PLAY PODCASTS
2015-028: using log analytics to discover Windows malware artifacts

2015-028: using log analytics to discover Windows malware artifacts

BrakeSec Education Podcast · Bryan Brake

June 29, 201544m 49s

Audio is streamed directly from the publisher (traffic.libsyn.com) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.

Show Notes

In this podcast, you'll learn about:

Log analytics software that can be used to parse system logs for naaty malware

Detecting Malware artifacts

learn about windows directory locations

looking for indicators like packing, changed hashes, etc

Tips for capturing malware using tools like RoboCopy

Learn about what code caves are and how malware hides inside them (http://www.codeproject.com/Articles/20240/The-Beginners-Guide-to-Codecaves)

SANS DFIR poster - https://www.sans.org/security-resources/posters/windows-forensics-evidence-of-75