Introduction to Forensics

Kyle Rankin

Systems Architect

QuinStreet Inc.

Author of Knoppix Hacks, Ubuntu Hacks, and The Official Ubuntu Server Book


http://greenfly.org/talks/security/forensics.html

Agenda

What is Forensics

MAC Times

Order of Volatility

Before You Do Anything

Sleuthkit and Autopsy

Our Sample Image

A Forensics Walk-through

Demos are always dangerous...

Questions?

Additional Resources