Full Stack Forensics with FOSS

No ratings

Presented at hack.lu 2023 by

This workshop will showcase a suite of free and open source tools to leverage threat intelligence in DFIR investigations. Participants will be setting up a full forensics pipeline, including collection ([GRR](https://github.com/google/grr)), processing ([Plaso](https://github.com/log2timeline/plaso)) and analysis ([Timesketch](https://github.com/google/timesketch/)), and orchestration ([dfTimewolf](https://github.com/log2timeline/dftimewolf)). In addition to that, they'll be using [Yeti](https://github.com/yeti-platform/yeti) to augment their processing and analysis with threat intelligence. Thw workshop will last two hours and is open for anyone to attend. Experience installing packages on Linux and using the Linux CLI in general is required. Experience running and managing Docker containers would be a nice addition. Participants will be given an initial list of Docker containers to pull and set up before the workshop [UPDATE] Here's the list! https://docs.google.com/document/d/1TKqOleH2rdtPjybUt3PYybJ7RrH59kqaHnmywJhRPGk/preview [UPDATE2] Here's the slides with the links to everything: https://docs.google.com/presentation/d/1_IIhazlZF4Nxa_fn4YJ0SieFPJGzP91OwuAO4LIUWOg/edit#slide=id.g24fcb0d3240_0_70