Help required in order to investigate

This page summarizes the projects mentioned and recommended in the original post on /r/computerforensics

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • EventFinder2

    Finds event logs between two time points. Useful for helpdesk/support/malware analysis.

  • You might want to start by using something to build a timeline around the hour that you have to look at. You can use this to extract ALL evtx logs from that timeframe and put them in temporal order. If you aren't used to digging through these though, you're going to find a lot of things that look suspicious, but aren't. You'll have to do some baselineing for what is in your environment. https://github.com/BeanBagKing/EventFinder2

  • sysmon-config

    Sysmon configuration file template with default high-quality event tracing

  • In the future, capture memory first. Everything else won't just disappear, memory is gone once you shut the machine down though. Also, look at increasing the logging on your systems. Use sysmon / https://github.com/SwiftOnSecurity/sysmon-config, enable firewall logging, enable command line logging, etc. I'll try to do a post on baseline logging, keep an eye on nullsec.us for the next article.

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts