DFSP # 428 - It's all about that XML

DFSP # 428 - It's all about that XML

When you're triaging a Windows system for evidence of compromise, it's ideal if your plan is focused on some quick wins upfront. There are certain artifacts that offer this opportunity, and Windows Events for New Scheduled Tasks are one of them. Sometimes overlooked, at least in part, because the good stuff contained within the XML portion of the log. This week I'm covering the artifact from a DFIR point of view, I'll go over all the elements of the log entry that are of interest for investigations, and I'll provide a triage methodology that you can employ to find evidence quickly.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(498)

Suosittua kategoriassa Tiede

rss-mita-tulisi-tietaa
hippokrateen-vastaanotolla
rss-hereilla
tiedekulma-podcast
rss-duodecim-lehti
rss-jyvaskylan-yliopisto
sotataidon-ytimessa
rss-laakaripodi
utelias-mieli
docemilia
filocast-filosofian-perusteet
rss-ranskaa-raakana
rss-vaasan-yliopiston-podcastit
rss-poliisin-mieli
rss-ammamafia