SANS DFIR Webcast - Incident Response Event Log Analysis

SANS DFIR Webcast - Incident Response Event Log Analysis

84,482 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@Qantum802
@Qantum802 - 16.11.2022 11:41

So how do you install Fallout2.exe on a Windows 10 from just the files off the disk because you have a copy but don't know where your usb disk drive is or let alone the disk yet haven't tried finding either because well. Log(s)🧗‍♂️ hahahahaha.

I'm serious though, I'm sure you've gotta have the answer I'm looking for.

Ответить
@lancemarchetti8673
@lancemarchetti8673 - 21.09.2022 22:49

With Velociraptor deployments on Debian clouds...DFIR tech has really stepped up the game in a huge way!

Ответить
@laptoplifestylegeez
@laptoplifestylegeez - 28.07.2022 00:02

Fantastic training but I can't find the recommended log alerts settings

Ответить
@cyberofthinx
@cyberofthinx - 13.04.2022 12:52

Perfect points to make me get it, many thanks!

Ответить
@ITinProduction
@ITinProduction - 03.08.2021 01:12

Thank you so much for this video, this is so old but still a gold, i always have a confusion about reading any security log files to find the vulnerabilities and trojans or viruses. i wish if you can make another video a lot in detail.

Ответить
@ruthawele2102
@ruthawele2102 - 08.05.2020 02:27

Love this, very informative

Ответить
@Eskimoz
@Eskimoz - 25.11.2019 11:30

On like :)

Ответить
@Jpsalm91
@Jpsalm91 - 15.10.2019 19:48

When systems become too complicated, thats when the most basic attack becomes effective and vice versa

Ответить
@esinyelk
@esinyelk - 23.03.2019 21:01

Very nice video to go through the basics. Thank you very much.

Ответить
@kenjboyd6233
@kenjboyd6233 - 02.01.2019 07:39

This video is a bit dated. But it wasn't long after this video was produced that Microsoft triggered the control algorithms that they had been working on for many years, and started changing computers two Windows 10 without permission from users. By this point, anyone who doesn't realize that Microsoft is patient zero, as it is called in this video, is either Clueless or scared of Microsoft. No, they will never plant files called malicious. Anything. but any file that starts with the name trusted is a dead giveaway as to being a major component in the first malware driven operating system in history.

Ответить
@alfie0311
@alfie0311 - 28.03.2018 06:15

Well done, thanks

Ответить
@joshuablanchette878
@joshuablanchette878 - 31.07.2017 23:33

excellent video, the speaker did a great job.

Ответить
@kepenge
@kepenge - 13.12.2016 19:12

was this investigation conducted using the compromised machine or did you use SIFT?

Ответить