YoVDO

Putting Together the RDPiece

Offered By: BasisTech via YouTube

Tags

Open Source Digital Forensics Conference (OSDFCon) Courses Data Analysis Courses Digital Forensics Courses PowerShell Courses Incident Response Courses Data Extraction Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the intricacies of ransomware investigations and the often-overlooked RDP Bitmap Cache artifact in this 35-minute conference talk from OSDFCon 2020. Learn how to piece together crucial information about attacker activities, even after cleanup attempts, using the RDPiece tool. Gain insights into extracting and analyzing RDP Bitmap Cache data, understanding its significance in digital forensics, and leveraging PowerShell scripts for efficient investigation. Discover how this underutilized artifact can provide answers to key questions about system access, data exfiltration, and attacker behavior. Benefit from Brian Moran's extensive experience in digital forensics and incident response as he shares his expertise on this evolving field.

Syllabus

Introduction
Title
Topics
Who am I
D for Fit
What is RDP
Why is RDP important
How I got interested in RDP
What is the already pippin bad cache
What is the RDPiece
Location of the files
Cache
Resources
OSDFCon
Extract RDPiece Data
Powershell
Folder Structure
Reorganizing
Math
Starting from scratch
Image Magic
Putting Pieces Together
Generating Data
Script Overview
Test Results
Saving Images
Output
Its not perfect
Open Source
Download Script
Heather
Questions


Taught by

BasisTech

Related Courses

Windows PowerShell Fundamentals
Microsoft via edX
Windows 10 Features for a Mobile Workforce: Managing and Maintaining Devices in the Enterprise
edX
Deploying Your First Resources in Azure
Udemy
Advanced Server 2016 Administration: Hands-on Training
Udemy
Windows Server 2016 Administration
Udemy