Rapid Windows Endpoint Investigations with Velociraptor & KAPE w/ Patterson

Описание к видео Rapid Windows Endpoint Investigations with Velociraptor & KAPE w/ Patterson

🛝 Slides for this webcast:
https://www.blackhillsinfosec.com/wp-...

You've had a "true positive" security event on a Windows endpoint (or more than one). Now what!?!?

Combining investigative methodology with creative utilization of some free tools! We'll discuss "tactical forensics" in response to Windows endpoint security events, with artifact acquisition and analysis to rapidly determine what happened, identify indicators of compromise, and help make informed decisions regarding scope of impact and next steps.


Chat with your fellow attendees in the Black Hills Infosec Discord server here:   / discord   -- in the #webcast-live-chat channel.

Комментарии

Информация по комментариям в разработке