Introduction to Cyber Triage - Fast Forensics for Incident Response

แชร์
ฝัง
  • เผยแพร่เมื่อ 16 พ.ย. 2024

ความคิดเห็น • 31

  • @Richard_AG
    @Richard_AG 4 ปีที่แล้ว +6

    Thanks Mr. Richard for another great video. Could you try and review the Remote acquisition or "network collect" functions? I'm very interested in those capabilities.

    • @13Cubed
      @13Cubed  4 ปีที่แล้ว +3

      It's a bit harder to lab up, but if there is a decent amount of interest I will consider doing so.

  • @0xtz_
    @0xtz_ 4 ปีที่แล้ว +4

    Thanks for this amazing video 🙂😍

  • @mahesh3960
    @mahesh3960 4 ปีที่แล้ว +4

    Videos are amazing and I really loved the channel. Sir can we have some videos on Smart Phone forensics which covers the Android platform mostly?

    • @13Cubed
      @13Cubed  4 ปีที่แล้ว +1

      Thanks. I would consider bringing in some experts to present such content, but mobile forensics is not my area of expertise. Thus far, the channel only has one episode covering that topic, which is specifically for iOS/iPadOS devices.

    • @mahesh3960
      @mahesh3960 4 ปีที่แล้ว

      @@13Cubed we really love the effort put into sharing knowledge for everyone sir. And if possible please make a video on career guide and pathway to DFIR field. Thank u sir :)

    • @13Cubed
      @13Cubed  4 ปีที่แล้ว +1

      @@mahesh3960 Good idea - thanks!

  • @josemuanespinto7675
    @josemuanespinto7675 4 ปีที่แล้ว +2

    Thanks for the video

  • @demetriahorne1006
    @demetriahorne1006 3 ปีที่แล้ว +1

    Thank you!

  • @myhackertech
    @myhackertech 4 ปีที่แล้ว +2

    Need to try the light version that is free as the developer is same person behind Autopsy

  • @DE-gc8up
    @DE-gc8up 3 ปีที่แล้ว +2

    hey... This is one great demo!! Are there any more such tools or this is only one such in market?

    • @13Cubed
      @13Cubed  3 ปีที่แล้ว +1

      Maybe Magnet AXIOM?

  • @johnhack67
    @johnhack67 3 ปีที่แล้ว +1

    Thanks.

  • @davidmacfarlane8228
    @davidmacfarlane8228 4 ปีที่แล้ว +2

    Another great video thanks!! I tried processing a .raw memory file that I acquired using Magnet's free RAM capture software but Cyber Triage did not seem to like it at all.
    I was able to process it using Volatility3... have you had any issues like this?

    • @13Cubed
      @13Cubed  4 ปีที่แล้ว

      Interesting, no I have not. In fact I used that same tool to create a memory capture and then used Cyber Triage to analyze it without any issues.

    • @davidmacfarlane8228
      @davidmacfarlane8228 4 ปีที่แล้ว

      I'm going to give it another go but within the "choose memory image" dialog box .raw doesn't seem to be a supported file type which I assume is the issue for me.

    • @13Cubed
      @13Cubed  4 ปีที่แล้ว

      David MACFARLANE Just change the extension to .mem and try again.

    • @briancarrier3134
      @briancarrier3134 4 ปีที่แล้ว +3

      @@13Cubed Sorry about that. We just added ".raw" to our list of types in the file picker for the next release.

  • @terrorbit3553
    @terrorbit3553 3 ปีที่แล้ว +1

    Thanks for the content. I hope I'm not repeating previous requests or that this is an obvious answer, but do you have any recommendations on free resources to practice data forensics/Incident Response on?

    • @13Cubed
      @13Cubed  3 ปีที่แล้ว

      SANS has a ton of free resources. Check out their TH-cam channel and website.

  • @GruberAG
    @GruberAG ปีที่แล้ว

    No more free version..
    By the way great video, tnx4it!

    • @13Cubed
      @13Cubed  ปีที่แล้ว

      Oh that's too bad -- I didn't realize the free version was no longer available. :(

  • @sai1234g24
    @sai1234g24 4 ปีที่แล้ว +1

    Hi Sir,
    This is indeed very helpful. Can you point me to any online resources where we can download free memory and disk samples? I am just starting out in forensics and would love to get my hands on some really interesting memory/disk samples. I know you already uploaded one memory sample as part of your videos, but wondering if there are more out there.
    thanks again.

    • @13Cubed
      @13Cubed  4 ปีที่แล้ว +5

      I have two memory samples on my channel associated with "Pulling Threads" and "Mini Memory CTF". Otherwise, check out this page for more resources: www.dfir.training/dfir-training-blog/forensic-test-images-2

    • @sai1234g24
      @sai1234g24 4 ปีที่แล้ว +1

      @@13Cubed thank you sir. This helps

  • @cyberforstudents
    @cyberforstudents 4 ปีที่แล้ว +1

    Are there volatility profiles for windows servers?

    • @jayaram_sreevalsan_gatech8260
      @jayaram_sreevalsan_gatech8260 4 ปีที่แล้ว +1

      Most of the volatility profiles for servers are just aliases that map back to a corresponding desktop version if there are no changes. Ie 2019 is win10 etc.

  • @sami9348
    @sami9348 4 ปีที่แล้ว

    what is the background music you used here?

    • @13Cubed
      @13Cubed  4 ปีที่แล้ว

      It's called Green Space - Halcyon Lounge.