Introduction to Forensics

Kyle Rankin

Senior Systems Administrator

QuinStreet Inc.

Author of Knoppix Hacks, Knoppix Pocket Reference, Linux Multimedia Hacks, and Ubuntu Hacks


http://greenfly.org/talks/security/forensics.html

Agenda

What is Forensics

MAC Times

Order of Volatility

Before You Do Anything

Sleuthkit and Autopsy

Our Sample Image

A Forensics Walk-through

Demos are always dangerous...

Questions?

Additional Resources