Incident Response on macOS

Incident Response on macOS

via YouTube Direct link

Kernel extensions

7 of 22

7 of 22

Kernel extensions

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Incident Response on macOS

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 A Mac is infected! What do you do now?
  3. 3 Forensic collection
  4. 4 IR collection
  5. 5 Login itens
  6. 6 "Hidden" login items
  7. 7 Kernel extensions
  8. 8 Login hooks
  9. 9 Startup itens
  10. 10 Processes
  11. 11 Install history
  12. 12 Safari
  13. 13 Firefox
  14. 14 Quarantine
  15. 15 bash config
  16. 16 bash history
  17. 17 System config
  18. 18 Pre-Sierra logs
  19. 19 Unified logs
  20. 20 Python's os.walk and os.stat
  21. 21 Other tools
  22. 22 Questions?

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.