SecurityFest: Anti-Forensics - You are doing it wrong
本文探讨了常见的反取证策略(如删除USN日志、清理shellbag、篡改时间戳等),指出这些方法常因执行不当或被误解而失效。防御者可利用这些“擦除痕迹”发现恶意行为。适合事件响应人员学习如何识别和应对反取证技术。 2025-10-30 11:34:11 Author: dfir.ch(查看原文) 阅读量:17 收藏

Abstract

In this talk, we’ll dissect common anti-forensics strategies—like USN Journal deletion, shellbag clearing, timestamp manipulation, and disabling access time updates—and reveal how they are often executed ineffectively or misunderstood.

From registry edits like masking user account activity to configuring Windows EFS, we’ll examine why these techniques often fail against modern investigative workflows and how defenders use these “footprints of erasure” to uncover malicious intent.

Attendees will gain a comprehensive understanding of what works and what doesn’t and how to identify these techniques during incident response. Whether you’re an IR consultant, security analyst, or blue teamer, this talk offers actionable knowledge to outsmart adversarial anti-forensics tactics.

Anti-Forensics - You are doing it wrong (Believe me, I’m an IR consultant)

Figure 1: Anti-Forensics - You are doing it wrong (Believe me, I'm an IR consultant)

Youtube Video

Anti-Forensics - You are doing it wrong (Believe me, I’m an IR consultant)


文章来源: https://dfir.ch/talks/securityfest_2025/
如有侵权请联系:admin#unsafe.sh