Forensic Artifacts and Techniques that are Essential for a Fraud Investigation

No ratings

Presented at TechnoSecurity&DigitalForensics 2019 by

Fraud investigations can be challenging for a number of reasons. They can be initiated either internally or externally from the organization; they could involve law enforcement or simply be treated as a civil matter. Your employees may be the suspect or the victim depending on the circumstances and jumping conclusions to either may do more harm than good. This demo will investigate common Operating System artifacts and files that would be used in both attack vectors such as Windows Event Logs, RDP activity, SRUM, Amcache, Storport USB History, evidence of local file access such as LNK files, shellbags, etc., and use AXIOM to build a timeline of activity that helps the examiner step through an incident.