You have likely heard of Velociraptor - the leading open source DFIR platform! Velociraptor provides unprecedented deep visibility into the endpoint with an impressive number of built in and community contributed analysis modules.
With all the capabilities that Velociraptor comes with, it can be hard to know exactly which artifact to collect when responding to any one situation. This can be even harder when the clock is ticking while containing an incident!
In this real world, practical walk through of Velociraptor, Mike Cohen, the main developer of Velociraptor will work through a typical DFIR investigation: Detecting and containing an attacker who gains a foothold on a network. We will examine techniques for hunting at scale for the attacker to identify their foothold and reconstruct the event timeline. We then detect attacker persistence to prevent re-infection. Finally we remediate the network by removing the adversary's access.
Join us to gain a practical understanding of core capabilities of Velociraptor, and how it can be leveraged to quickly identify and contain attackers.