Overview
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore live Linux forensics techniques through a comprehensive shell scripting tutorial presented at GrrCON 2015. Learn why live forensics matters, follow a roadmap for investigations, and discover how to set up USB response drives with known-good binaries. Master techniques for minimizing system disturbance, sending data over networks, and automating log and file listeners. Dive into practical data collection methods, including identifying users and failed login attempts. Gain hands-on experience by putting these concepts together in a script, enhancing your skills in live system analysis and digital forensics.
Syllabus
Intro
Why should you care?
Roadmap
Opening a Case
USB Response Drive
Mounting Known-Good Binaries
Demo: Mounting Binaries
Minimize Disturbance to System
Sending data over the network
Setting Up Log Listener
Automating the Log Listener
Automating the Log Client - Part 2
Automating the File Listener
Automating the File Client
Collecting Data (continued)
Putting It Together with a Script
Who is Johnn?
Who failed to login?
Live Analysis