使用 osquery 进行远程取证
blog.trailofbits.com | 博客 | #incident-response | #dfir | #digital-forensics | #osquery | #ntfs | #timestomping
摘要
Trail of Bits 与 Crypsis 演示用 osquery 开展远程取证:其 NTFS 取证扩展可对比 $SI 与 $FN 两套时间戳识别“时间戳篡改”反取证手法,还能通过目录项残留定位已删除文件的痕迹。
- 发布时间
- 收录时间
Skip to content