Mass Digital Forensics & Incident Response with Velociraptor

Поділитися
Вставка
  • Опубліковано 15 гру 2024

КОМЕНТАРІ • 21

  • @iamkingsage8571
    @iamkingsage8571 Рік тому +11

    0:00 Introduction
    1:08 Velociraptor VFS
    4:05 Artifacts & Automation w/ VQL
    6:16 Sigma Rule matching w/ Hayabusa
    7:20 Waiting on Hayabusa to finish scan.
    9:20 How does Hayabusa compare to Chainsaw?
    10:40 Parsing Hayabusa Findings
    13:40 PsTree Attempt 1 w/PsList
    17:55 PsTree Attempt 2 w/Velociraptor Process Tracker
    19:50 Velociraptor Process Tracker
    22:35 PSExec Change in v2.30 & How to look for the usage of PSExec
    25:25 Why this is useful and example use case'
    26:10 PowerShell Artifacts
    27:30 Bits Transfer Artifact
    28:50 How to hunt for multiple compromised machines.
    30:40 Parsing the Results using VQL
    33:20 Demo Conclusion

  • @christophertharp7763
    @christophertharp7763 10 місяців тому +1

    That new psexec...key with the source is HUGE

  • @KenPryor
    @KenPryor Рік тому

    I recently set up a Velociraptor server at home and installed agents on all my virtual machines. I still have much to learn, but I love it so far. Still have to dive in to VQL so I can do my own artifacts.

  • @Love-yv1fc
    @Love-yv1fc Рік тому +20

    John, please use time stamps, it will be helpful😊

    • @_JohnHammond
      @_JohnHammond  Рік тому +1

      Big thanks to @iamkingsage8571, they knocked them out for us!

    • @Jason-c1b3r
      @Jason-c1b3r Рік тому +1

      Not only that but under the section that pops up when you click 'more' you see the chapters which are time stamped

  • @dominiksabat
    @dominiksabat Рік тому +1

    Such a great demo!

  • @mindtropy
    @mindtropy Рік тому

    I always wanted to try out Velociraptor but did not have a chance, thank you! I normally use Binalze AIR for mass DFIR, I will watch this with my full attention 😊

  • @JonathanLuticia
    @JonathanLuticia Рік тому

    Hi guys, awsome demo and product! It would be so great to see you guys working together with the opensource tool Elastic in order to integrate with each other!

  • @SlingerJames
    @SlingerJames 3 місяці тому

    Is part 2 of this video available on UA-cam?

  • @HitemAriania
    @HitemAriania Рік тому

    used the tool for a long time, its amazing! unfortunately i dont do hunts anymore - which i would love to get back to :)

  • @squid13579
    @squid13579 Рік тому +4

    Time stamps would be better. But amazing video 🔥.

    • @_JohnHammond
      @_JohnHammond  Рік тому

      Big thanks to @iamkingsage8571, they knocked them out for us!

  • @ericmoore4515
    @ericmoore4515 11 місяців тому

    Hello. Have you experienced small customers installing Velociraptor? I'm asking because we did a POC for a start-up company and now they wish to deploy it in production.

  • @bbelsito
    @bbelsito Рік тому +2

    Clever girl

  • @Headh0t549
    @Headh0t549 Рік тому

    Can you consider making a updated "setup a hacking lab"?
    Pros and cons with virtual machines on a local hypervisor vs for instance VPS and cloud vms etc

  • @Yorak404
    @Yorak404 Рік тому

    I wanna learn about digital forensics in MacOS & malware analysis does anyone know any good courses (freee) or cheap certs & courses & or resources please?

  • @Felttipfuzzywuzzyflyguy
    @Felttipfuzzywuzzyflyguy Рік тому

    Clever Girl...

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Рік тому

    Liters size

  • @rpt3066
    @rpt3066 Рік тому

    can't wait more for @mgreen27