BSides Kent: The Gist of Hundreds of Incident Response Cases
本文探讨了如何通过关注关键法证数据提高事件响应效率。重点包括追踪攻击者的横向移动路径、识别隐藏的后门以及利用智能方法提升工作效率。同时介绍了MPLogs和bitmap cache等不为人知的法证工具。 2025-5-16 20:46:30 Author: dfir.ch(查看原文) 阅读量:7 收藏

Abstract

How to become an Incident Response Rockstar? After conducting hundreds of Incident Response cases, more data is not always better. Focusing on the most relevant forensic data can speed up the investigation process rapidly. In this talk, we will discuss the importance of various event logs to track down lateral movement paths from the attackers, how to find planted (and seemingly legitimate) backdoors, and how you can work smarter, not harder - which also holds true in digital forensics. As a bonus, we will discuss less-known artifacts like MPLogs and the bitmap cache. By attending this talk, participants will be better and more efficient Incident Responders as they can focus on key aspects of an investigation.

Gist Abstract

Figure 1: The Gist of Hundreds of Incident Response Cases

Youtube Video

Not recorded.


文章来源: https://dfir.ch/talks/bsides_kent_2025/
如有侵权请联系:admin#unsafe.sh