Тёмный

Windows Forensics: Event Trace Logs - SANS DFIR Summit 2018 

SANS Digital Forensics and Incident Response
Подписаться 72 тыс.
Просмотров 18 тыс.
50% 1

Опубликовано:

 

1 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 17   
@sabsy7
@sabsy7 4 года назад
Learnt a lot of stuff from this video. Would have been a lot better listening experience if the speaker wasn't chewing while talking.
@RockNrola99
@RockNrola99 3 года назад
unbelivable!!!
@osmaster3327
@osmaster3327 4 года назад
Seriously ? Chewing gum while lecturing ?
@Lortz2610
@Lortz2610 3 года назад
Yeah. Who cares?
@joeneighbor
@joeneighbor 5 лет назад
You rock! Best ETW presentation I've seen. Cuts through a lot of the hype, buzz/tech-words, sumerizes, and gets to the point of where some of the ETW .etl files are and how to properly view them et al. The PDF lead me to her talk: www.sans.org/cyber-security-summit/archives/file/summit-archive-1528388048.pdf A related great post of hers too: www.hecfblog.com/2018/06/etw-event-tracing-for-windows-and-etl.html?m=1
@kantnklaar
@kantnklaar 5 лет назад
4:54 "Because Windows progresses right?! They're not gonna stick with old technology from 2000" Microsoft: (ö ö) ......(ő ő)............
@hamadaljassmi3954
@hamadaljassmi3954 5 лет назад
well windows don't have root it's called superuser :)
@lulujrlaulom7905
@lulujrlaulom7905 3 года назад
i have been doing research with ETL files for 3 years now... i found a way...
@morr8842
@morr8842 4 года назад
Hi there, Please, do you have researches related to Windows performance analysis?
@michaelmelanson7345
@michaelmelanson7345 2 года назад
Thank you for this talk! I'm wondering if the BootCKCL.etl file has been deprecated. I've looked on Window 11 and a couple of Windows 10 VMs. What I am seeing in WDI\Logfiles\ is BootPerfDiagLogger.etl which mmaayyyyy be the replacement? Also there is a StartupInfo folder at this location that contains a number of XML files with the user SID _StartupInfox.xml where x is a sequential number. In any event, looks like some stuff has changed.
@LadyLatency
@LadyLatency 4 года назад
/i cant believe there posting free content
@ya-asmr
@ya-asmr 5 лет назад
Where can we download ETL Viewer shown to us?
@Nicole-iu2lc
@Nicole-iu2lc 5 лет назад
Unfortunately, the viewer isn't publicly available. You can download the command line tool we released. It outputs the data to a CSV file and an SQLite database. Find it here: github.com/gcpartners/ETLParser
@lulujrlaulom7905
@lulujrlaulom7905 3 года назад
@@Nicole-iu2lc we should talk.
@mandowall
@mandowall 4 года назад
SANS
@Jay-hr9ci
@Jay-hr9ci 4 года назад
What I don't get is why don't the companies who make Hard Drives, Operating Systems, etc make the tools and support law enforcement? They obviously know all the ins/out of the environment.
@mannygar6705
@mannygar6705 4 года назад
Good Information, maybe next time someone should remind the presenter that chewing gum during a presentation may not be a good idea
Далее
I Took An iPhone 16 From A POSTER! 😱📱 #shorts
00:18
🛑самое главное в жизни!
00:11
Просмотров 132 тыс.
小路飞嫁祸姐姐搞破坏 #路飞#海贼王
00:45
The Event Viewer, Explained (It's a mess)
10:21
Просмотров 20 тыс.
Introduction to ETW
23:11
Просмотров 2,1 тыс.
Threat Hunting via Sysmon - SANS Blue Team Summit
51:01
Network Security - Deep Dive Replay
3:08:19
Просмотров 161 тыс.
I Took An iPhone 16 From A POSTER! 😱📱 #shorts
00:18