YoVDO

OS Analysis with RegRipper

Offered By: Pluralsight

Tags

Penetration Testing Courses Cybersecurity Courses Incident Response Courses Forensic Analysis Courses Data Exfiltration Courses

Course Description

Overview

RegRipper is an open-source application for extracting, correlating, and displaying specific information from Windows Registry hive files. In this course, you will learn to detect adversary activity on a Windows host using RegRipper.

Windows Registry analysis is a fundamental step during any incident response scenario, as it provides conclusive evidence needed to support or deny any suspicious activity on a Windows system. In this course, you’ll cover how to utilize RegRipper to detect adversary endpoint attack techniques in an enterprise environment. First, you’ll demonstrate the RegRipper plugins which are a unique approach for Registry analysis. Next, you’ll operate RegRipper to run against various registry hives using a custom set of plugins. Finally, you’ll analyze Windows Registry to detect adversary activity on a Windows host. When you’re finished with this course, you’ll have the skills and knowledge to detect these techniques: Create or Modify System Process (T1543), Boot or Logon Autostart Execution (T1547), Exfiltration Over Physical Medium (T1052), using RegRipper.

Taught by

Shoaib Arshad

Related Courses

DNA Decoded
McMaster University via Coursera
Investigación en Informática Forense y Ciberderecho
University of Extremadura via Miríadax
Setting up a Forensic Workstation
Pluralsight
Enumerating the Network Infrastructure as a Forensics Analyst
Pluralsight
Architecting with Google Kubernetes Engine: Production 한국어
Google Cloud via Coursera