Overview
Explore an efficient approach to Digital Forensics and Incident Response (DFIR) using Osquery in this 20-minute conference talk from BSidesSF 2020. Delve into the challenges faced by Incident Responders when analyzing security breaches and understanding attack patterns. Learn how to leverage Osquery as an alternative to time and resource-intensive forensics tools, potentially accelerating the IR process. Discover techniques for tracking attacker breadcrumbs and gain insights into implementing DFIR at scale using this powerful open-source tool.
Syllabus
BSidesSF 2020 - Leveraging Osquery for DFIR at Scale (Sohini Mukherjee)
Taught by
Security BSides San Francisco