Sinopsis
Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.
Episodios
-
DFSP # 074 - Detecting Lateral Movement
18/07/2017 Duración: 16minThis week I review a document put out by the Japan Computer Emergency Response Team Coordination Center on "Detecting Lateral Movement through Tracking Event Logs."
-
DFSP # 073 - Jump Lists
11/07/2017 Duración: 19minThis week I break down the forensic value of Windows Jump lists.
-
DFSP # 072 - Free Training & Free Beer
04/07/2017 Duración: 18minThis week I talk about how to design your own training programs using low cost\ no cost options.
-
DFSP # 071 - Automated Malware Triage
27/06/2017 Duración: 22minThis week I take a look at online sandboxes for malware analysis.
-
DFSP # 070 - Notepad++
20/06/2017 Duración: 18minThis week I talk a Notepad++, a freely available code editing tool with some great options built in that are useful for inspecting forensic artifacts.
-
DFSP # 069 - Automated Memory Triage
13/06/2017 Duración: 21minThis week I take a look at Redline by Mandiant, a tool that offers automated memory triage and much more.
-
DFSP # 068 - Is Scanning On-Scene Legit?
06/06/2017 Duración: 24minThis week I explore the idea of using scanning tools as part of an on scene triage process in order to find hidden devices and\or to document the systems of the local network.
-
DFSP # 067 - IR A-Z
30/05/2017 Duración: 18minLooking for the ultimate DFIR checklist? This week I check out a freely available guidebook that, as the name implies, is aimed at addressing all things DFIR related A-Z.
-
DFSP # 066 - Skype Forensics
23/05/2017 Duración: 20minThis week I talk about the Skype artifacts forensic examiners need to be aware of.
-
DFSP # 065 - Is CSA+ Certification right for you?
16/05/2017 Duración: 23minThis week I take a look at CompTia's CSA+ certification and how it fits into a DFIR career.
-
DFSP # 064 - Chrome Forensics
09/05/2017 Duración: 18minThis week it's back to browsers with Chrome Forensics.
-
DFSP # 063 - Bulk Extractor
02/05/2017 Duración: 16minThis week is tool review week featuring Bulk Extractor. This is a great triage tool, lab tool and all around tool to help generate leads for your case.
-
DFSP # 062 - Building a Forensic VM with VirtualBox
25/04/2017 Duración: 20minThis week I take you through some of the "pain points" of using VirtualBox as a forensic machine virtualization platform. VirtualBox is freely available and is a great tool to scale your lab and field systems at a low cost. VirtualBox does not have the "easy" buttons the pay tools have but do not let that stop you. In this episode I talk about the solutions that will have you up and running.
-
DFSP # 061 - Firefox Forensics
18/04/2017 Duración: 16minThis week I talk Firefox forensics and identify the artifacts examiners need to know about.
-
DFSP # 060 - Browsing on the Edge
11/04/2017 Duración: 19minThis week I’m talking about the Windows browser some are still surprised to learn about, MS Edge. Windows 10 comes with two browsers and in this week’s podcast I’m going to go over one of them, MS Edge, and what computer forensic examiners need to know about it.
-
DFSP # 059 - Thumbcache Forensics
04/04/2017 Duración: 24minThis week I talk about surviving Windows Thumbcache forensics. A great source of evidence for File Use & Knowledge investigations.
-
DFSP # 058 - Linux FU&K Artifacts
28/03/2017 Duración: 23minThis week I talk Linux forensics and breakdown some useful artifacts that may generate leads for investigations.
-
DFSP # 057 - Webmail Collections
21/03/2017 Duración: 20minThis week I talk about a methodology to collect webmail using freely available tools as well as the things you must consider before you do so.
-
DFSP # 056 - Surviving Solid State Drives
14/03/2017 Duración: 15minThis week I go over my survival tips for imaging solid state drives (SSDs).
-
DFSP # 055 - Automated Host Intelligence
07/03/2017 Duración: 25minThis week I talk about threat intelligence tool Hostintel by Keith Jones.