7MS #299: Windows System Forensics 101 episode artwork

EPISODE · Feb 28, 2018 · 10 MIN

7MS #299: Windows System Forensics 101

from 7 Minute Security · host Brian Johnson

I had the privilege of creating a Windows System Forensics 101 course/presentation for a customer. The good/bad news is there is so much good information out there, it's hard to boil things down to just an hour. For the first part of the presentation, I focused on Mark Russinovich's technique of using Sysinternals as the primary surgical tool. This approach includes things like: Use Process Explorer to find processes with no signature and/or description. Put any suspicious processes to sleep before killing them (it's more humane! :-) Use autoruns to find registry entries, scheduled tasks, etc. that might be hooked to malicious executables that run on startup. Rinse and repeat. In part 2 (coming up soon!), I'll continue the forensics fight and talk about tools like Redline, Volatility and FTK Imager! Stay tuned.

Episode metadata supplied by the publisher feed · Published Feb 28, 2018

Embed this episode

NOW PLAYING

7MS #299: Windows System Forensics 101

0:00 10:54

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of 7 Minute Security?

This episode is 10 minutes long.

When was this 7 Minute Security episode published?

This episode was published on February 28, 2018.

Can I download this 7 Minute Security episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!