Using osquery for remote forensics
blog.trailofbits.com | blog | #incident-response | #dfir | #digital-forensics | #osquery | #ntfs | #timestomping
Summary
Trail of Bits and Crypsis demonstrate osquery as a remote forensics tool: the NTFS extension surfaces $SI vs $FN timestamp mismatches revealing timestomping and directory entries of deleted files.
- Published
- Collected
Skip to content