apple FSEvent artifacts. Learn what they are and how to leverage them for investigations.