Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Incident Response and Computer Forensics on Rootkits

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
2,224
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jun 27, 2011

Lets pick up where we left off with the rootkit and post-exploitation video (http://www.youtube.com/watch?v=izv1b-BTQFw). Except, we are now doing incident response.

First you'll see some normal live forensics on the victim and come up with nothing. Then we show how using network forensics techniques (looking at the victim from the outside) we start to see clear evidence of "doh! we've been owned".

We walk through how to see these signs and prove to them that what Windows and traditional forensics is telling them is a LIE in this particular investigation.

You'll learn how to do this type of forensics technique and many more from our InfoSec Institute Computer Forensics Boot Camp: http://www.infosecinstitute.com/courses/computer_forensics_training.html

  • likes, 1 dislikes

Link to this comment:

Share to:
see all

All Comments (4)

Sign In or Sign Up now to post a comment!
  • hxdef allows placing the listenener as a mitm on an existing port...a much better ide

    a

  • good vid, when is the next video?

  • Why you telling the enemy this shit!!!!!!!!!!!!. ffs.

  • Nice Vid !!!

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more