Sinopsis
Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.
Episodios
-
DFSP # 195 – BAM!
15/11/2019 Duración: 12minThis week I talk about the Windows Background Activity Monitor, an artifact that may be used to find evidence of execution.
-
DFSP # 194 - Powershell Collection Tools
05/11/2019 Duración: 14minThis week I talk about some issues surrounding powershell when used as a digital forensic collection tool.
-
DFSP # 193 - LOKI
29/10/2019 Duración: 15minThis week I talk about LOKI, a tool designed to help analyst scan for APT IOCs.
-
DFSP # 192 - KAPE
22/10/2019 Duración: 17minThis week I talk about KAPE, a freely available forensic evidence collection and triage tool.
-
DFSP # 191 - Linux File Systems
15/10/2019 Duración: 12minThis week I talk about the common Linux file systems and what to expect when dealing with different hosts.
-
DFSP # 190 - Dead Simple Boot Disks
09/10/2019 Duración: 16minThis week I go over how to create a boot disk using the native capability of Ubuntu. You'll never have to rely on third-party tools again!
-
DFSP # 188 - Container Attack Vectors
01/10/2019 Duración: 22minThis week I breakdown container attack vectors for Cloud Incident Response.
-
DFSP # 187 - SUDOERS File and Forensics
01/10/2019 Duración: 14minThis week I breakdown the SUDOERS file for forensic triage.
-
DFSP # 186 - Powershell Forensics
01/10/2019 Duración: 22minThis week I talk about Powershell through the lens of the Service Control Manager.
-
DFSP # 189 - NVMe
01/10/2019 Duración: 15minThis week I talk about NVMe, a data storage technology, from a forensic point of view.
-
DFSP # 185 - Understanding Linux Executables
30/09/2019 Duración: 17minThis week I cover how to approach Linux binaries during investigations.
-
DFSP # 184 - Cloud Incident Response
27/08/2019 Duración: 19minThis week I continue the series about the DFIR changes on the horizon with cloud technology and focus on AWS EC2 forensics.
-
DFSP # 183 - WMI Forensics
20/08/2019 Duración: 22minThis week I talk about using WMI to create processes remotely.
-
DFSP # 182 - Density Scout
13/08/2019 Duración: 10minThis week I talk about Density Scout, an open source tool for malware triage.
-
DFSP # 181 - Remote Execution One-Liners
06/08/2019 Duración: 15minThis week I cover a resource you can use to develop windows remote execution triage methodology and threat hunting.
-
DFSP # 180 - Credential Guard
30/07/2019 Duración: 10minThis week I talk about the Windows credential guard process.
-
DFSP # 179 - OWASP: Insufficient logging and monitoring
23/07/2019 Duración: 17minThis week I talk about OWASP's Number 10 vulnerability category from their top 10 list, insufficient logging and monitoring.
-
DFSP # 178 - Attacker Recon Commands
16/07/2019 Duración: 18minThis week I talk about the most frequently seen attacker recon commands.
-
DFSP # 177 - PSEXEC Forensics
09/07/2019 Duración: 17minThis week I talk about a popular Windows utility attackers often exploit.
-
DFSP # 176 - Cloud Incident Response
02/07/2019 Duración: 17minThis week I talk about incident response in container deployments.