Mass Digital Forensics & Incident Response with Velociraptor
John Hammond via YouTube
-
11
-
- Write review
Overview
Syllabus
Introduction
Velociraptor VFS
Artifacts & Automation w/ VQL
Sigma Rule matching w/ Hayabusa
Waiting on Hayabusa to finish scan.
How does Hayabusa compare to Chainsaw?
Parsing Hayabusa Findings
PsTree Attempt 1 w/PsList
PsTree Attempt 2 w/Velociraptor Process Tracker
Velociraptor Process Tracker
PSExec Change in v2.30 & How to look for the usage of PSExec
Why this is useful and example use case'
PowerShell Artifacts
Bits Transfer Artifact
How to hunt for multiple compromised machines.
Parsing the Results using VQL
Demo Conclusion
Taught by
John Hammond
Reviews
4.7 rating, based on 3 Class Central reviews
-
Velociraptor Forensics is a great tool that makes digital forensics more understandable. The demo provided a comprehensive overview of its capabilities, showcasing its potential to streamline forensic investigations. Velociraptor helps users to easily collect, analyze and visualize data while saving up on time and resources.
-
The course was enlightening by discussing the velociraptor application for digital forensics for mostly servers or endpoints. I really enjoyed this course.
-
I found the presentation super helpful and easy to apply. The presenter was also very knowledgeable and was able to deliver the presentation in a way that is easy to follow and understand. I will definitely go to give a try on the tools suggested using the knowledge acquired.