How to Analyse a Windows 10 Workstation for Digital Forensics
Автор: hascyber
Загружено: 2022-09-21
Просмотров: 1538
Описание:
In this episode I will show you how to perform a Digital Forensics Analysis of a compromised Windows 10 Workstation.
I will also show you interesting locations where forensics artefacts can be found in Windows workstations.
Tools used in this episode are Autopsy which is used for analysing forensic images and Mitec which is used for analysing Windows registry.
Below are interesting locations to extract artefacts for analysis
Windows Event (Security, System, and Application)
C:\Windows\winevt
Scheduled Tasks
C:\Windows\System32\Tasks folder
Registry Files (SAM, SYSTEM, and SOFTWARE)
C:\Windows\System32\Config
#cybersecurity #hascyber #blueteam #forensics #dfir #digitalforensics computer forensics
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: