Digital Forensic Survival Podcast

  • Autor: Vários
  • Narrador: Vários
  • Editor: Podcast
  • Duración: 159:21:00
  • Mas informaciones

Informações:

Sinopsis

Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.

Episodios

  • DFSP # 395 - Lateral Movement and Admin Logons

    12/09/2023 Duración: 18min

    This week is on lateral movement detection techniques. Inspecting Domain Admin account logons is a key component to lateral movement triage. Admin accounts are sought after by attackers for their elevated privileges. Evidence is often left behind both on the targeted system and on the domain controller. Both these factors provide protection opportunity through Windows event log analysis. I’ll break down the method....

  • DFSP # 394 - Functional Documentation

    05/09/2023 Duración: 15min

    This week I want to talk about the value of having functional documentation for your organization, or, at least for your team. Functional documentation means you have thoughtful and up-to-date incident run books, and play books that provide utility and usefulness for a responder. Without such documentation, you are always in danger of some dangerous pitfalls, some of which I'll discuss. This episode I cover what functional documentation is, it's investigative value for an organization, how to get started...

  • DFSP # 393 - Linux Subsystems for Windows

    29/08/2023 Duración: 24min

    The linux subsystem for windows, create both opportunity and challenges for forensic analysts. It makes Windows an excellent platform for multi platform forensic analysis tasks, allowing it to take it vantage of the many many Linux tools available. The challenges are foreseeable, you have Linux artifacts, now commingled on a Windows platform, which makes forensic analysis that much more difficult when examining such a system as evidence. This week I'm going to break down the linux subsystems for forensic investigators…

  • DFSP # 392 - Simulation Training

    22/08/2023 Duración: 20min

    This week I'm going to talk about tabletop exercises as part of a security training program. I feel that there is too much focus on technical skill training and not enough focus on actual incident management training in the industry. There are plenty of highly skilled professionals that can do DFIR work… However, a roadblock, many organizations and practitioners encounter is in the struggle of how to actually implement their knowledge and skills for a security incident response investigation within a specific organization. They may know what to do, but there are many challenges in identifying actually how to do it when the time comes. I will share my thoughts on how to improve your security program through simulation training…

  • DFSP # 391 - Investigation Lifecycle

    15/08/2023 Duración: 26min

    This week I'm talking about The NIST (National Institute of Standards and Technology) investigation lifecycle. The NIST investigation lifecycle encompasses a series of well-defined steps, starting from problem identification and scoping, through data collection and analysis, to the formulation of conclusions and recommendations. This comprehensive framework ensures that investigations conducted by NIST are rigorous, unbiased, and provide reliable results that can be used to inform decision-making, improve practices, and promote innovation across a wide range of disciplines. More about it...

  • DFSP # 390 - SSH Triage

    08/08/2023 Duración: 17min

    This week I'm talking about linux forensic triage strategy. In particular, I'm covering SSH. SSH traffic comes up in many different types of investigations. For that reason, it is a common and standard artifact every examiner should be familiar with. I will provide you the artifact background and the triage strategy…..

  • DFSP # 389 - $Usnrl

    01/08/2023 Duración: 15min

    The USN Journal, also known as the Update Sequence Number Journal, is a feature of the Windows operating system that serves as a record of changes made to files and directories on a disk volume. It provides valuable information and insights into file system activities, which can aid investigators in reconstructing events, understanding system behavior, and uncovering evidence. This week I break down the artifact from a DFIR point of view provide triage strategy.....

  • DFSP # 388 - Web 3.0 Talk with SUMURI

    25/07/2023 Duración: 38min

    This week Jason Roslewicz from SUMURI returns for some web 3.0 and virtual reality talk.

  • DFSP # 387 - Network Share Modifications

    18/07/2023 Duración: 20min

    This week I talk about adding, modifying, and removing network shares through the lens of detecting lateral movement.

  • DFSP # 386- The Three Task Hosts

    11/07/2023 Duración: 12min

    This week I break down the three Windows task hosts from a DFIR point of view.

  • DFSP # 385 - Network Share Access

    04/07/2023 Duración: 19min

    This week I talk about network share access events and lateral movement detection.

  • DFSP # 384 - Cloud Talk with SUMURI

    27/06/2023 Duración: 01h16min

    This week Jason Roslewicz from SUMURI returns for some cloud talk.

  • DFSP # 383 - WMI Exploitation

    20/06/2023 Duración: 20min

    This week I talk about the exploitation of the Windows Management Instrumentation application.

  • DFSP # 382 - Protocol Buffers

    13/06/2023 Duración: 40min

    This week Chris Currier and I talk about mobile forensics and protocol buffers.

  • DFSP # 381 - Spoliation

    06/06/2023 Duración: 16min

    This week I cover Windows events commonly associated with data spoliation and insider threats.

  • DFSP # 380 - Ransomware Talk with SUMURI

    30/05/2023 Duración: 58min

    This week Jason Roslewicz from SUMURI returns for some ransomware talk.

  • DFSP # 379 - New Process Creation

    23/05/2023 Duración: 18min

    This week I Cover my all-time favorite Windows event, security event 4688: new process creation. If you do windows, incident, response, forensics, this is a must-know know artifact.

  • DFSP # 378 - SVCHOST Revisited

    16/05/2023 Duración: 18min

    This week I talk about SVCHOST; how it fits into the Windows operating system, and how to think about it from a DFIR point of view.

  • DFSP # 377 - Interview with Yugal Pathak

    09/05/2023 Duración: 39min

    This week I talk with Interview with Yugal Pathak about organizational forensic readiness.

  • DFSP # 376 - Zero-Day and DFIR

    02/05/2023 Duración: 25min

    This week I talk about the role and typical responsibilities DFIR professionals may be called up to take to assist with a zero-day response.

página 6 de 25