426 avsnitt

Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.

Digital Forensic Survival Podcast Digital Forensic Survival Podcast

    • Teknologi
    • 4,0 • 1 betyg

Listen to talk about computer forensic analysis, techniques, methodology, tool reviews and more.

    DFSP # 427 - MOF Balls

    DFSP # 427 - MOF Balls

    Windows management instrumentation, also known as WMI, is an App on Windows that allows a user to query all sorts of things about a system. Being native to Windows, it is an attractive target for a attackers to leverage. This week I'll break down the artifact from a DFIR point of a few and talk about how to detect its misuse.

    • 31 min
    DFSP # 426 - SSH Forensics: Log Analysis

    DFSP # 426 - SSH Forensics: Log Analysis

    This week I'm wrapping up my series on SSH forensics with a discussion on SSH log triage. Logs are usually what an analyst will start with, so this episode is important. There are a few different log types, and there is a pitfall with one of them, which is something you must be aware of to avoid making inaccurate conclusions. I'll provide the artifact breakdown, triage methodology, and more.

    • 22 min
    DFSP # 425 - SSH Forensics: Host-Based Artifacts

    DFSP # 425 - SSH Forensics: Host-Based Artifacts

    In the last episode on this topic, I covered SSH from a investigation point of view. I explained SSH and the artifacts that typically come up when your investigating. In this episode, we're getting into the triage methodology. This includes the artifacts targeted for a fast, but yet effective triage for notable SSH activity on a given host.

    • 30 min
    DFSP # 424 - SSH Forensics: Understanding Secure Shell

    DFSP # 424 - SSH Forensics: Understanding Secure Shell

    SSH is a protocol used to secure remote access to systems, making it a cornerstone in safeguarding sensitive information and ensuring secure communications. In this podcast, we will delve into the basics of SSH, its key concepts and other useful elements important for context when investigating for notable SSH activity.

    • 23 min
    DFSP # 423 - Guiding Lights: Cyber Investigations Investigation Lifecycle

    DFSP # 423 - Guiding Lights: Cyber Investigations Investigation Lifecycle

    This week I'm discussing a fundamental aspect of cybersecurity: incident response preparation. Effective incident response is paramount, and preparation is the key to success. This preparation includes comprehensive documentation, training, having the right tools and resources in place, and developing incident response plans and playbooks. It also involves ensuring clear communication protocols and conducting regular training and testing. 
    I'll explore preparation from the perspective of the investigation life cycle, where success is the reward for preparation. Join me as I uncover the importance of preparation in incident response and how it lays the foundation for success in investigations.

    • 30 min
    DFSP # 422 - EVTX Express: Cracking into Windows Logs Like a Pro

    DFSP # 422 - EVTX Express: Cracking into Windows Logs Like a Pro

    Today I'm talking Windows forensics, focusing on Windows event logs. These logs are very valuable for fast triage, often readily available in your organization's SIEM. But have you ever wondered about the processes enabling this quick access? Not only are the logs automatically collected and fed into the appliance, but they are also formatted and normalized for easy data searchability. This is crucial, as the logs are originally in a complex format challenging to natively interpret. Now, picture a scenario where event logs are inaccessible through a security appliance—enter this week's topic: EVTX analysis options. Don't be caught unprepared.

    • 21 min

Kundrecensioner

4,0 av 5
1 betyg

1 betyg

Mest populära poddar inom Teknologi

Internetpionjärerna
Tele2
Lex Fridman Podcast
Lex Fridman
Acquired
Ben Gilbert and David Rosenthal
Darknet Diaries
Jack Rhysider
Allt du behöver veta om ny teknik
Ny Teknik
Bilar med sladd
Bilar med sladd

Du kanske också gillar

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
Risky Business News
risky.biz
Hacking Humans
N2K Networks
Risky Business
Patrick Gray
CyberWire Daily
N2K Networks
Malicious Life
Malicious Life