Sinopsis
Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.
Episodios
-
DFSP # 355 - Network Triage
06/12/2022 Duración: 14minThis week I talk about essential network basics necessary for triage.
-
-
-
DFSP # 352 - Startup Locations
15/11/2022 Duración: 10minThis week I talk about Windows startup locations.
-
-
DFSP # 350 - Linux Fileless Attacks
01/11/2022 Duración: 16minThis week I talk about fileless attacks Linux systems.
-
DFSP # 349 - Registry Modification Events
25/10/2022 Duración: 20minThis week I talk about how to find evidence of malicious autoruns in the windows registry using Windows event codes.
-
DFSP # 348 - Root Cause
18/10/2022 Duración: 12minThis week I talk about strategies to determine root cause early during an investigation.
-
DFSP # 347 - Weblogs
11/10/2022 Duración: 24minThis week is a breakdown of HTTP log forensic triage.
-
DFSP # 346 - Masquerading
04/10/2022 Duración: 15minThis week I talk about finding evidence of Kernel file masquerading on Linux systems.
-
DFSP # 345 - AutoRuns
27/09/2022 Duración: 18minThis week I talk about how to find evidence of malicious autoruns in the windows registry.
-
DFSP # 344 - Mac Spotlight DB
20/09/2022 Duración: 18minThis week I talk about the forensic value of the Apple Spotlight DB.
-
DFSP # 343 - Registry aka The Dungeon Maze
13/09/2022 Duración: 11minWhen you talk autoruns you must talk about the Windows registry. This artifact is very dense and it may be difficult to zero in on the elements that are important for compromise assessment. Given that, I am going to begin the series with a breakdown of the Windows Registry from a DFIR point of view. This is crucial in understanding ...
-
DFSP # 342 - FLUX It
06/09/2022 Duración: 14minThis week I talk about the attack methodology known as Fast Flux.
-
DFSP # 341 - Those other taskers
30/08/2022 Duración: 14minThis week’s focus is on other scheduled task events useful for DFIR triage.
-
DFSP # 340 - PSEXEC, ready or not
23/08/2022 Duración: 17minThis week I talk about a popular Windows utility attackers often exploit.
-
DFSP # 339 - That SUDO that you do
16/08/2022 Duración: 15minThis week I breakdown the SUDOERS file for forensic triage.
-
DFSP # 338 - Taskers
09/08/2022 Duración: 20minThis week’s focus is on new scheduled tasks, which are a common way of establishing longevity on system. I will have my breakdown of the artifact and how to interpret it for fast analysis coming up….
-
DFSP # 337 - ResponderCon
02/08/2022 Duración: 18minThe must-attend event for Cyber First Responders who must detect and deal with ransomware, zero-day events, and more!
-
DFSP # 336 - BAM!
26/07/2022 Duración: 12minThis week I talk about the Windows Background Activity Monitor, an artifact that may be used to find evidence of execution.