PSExec Change in v2.30 & How to look for the usage of PSExec
12
Why this is useful and example use case'
13
PowerShell Artifacts
14
Bits Transfer Artifact
15
How to hunt for multiple compromised machines.
16
Parsing the Results using VQL
17
Demo Conclusion
Description:
Explore mass digital forensics and incident response techniques using Velociraptor in this comprehensive video tutorial. Learn about Velociraptor's Virtual File System (VFS), artifacts, and automation with VQL. Discover how to perform Sigma rule matching with Hayabusa and compare it to Chainsaw. Dive into parsing Hayabusa findings, creating process trees using PsList and Velociraptor Process Tracker, and investigating PSExec usage. Examine PowerShell artifacts, Bits Transfer artifacts, and techniques for hunting multiple compromised machines. Master parsing results using VQL to enhance your digital forensics and incident response capabilities.
Mass Digital Forensics & Incident Response with Velociraptor