YoVDO

These Artifacts Aren't Fiction

Offered By: YouTube

Tags

Conference Talks Courses Digital Forensics Courses PowerShell Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore a conference talk on digital forensics and artifact analysis, focusing on Windows SRUM database, web browser artifacts, and PowerShell. Learn about data preservation methodology, network resource usage, and investigation tooling. Discover techniques for analyzing memory dumps, parsing history artifacts, and collecting PowerShell artifacts. Gain insights into system time manipulation, file hashing, and less volatile network artifacts. Understand the importance of execution policy settings, clipboard data, auto-runs, and tasks in forensic investigations. Acquire practical tips and tricks for effective PowerShell usage in digital forensics.

Syllabus

Intro
Introducing: Matt Scheurer
Data Preservation Methodology
The Windows SRUM Database
Useful SRUM Data
Network Resource Usage
SRUM Database Conclusions
Web Browser Artifacts
Investigation Tooling
Artifact Sources
Memory Dumps
Example History Artifact Paths
History Parsed Example 4/4
Download Parsed Example 1/2
PowerShell Artifacts Collection
Objectives
Warning!
PowerShell Logging
PowerShell Version
PowerShell Pro Tip!
System Time
Hashing Files
Less Volatile Network Artifacts
Execution Policy Settings
Clipboard, Auto-runs, and Tasks
Host Details
The Open Files Conundrum
More PowerShell Tips & Tricks
Thank you for attending!


Related Courses

Windows PowerShell Fundamentals
Microsoft via edX
Windows 10 Features for a Mobile Workforce: Managing and Maintaining Devices in the Enterprise
edX
Deploying Your First Resources in Azure
Udemy
Advanced Server 2016 Administration: Hands-on Training
Udemy
Windows Server 2016 Administration
Udemy