Forgotten But Not Gone: Gathering NTFS Artifacts of Deletion - SANS Tactical Detection Summit 2018

Поділитися
Вставка
  • Опубліковано 4 лют 2019
  • SIEM Summit 2019 Agenda: www.sans.org/u/UIC
    Presenter: Mari DeGrazia (@MariDeGrazia) and Scott Hanson, Kroll
    While endpoint threat monitoring tools are powerful, many lack ways to quickly and efficiently recover evidence of deleted information. This deleted information may include evidence of staging tools, exfiltration files and malware that attackers clean up as they go. How can you track an attacker through your environment if they are cleaning up after themselves? Learn how to pull back and leverage two files on the system, the MFT and the NTFS Index Attribute, to discover evidence of deleted files. Once an attacker’s favorite staging location is known, this technique can be scaled up and automated to sweep an environment to locate and analyze evidence of deleted files.

КОМЕНТАРІ •