Getting Started with the SIFT Workstation Webcast with Rob Lee

preview_player
Показать описание


Speaker Bio

Рекомендации по теме
Комментарии
Автор

Here are some video checkpoints for the lazy folk.

Getting Started with SIFT 2:30
Downloading SIFT 8:42
Mounting Disk Images 19:59
Volume Shadow Examinations 26:48
Creating Timelines via SIFT 35:58
Memory Analysis via SIFT 39:40
Registry Examinations 43:07
Cheatsheets 49:59
Questions 1:00:50

brandonjacksoncybersecurity
Автор

Hello, where can we download some sample .E01 case files from?

ethicalsecurities
Автор

Excellent, gives a real sense of what can be done with Sift if you know how. Well done- this is a very professional presentation I look forward to more.

johncronin
Автор

the cases folder is empty on my end, and i do not have cases on my macbine. im new to this !

vincentavila
Автор

can some tell me where to download the case file when I went to the folder its empty

mastertcs
Автор

What's going on with authentication to the SIFT download page? It's not taking my credentials yet I can log into the SANS site just fine with the same credentials.

bryanmccaffrey
Автор

what if my file is a FAT32 instead of a ntfs file?

deathtoy
Автор

Excellent video, could anyone please tell me, why we are mounting the raw image(.E01) to ewf_mount and from there we are mounting to windows _mount. Why we are unable to mount the (.E01) file directly to windows _mount ?? Thanks in advance

iloveyou
Автор

Once I run in my virtual machine the ifconfig command, it is not showing an ip address where i can connect to download the sample files

seans
Автор

I love it when you think plural...other things slow down a fraction of a second. when stuff like passwords irritate you :)

chrisfrazier
Автор

Can someone please explain?

Command 'vshadow' not found, did you mean:

command 'shadow' from deb golang-golang-x-tools

Try: apt install <deb name>

sinisahusnjak
Автор

Can it be installed on my windows 10 turned into Parrot Sec. uname -a=Linux parrot 5.2.0-2parrot1-amd64 #1 SMP Debian 5.2.9-2parrot1 (2019-08-25) x86_64 GNU/Linux

JKY-
Автор

Great stuff, anyone tell me how to recover deleted files from RECYCLER in Windows XP *.dd image as evidence?

arsyeedutube
Автор

What is the difference between SIFT and Kali Linux?

jeffreyz
Автор

Бляя, автор сделай на русском. Я по английски не шарю

ДенисМедведев-оф
Автор

Excellent video, could anyone please tell me, why we are mounting the raw image(.E01) to ewf_mount and from there we are mounting to windows _mount. Why we are unable to directly mount the (.E01) file to windows _mount ??

iloveyou