Multitasking Host Forensics

No ratings

Presented at BSidesNova 2019 by

Knowing how a host was compromised will help determine if other hosts on your network are vulnerable or have been compromised. This presentation will discuss strategies and steps for host based forensics focusing on things that can be done simultaneously.New analysts may feel overwhelmed at first with hosts forensics. Preparation and planning will help you respond quicker in a crisis. Strategies for what to examine first for a given situation can save valuable time. We will step through a typical situation that requires host forensics to attempt to identify the source of the exploit.Acquire a memory dump Pull network data from your SIEM Pull the password hashes and start password cracking with tools such as John the Ripper and/or Hashcat Review system log files Review application log files Start running anti-virus on the image