The Forensic Lunch!
The one hour, mostly, live digital forensics and incident response focused video cast and podcast.
php/*
The Forensic Lunch!
The one hour, mostly, live digital forensics and incident response focused video cast and podcast.
Copyright: © Copyright 2016 G-C Partners, LLC
It's the Forensic Lunch! The twice a month live videocast/podcast all about DFIR This episode's guests: Phil Hagen Eric Zimmerman Links: - Twitter: @SOF_ELK - Config/code repo: http://for572.com/sof-elk-git - VM readme (w/ instructions and download link):
It's the Forensic Lunch! The twice monthly videocast/podcast just about #DFIR join us as we talk about whats new and what new things you can do! This broadcast we are taking the time to update you on our own tools. We talked about: Pancake Viewer, an open source tool to visually explore forensic images and shadow copies (like an open source ftk imager), https://github.com/forensicmatt/PancakeViewer Event Monkey, an open source and multi threaded event log parser that outputs to sqlite and ElasticSearch, https://github.com/devgc/EventMonkey Event Monkey Monitor, a tool we are working on releasing that lets you monitor event logs in real time pytskUSBDeviceForensics, a version of WoanWare's USB Device Forensics program that allows you to feed in images, https://github.com/woanware/usbdeviceforensics/blob/master/pyTskusbdeviceforensics.py
This episode is live from Enfuse with
Jake Williams and Heather Mahalik
Paul Shomo of Guidance Software
Ashley Hernandez of Guidance Software
Jeff Hedlesky of Guidance Software
Forensic Lunch live from EnFuse with Rob Batzloff talking about Encase 8, and James Wiebe talking about new advancements at CRU
The Forensic Lunch! A special episode hosted by Nicole Ibrahim and featuring in no particular order: Mari Degrazia Cindy Murphy Heather Mahalik Sarah Edwards Shelly Giesbrecht
The forensic lunch!The one hour, mostly, DFIR videocast/podcastThis weeks guest:Jared Atkinson,@jaredcatkinson, talking about about DFIR in powershell or as he calls his toolset PowerForensicsWhat a great Forensic Lunch today with Jared Atkinson talking all about how to do forensics on a live system or mounted image with his Powershell framework PowerForensics.You can grab your own copy of PowerForensics on Github here:https://github.com/Invoke-IR/PowerForensicsRead his Blog here:www.invoke-ir.comVote for him in the Forensic4Cast Awards here:https://forensic4cast.com/forensic-4cast-awards/Reminder I'm up for voting in another category as well!and of course you can follow him on Twitter here:https://twitter.com/jaredcatkinsonBtw, if you want to learn Windows Forensic with me I'm schedule to teach SANS FOR408 Windows Forensics in Houston May 9-14. You can find out more here:https://www.sans.org/event/houston-2016/course/windows-forensic-analysis
The Forensic Lunch!The one hour, mostly, videocast/podcast all about DFIR.This weeks guests:Maxime Lamothe-Brassard of Refraction Point talking about his project Lima Charlie https://github.com/refractionPOINT/li...Ryan Nolette, Security Operations Lead at Carbon Black, talking about all of the ransomware variants he's been seeing and how shadow copies are affectedUs talking about how different tools deal with shadow copies and accessing deleted shadow copies
It's the forensic lunch!
This broadcast James and I go through the results of our testing of different file carving tools:
X-Ways Forensics
Bulk Extractor
Blade
Blackbag Blacklight
It's the Forensic Lunch! The one hour, mostly, videocast/podcast all about DFIR! This weeks guests:Austin Colby, Joe Sylve and Vico Marziale from Black Bag talking about the newest additions to the new version coming out in a matter of days.
The Forensic Lunch!The 1 hour, usually, videocast/podcast that brings you the latest in new DFIR research, topics and people. This weeks guests:Hal Pomeranz,@hal_pomeranz, of Deer Run associates talking about updates to his Linux Memory Grabber and some research into bash_history behavior.You can get the linux memory grabber he discussed here https://github.com/halpomeranz/lmgHal can be reached at hal@deer-run.comEric Zimmerman,@EricRZimmerman, of Kroll's cyber security practice talking about prefetch and explaining his tool to get more, as well as whats new in Windows 10 prefetchYou can get Eric's prefetch parser here: https://github.com/EricZimmerman/Prefetchhttp://www.kroll.com/en-us/who-we-are/kroll-experts/eric-zimmermanMatthew and I showing how to use the hfs+ journal parser and what to do with itYou can get the HFS+ Journal parser here: https://www.gettriforce.com/product/hfs-journal-parser/