The Hitchhiker’s Guide to Evidence Sources - SANS Webcast

preview_player
Показать описание

When conducting an investigation, knowing where to find the most valuable evidence across a corporate network can be difficult. Many organizations don't consider evidence before an incident occurs, which is especially true for smaller organizations or those which dont experience incidents very often.

So in most cases, were limited to whatever evidence happens to be available; we collect the breadcrumbs we can find.

In this presentation, Nick will discuss the most valuable sources of evidence for several typical investigation types, so you can:

- Identify the value of specific evidence sources across your environment
- Know how forensic investigators use them to reconstruct a breach or other incident

- Start collecting these evidence sources to maximize your ability to investigate when an incident occurs.

Presenter: Nick Klein
Рекомендации по теме