Overview
Syllabus
Introduction
Jareds background
Jareds certifications
What is PowerShell
Hunting Philosophy
Requirements
What is forensics
Typical forensics toolbox
How PowerShell works
Speed
Modules
Download
Unblock Files
Module Path
Power Forensics
Invoke DD
Boot Sectors
Boot Record
Get MBR
Boot Kits
Set Master Boot Record
Boot Code
GPT
UEFI
Get GPT
Get Boot Sector
GPT Partitions
Overview
System Files
Volume Boot
Volume Boot Record
Master File Table
Get File
Individual File Records
Temporal Funding Funnel
Master File Attributes
Standard Information Attributes
File Name Attributes
Data Attributes
NonResident Attributes
Data Runs
Alternate Data Stream
Get Alternate Data Stream
Stream Name
Taught by
44CON Information Security Conference