Reading Time: 3 minutes Case 002 Hudak s Honeypot The Case of The Forgotten Honeypot Readme: The best way to introduce this is to start with the README from Tyler: This Ubuntu Linux honeypot was put online in Azure in early October with the sole purpose of watching what happens with those exploiting [ ] The post Case 002 Tyler Hudak s Honeypot appeared first on DFIR Madness .
Reading Time: 3 minutes The Fortress Daily drivers can be InfoSec War Machines! Infosec-fortress.py is designed to turn Ubuntu Desktop 20.04 into a single system that supports DFIR, RE, and Penetration Testing Operations in a single VM (or bare metal). Threat hunting with teeth. No, wait. DFIR with Teeth. We could also just call [ ] The post InfoSec-Fortress appeared first on DFIR Madness .
Reading Time: 24 minutes Case001 Super Timeline Creation and Analysis Before Starting this lab it is strongly recommended you examine the memory, autoruns, pcap, or logs first. Come to this lab with indicators to search for. Learning Objectives of Super Timeline Creation and Analysis Be able to explain what a super timeline is. Understand [ ] The post Case 001 Super Timeline Analysis appeared…
Reading Time: 12 minutes Case 001 Triage Disk Analysis Case 001 Brief and Materials. Get the materials and follow along! Have you built your DFIR Fort Kickass, yet? How to build a DFIR Analyst Workstation found here. Make sure you understand the basic rundown of forensic artifacts. This post assumes you have a [ ] The post Triage Disk Analysis Case 001 appeared first on DFIR Madness .
Reading Time: 5 minutes The Timing of It All Lining Up the Timelines of the Artifacts There is a curveball in the data!! ** Warning: This will contain spoilers.** If you are turbo hardcore and do not want to spoil the initial vector then simply take this away: The hosts were set to incorrectly [ ] The post Case 001 The Timing of it All appeared first on DFIR Madness .
Reading Time: 1 minute Incident Response Thumb Drive A Note About USB Drives This is simply a list of recommended tools to keep on a USB drive. The intent is to have this USB Drive in your Go Bag for use during an incident. It will contain the tools you intend to use [ ] The post Incident Response Thumb Drive appeared first on DFIR Madness .
Reading Time: 20 minutes Case 001 AutoRuns Analysis Case 001 Brief and Materials. Get the materials and follow along! Have you built your DFIR Fort Kickass, yet? How to build a DFIR Analyst Workstation found here. Make sure you understand the basic rundown of forensic artifacts. This post assumes you have a DFIR Analyst [ ] The post Case 001 AutoRuns Analysis appeared first on DFIR Madness .
Reading Time: 5 minutes Mounting The Szechuan Sauce (Case 001) E01 Files Learning Objectives of Mounting E01 Understand what an E01 File is and what it provides Be able to mount an E01 file in SIFT Semi-Required Knowledge Computer memory (the RAM) basic knowledge Basic Linux Command Line Fu Basic Virtual Machine Operation [ ] The post Mounting Case001 E01 Files appeared first on DFIR Madness .
Reading Time: 28 minutes Case 001 PCAP Analysis Case 001 Brief and Materials. Get the materials and follow along! Have you built your DFIR Fort Kickass, yet? How to build a DFIR Analyst Workstation found here. Make sure you understand the basic rundown of forensic artifacts. This post assumes you have a DFIR Analyst [ ] The post Case 001 PCAP Analysis appeared first on DFIR Madness .