The Most/Recent Articles

Showing posts with label dfir summit. Show all posts
Showing posts with label dfir summit. Show all posts

Daily Blog #619: SANS DFIR Summit 2019 CFP is Open!

SANS DFIR Summit 2019 CFP is open!



Hello Reader,
             A quick reminder that the 2019 SANS DFIR Summit call for presentations is open!

https://www.sans.org/event/digital-forensics-summit-2019/call-for-presentations

Happening in Austin, Texas on July 25-26, 2019 the SANS DFIR Summit has some of the best presentations of the year. We look forward to this event everywhere as usually there is some new tool or research shown here that we can use immediately in our lab.

Also, if selected, not only do you get a free ticket to go to the summit... you also get a free ticket for a friend!

Also Read: Daily Blog #618

Daily Blog #387:Forensic Lunch 6/8/18 - Live from the DFIR Summit

live from the DFIR Summit by David Cowen


Hello Reader,

           It's Friday which means I'm either posting a Forensic Lunch or a Test Kitchen video. This week it's a Forensic Lunch we recorded live from the DFIR Summit. I apologize for the background audio but hopefully you'll find this rundown of what to expect from the talks that are being uploaded from the DFIR Summit to Youtube!

On this broadcast we had Lee Whitfield, Rob Lee, Matt Seyer and myself talking about the DFIR Summit!



Forensic Lunch 3/20/15 - James Carder and Eric Zimmerman

Forensic Lunch 3/20/15 - James Carder and Eric Zimmerman


Hello Reader!,
           We had another great Forensic Lunch! This broadcast we had:

James Carder of the Mayo Clinic, @carderjames, talking all about automating your response process to separate the random attacks from sophisticated attacks. You can hear James talk about this and much more at the SANS DFIR Summit where he'll be a panelist! If you want to work with James Mayo Clinic is hiring.

Mayo Clinic Infosec and IR Jobs: http://www.mayo-clinic-jobs.com/go/information-technology-engineering-and-architecture-jobs/255296/?facility=MN
Contact James Carder: carder.james@mayo.edu

Special Agent Eric Zimmerman of the FBI, @EricRZimmerman , talking about his upcoming in depth Shellbags talk at the SANS DFIR Summit as well as his new tool called Registry Explorer. RE and Eric's research into windows registries will be continued in the next broadcast. Whether you are interested in registries from a research, academic or investigative perspective this is a must see, and FREE, tool!

Eric's Blog: http://binaryforay.blogspot.com/
Eric's Github:https://github.com/EricZimmerman
Registry Explorer: http://binaryforay.blogspot.com/p/software.html


You can watch the broadcast here on Youtube: https://www.youtube.com/watch?v=lj7cMHySGSE

Or in the embedded player below:



Daily Blog #352: Slides from SANS DFIR Summit

Slides from SANS DFIR Summit by David Cowen - Hacking Exposed Computer Forensics Blog

Hello Reader,
        Thanks to those of you who attended our talk 'Best finds of 2014'. I hope you walked away with some new artifacts and techniques that you can use in your investigations today. For those who couldn't attend the SANS DFIR Summit I have good news, this year they recorded all the sessions and they will be uploaded to Youtube! So while you can see the slides now they won't really explain everything we said in an hour until you see the video.

With all that said, I'm happy with the work we've done and hope you get some good use out of it! Here are the slides:https://drive.google.com/file/d/0B_mjsPB8uKOAcWZobUJvTjRYMk0/edit?usp=sharing

Also Read: Daily Blog #351

Daily Blog #347: SANS @Night Presentation

SANS @Night Presentation - David Cowen


Hello Reader,
               This post is for those of you who came to see my SANS @Night presentation at the DFIR Summit. I hope you enjoyed it and I've gotten you excited about file system journaling forensics. You can find the slides here:

https://drive.google.com/file/d/0B_mjsPB8uKOAdHRGdnJaTmdfQ3c/edit?usp=sharing

Also Read: A quick note on Shellbag analysis in Windows 7/8

Daily Blog #284: SANS Webcast

SANS Webcast by David Cowen - Hacking Exposed Computer Forensics Blog

Hello Reader,
            I'll be doing a SANS Webcast Tuesday April 8th at 1PM EST / 12:00PM CST on my talk for the SANS DFIR Summit 'best finds of 2014'. Tune in to get a preview and your chance to ask me questions! For information about the SANS DFIR Summit, click here!

Register for the webcast here:
https://www.sans.org/webcasts/finds-dfir-2014-97965

Also Read: Daily Blog #283

Daily Blog #268: SANS DFIR Summit details

SANS DFIR Summit details by David Cowen - HECF Blog

Hello Reader,
            You may have seen on Sunday's post some information about my upcoming talk at the SANS DFIR Summit. I thought I would spend some time this week talking about each of the events I'll be talking about in detail so you can set your expectations on which event you'd like to see me at the most (or all of them!). I try to always talk about something different at the major events to keep things interesting for both of us. I also always put my slides up from the event here on the blog, maybe one day they'll let me put up recordings of the talks as well!

