Mass Digital Forensics & Incident Response with Velociraptor

Mass Digital Forensics & Incident Response with Velociraptor

John Hammond via YouTube Direct link

PsTree Attempt 1 w/PsList

8 of 17

8 of 17

PsTree Attempt 1 w/PsList

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Mass Digital Forensics & Incident Response with Velociraptor

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Introduction
  2. 2 Velociraptor VFS
  3. 3 Artifacts & Automation w/ VQL
  4. 4 Sigma Rule matching w/ Hayabusa
  5. 5 Waiting on Hayabusa to finish scan.
  6. 6 How does Hayabusa compare to Chainsaw?
  7. 7 Parsing Hayabusa Findings
  8. 8 PsTree Attempt 1 w/PsList
  9. 9 PsTree Attempt 2 w/Velociraptor Process Tracker
  10. 10 Velociraptor Process Tracker
  11. 11 PSExec Change in v2.30 & How to look for the usage of PSExec
  12. 12 Why this is useful and example use case'
  13. 13 PowerShell Artifacts
  14. 14 Bits Transfer Artifact
  15. 15 How to hunt for multiple compromised machines.
  16. 16 Parsing the Results using VQL
  17. 17 Demo Conclusion

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.