Open Source Forensic Threat Hunting

May 25, 2021

In this session I will demonstrate the use of open source software Judge Jury and Executable to acquire forensic data into a database where we will perform threat hunting queries. The queries will cover useful data points such as digital signatures, imphash, compile time, YARA, file type, file owner, along with NTFS and MFT timestamps. After crafting a query we will review results to hunt for suspicious files.

Would you like to speak to an advisor?

How can we help you today?

Image
field-guide-cloud-list-image@2x.jpg
Cybersecurity Field Guide #13: A Practical Approach to Securing Your Cloud Transformation
Image
OptivCon
Register for an Upcoming OptivCon

Ready to speak to an Optiv expert to discuss your security needs?