Click here to learn more about the event and see the schedule.

Today I wanted to focus on the SANS DFIR Summit as they choose a topic I submitted and was hoping they would like called 'Best Finds of 2014'. I'll be speaking on the first day at 1:45pm in Track 2. I'm excited about this talk because of the huge amount of space SANS has granted me to operate within the topic. Typically when I submit a topic to a CFP I have to choose one particular aspect of our research and focus on it for an hour, which you'll see me doing at other conferences this year. This topic though let's me really show you a wider survey of whats really cool and more importantly forensically useful from a whole years worth of research. I'll be hitting the highlights through all of the best artifacts we've covered here in the blog and those that we've only talked about during the Forensic Lunch.

I've found continued success in our own cases this year with the artifacts and analysis techniques I'll be showing this year and I'll give case citations to those of you who need to support using new artifacts by proving their use in past cases. My citations will be for US Civil courts (state and federal) so for those of you on the criminal side you'll likely have to do more validation. So I'm very confident in the utility of these artifacts having used them and defended them in court and achieving great results for our clients.

Here is the list of topics I proposed back in January:
 
  • Detecting writes to NTFS disks with the ntfs-3g driver
  • Recovering MTP access
  • Outlook attachment access through USN Journals
  • Artifacts from renaming accounts in Windows 7
  • Using task scheduler logs to recover past login
I'll be adding more to that list as we just keep finding more cool stuff! I love forensics, if you couldn't tell, and there is still so much we don't know that can lead to conclusive results and findings.

In addition to all of that SANS has made buying a ticket to the event much more affordable. If you use the discount code 'SUMMIT' now through March 31, 2014 the cost of a ticket will drop by $1,000. So the two day SANS DFIR Summit would just be $495 which includes great technical presentations (no sales pitches here) and lots of fun and socializing with your fellow forensic friends.

If that is still too much for your training budget you can still win a free pass to the event in upcoming Sunday Fundays so you have lots of opportunities to come down to Austin this June!

Also Read: Daily Blog #267

DFIR Summit 2013 Post

DFIR Summit 2013 by David Cowen - Hacking Exposed Computer Forensics Blog

 Two blogs in one day! Woh! I should have saved this one to fill it in later but I really wanted to make sure those of you sat through our hour of brain dumping had the slides I referenced so you can go over them again.

You can get the slides from today's presentation here:
https://docs.google.com/file/d/0B_mjsPB8uKOAdkxHcHNGRTV0eU0/edit?usp=sharing

If you haven't signed up for the public beta yet, you can do so here and download the latest version of the TriForce:
https://docs.google.com/forms/d/1GzOMe-QHtB12ZnI4ZTjLA06DJP6ZScXngO42ZDGIpR0/viewform

You can download the labs to test on your own here:

https://www.hecfblog.com/2013/05/ceic-2013-and-public-beta-of-ntfs.html

You can grab the whitepaper that solves the CD Burning lab here:
https://www.hecfblog.com/2013/07/daily-blog-13-7613-saturday-reading.html

    To sum up whats different between this talk and the CEIC talk, the CEIC talk was more about the tool and its use. The SANS DFIR Summit talk was more about file system journaling forensics as a practice and the theory for the analysis framework. We extended this from NTFS to EXT3 and HFS+ so we are nowhere close to done.

    My next planned presentation of our research is at PFIC, so if you missed me so far and want to get an in-person explanation this is my next stop until 2014.

http://www.pfic-conference.com/

    Having said that, if you are running a forensic conference and are looking to expand your topics to include our research please email me at dcowen@g-cpartners.com and I'll see if I can fit you into my travel calendar.


Daily Blog #12: DFIR Summit is coming!

DFIR Summit is coming!


Howdy Reader,
      Next week is the DFIR summit and Matthew and I have been told this is supposed to be a very technical conference compared to other forensic conferences. We considered this the gauntlet dropped and have prepared a presentation on the theory and application of journaled file system forensics for NTFS and EXT3 that should cause a few people to walk away confused.

    What's that you say EXT3 journaling? I've talked before about how this was our next focus after NTFS and we do have an alpha parser for EXT3 that does some pretty amazing things, but the triforce lead us back full force into NTFS. But since our work on and subsequent betas of the triforce we've gone back to the EXT3 file system for the summit and we may have found an alternate triforce for EXT3.

    So if you are coming to the DFIR Summit in Austin next week, get your questions ready because Matthew and I are going to be going deep and hard at 9am. Drink lots of coffee Monday morning and we'll see you there!

    For those of you in the Texas area you still have a chance to register !

Also Read: Daily Blog #11