Introduction to Redline

Поділитися
Вставка
  • Опубліковано 7 жов 2017
  • As a continuation of the “Introduction to Memory Forensics” series, we’re going to take a look at Redline - a free analysis tool from FireEye that allows us to analyze a potentially compromised Windows system. Redline can collect memory and disk-based artifacts, including all running processes and drivers from memory, file system metadata, registry data, event logs, network information, services, tasks, and web history. The software provides an easy-to-use GUI interface that can help us analyze the collected data to find evil on a given system.
    We’ll start with an overview of Redline collectors, and then we’ll create a collector and save it to a USB flash drive. We’ll then run that collector on our target Windows 10 VM and bring the results back to the analysis VM where we’ll briefly look at each category of collected forensic data.
    Introduction to Memory Forensics:
    • Introduction to Memory...
    Redline:
    www.fireeye.com/services/free...
    Redline User Guide:
    www.fireeye.com/content/dam/f...
    #Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics #MemoryForensics #MalwareAnalysis #Malware
  • Наука та технологія

КОМЕНТАРІ • 39

  • @ChrissssOfficial
    @ChrissssOfficial 28 днів тому

    your content is amazing man. Seriously. Thanks!

  • @TheKiller7276
    @TheKiller7276 6 років тому

    Another good video. I look forward to the next one.

  • @SilentKoala
    @SilentKoala 5 років тому +1

    This video is very clear to understand / follow...

  • @IBITZEE
    @IBITZEE 5 років тому +1

    Another great video...
    Thanks---
    a bit long... but I couldn't stop watching...

  • @Taskdriper
    @Taskdriper 6 років тому +1

    really great piece of content

  • @CatSmiling
    @CatSmiling Рік тому +1

    amazing as usual

  • @FahadAldosary
    @FahadAldosary 6 років тому +1

    Thanks you are always great.

  • @shahidkhan-pl1dn
    @shahidkhan-pl1dn 3 роки тому +3

    24:18 Now we have options for mac OSX and linux as well

  • @Eskimoz
    @Eskimoz 4 роки тому

    Belle réalisation !

  • @inokentiy_potapuch
    @inokentiy_potapuch 4 роки тому +1

    Thanks!

  • @subhamoyguha3481
    @subhamoyguha3481 5 років тому

    nice.. please make more details video about it.

  • @alanharper5087
    @alanharper5087 2 роки тому +1

    Good stuff Rich. Please consider creating a module for extracting passwords and using mimikatz.

  • @sumitbhat5961
    @sumitbhat5961 5 років тому +2

    how to take image while doing live forensics and window OS screen is locked?

  • @4n6wizard
    @4n6wizard 6 років тому

    I have been running Redline since 0930 today in a Mac laptop with Windows 10 Pro on it, is taking more than an hour and is not done yet, hopefully it will be done soon then ill run Ostriage to capture the RAM again to compare the results. One con in my opinion is that it take to long if I have to capture RAM from a life box in a crime scene.

  • @lukemallett7964
    @lukemallett7964 6 років тому +1

    What other tools could you use during the analysis section, if you just wanted to use redline for memory collection? (any FOSS for example?)

    • @13Cubed
      @13Cubed  6 років тому +5

      Volatility, Rekall, etc., but I wouldn't use Redline Collectors unless I was going to analyze the data with Redline. You could use FTK Imager, Belkasoft RAM Capturer, DumpIt, or any number of other tools to acquire memory.

    • @lukemallett7964
      @lukemallett7964 6 років тому

      13Cubed wow such swift response Thankyou!

    • @user-jn7bd1lv1s
      @user-jn7bd1lv1s 9 місяців тому

      @@13Cubed Can we collect Memory image through FTK Imager. My Prof has always recommended Red Line and Volatility for Memory image.

  • @davidm1635
    @davidm1635 3 роки тому +1

    Time for a refresh, redline 2.0 (4/28/20)

    • @13Cubed
      @13Cubed  3 роки тому

      Good point. I'll add that to the suggestion list.

  • @4n6wizard
    @4n6wizard 6 років тому

    Great video, do you mind making a memory analysis video using FTK imager?
    Thanks

    • @13Cubed
      @13Cubed  6 років тому +1

      FTK Imager can be used to acquire memory, but not to analyze it. Redline, Volatility, Rekall, etc. would be better suited for that task. FTK could be used, but I don't have a personal license for that software, and generally stick with open-source (free) tools, or lesser expensive tools that can be utilized by many.

    • @4n6wizard
      @4n6wizard 6 років тому +2

      Have you ever use OsTriage? Is pretty much the same concept the .exe have to be run from the USB, It seem to me that after running OsTriage on a life box I get a lot of information from the RAM just like Redine, I'm going to give it a try for sure.
      Very nice video keep up the great work, you are very knowledge.

  • @maymotto
    @maymotto 6 років тому +1

    can anyone offer advice? ive created a .dmp file with DumpIt and a .raw file with Magnet RAM Capture. When analysing the .raw file in redline i can get a lot of information, but when trying to analyse the .dmp there is no information at all. Any adivce?

    • @13Cubed
      @13Cubed  6 років тому

      What version of Redline are you running? Have you watched the "Introduction to Redline - Update" video? That may be of interest to you.

    • @maymotto
      @maymotto 6 років тому

      Hi, thanks for your reply. I am running version 1.20.1. I haven't watched that I will check it out.

    • @13Cubed
      @13Cubed  6 років тому

      Hmm. That is the new version that corrected many of the issues I had (including no results when analyzing certain captures). Can you try to obtain a memory capture with FTK Imager and see if you get the same results? If both FTK and Magnet's tools work, I would point the finger at DumpIt.

    • @maymotto
      @maymotto 6 років тому

      I've tried with FTK and Encase and both seem fine. Also tried another dump with DumpIt and Redline still didn't read anything. Probably a problem with DumpIt!

    • @13Cubed
      @13Cubed  6 років тому

      may motto Yep, sounds that way.

  • @user-rm8rx9yb6z
    @user-rm8rx9yb6z 3 роки тому

    Hello sir! Congratulations for the detailed video...I am a student and i have an issue about redline. I have to restore deleted files using redline. Do you know where to search? And how to do that? Thank you in advance!

    • @13Cubed
      @13Cubed  3 роки тому

      Redline is not a data recovery tool. I'm not sure what you are trying to do?

    • @user-rm8rx9yb6z
      @user-rm8rx9yb6z 3 роки тому

      @@13Cubed "Use and analyze Redline by Fireeye. Perform host investigation and find malicious activity through memory and file analysis. Develop a threat assessment profile using the tool" that's exactly the exercise that i have about redline. So far i have found the deleted file through your video, but i am stuck...

  • @manikandanpalanivel5203
    @manikandanpalanivel5203 4 роки тому

    What is -k parameter and what is means

  • @danafellows1542
    @danafellows1542 3 роки тому

    Been trying to watch this video and there is a constant loop of ads playing. I click "Skip Ad" and another starts to play about 10 seconds later. Closed the browser and reopened, same thing. Weird.

    • @13Cubed
      @13Cubed  3 роки тому

      Not sure what's going on there. I don't see any problems on my end. Maybe try an incognito/private browsing session, or a different browser?

  • @Glen_Tyson
    @Glen_Tyson 8 місяців тому

    I was wondering is there a possibility the file could take longer than an hour to run? At the two hour mark now and not sure if it’s right or not

    • @13Cubed
      @13Cubed  8 місяців тому

      Hard to say, but I've seen this take quite a while.