The Forensic Lunch!
The one hour, mostly, live digital forensics and incident response focused video cast and podcast.
php/*
The Forensic Lunch!
The one hour, mostly, live digital forensics and incident response focused video cast and podcast.
Copyright: © Copyright 2016 G-C Partners, LLC
The first new lunch of the new year withSarah Holmes of the Foreman project (Open Source DFIR Matter Management), You can get a copy (and contribute to!) foreman here:https://bitbucket.org/lowmanio/foreman/You can contact Sarah here: sarah@lowmanio.co.ukMichael Robinson of the Black T-Shirt Cyber Forensics Challenge talking about well the Black T-Shirt Cyber Forensics ChallengeYou can join the Black T-Shirt Cyber Forensics Challenge here:http://cyberforensicschallenge.com/You can contact them at cyberforensicschallenge@gmail.comOur FSEvents tool will be released just as soon as we write documentation for it. Want an early release for testing? Email me dcowen@g-cpartners.com
Forensic Lunch!
This episode we are live from Google in Mountain View, California getting an update on their development projects.
Included are:
LibYAL
Forensic Artifact project
GRR (Google Rapid Response)
Rekall memory analysis platform
Plaso
Timesketch and more!
Forensic Lunch!This weeks guests:Andrew Case,@attrc, from the Volatility Project talking about Volatility 2.5, new plugins and the winners of this years Volatility Plugin ContestYogesh Kahtri, from Champlain, talking about SRUM forensics in Windows 8.1+. A truly amazing new artifact Matt and I talking about our new open source tool Elastic Handler
The Forensic Lunch!
In this episode we are broadcasting live from OSDFCon with the following content:
1. A revised set of rules from our popular forensic game. This time we follow $10,000 pyramid rules to see which of two forensic teams can win!
2. Brian Carrier from Basis Technology talking about whats new Autopsy 4.0
3. Rob Fry from Netflix talking about their new open source framework called Fido and hanging with Kevin Spacey
4. Matthew and I talking about our new automation, normalization and correlation framework ElasticHandler
This week on the forensic lunch we have:
Dave Hawkins talking about his firms currently unbeaten contest, lampbash.work
Chris Pavan, talking about his computer forensics program at Cal State Fullerton and his work in IR at Bechtel
James Habben talking about his web based front end to volatility called eVOLVe and all the cool things you can do with it
This broadcast we have:
Mari Degrazia talking about testing MFT parsers and what goes into them.
Lee Whitfield talking about the events of the week
Suzanne Widdup talking about her work on the Verizon DBIR and a solicitation for your involvement
A talk about Cortana's location tracking storage
Live from CEIC with Michael Robinson, Ronald Clark and more!
In this episode:We discuss the Ashley Madison Data Leak and it's implications for DFIRDavid Dym, @dave873, talks about the newest version of Metadiver and it's ability to show even more metadata, including the contents of pst files and extended mapi!Get it at: www.easymetadata.comMatthew and I talk about our new open source project GC LNK Parser which exposes all of the shell item data we didn't know was there! (Except Joachim Metz) We also preview our integration of our tools to Elastic Search, a preview of our OSDF Con talk and a short talk about things to come in Triforce. Also SANS FOR578, Cyber Threat Intelligence, is now available publicly! Learn more about it here:https://www.sans.org/course/cyber-thr...The SANS Poster on Rekall Memory forensics is out as well and you can get it here: https://www.sans.org/security-resourc...
In this episode recorded in front of a live audience:Our first game of Forensic PassphraseVitaliy Mokosiy of Atola talking about Atola Insight Forensic and its cool direct firmware controlsBrain Carrier of Basis Technology talking about Autopsy 3, Plugin development with Python and OSDF ConBrian Moran of BriMor Labs talking about his live response scripts and new trends in attacker activities
Freedom Edition!Join Matt and I and current guests:Eric Zimmerman, talking deleted registry key analysis and new features in Registry Explorer and more!
You can get the #DFIRSummit release here: https://www.dropbox.com/s/s7doopqpwxz...