Docker Detection and Forensics, ‘Gotta catch them all’!

Adopting Docker containers works well for most fast moving orgs, due to flexibility, isolation, transient existence, ease of management and patching. On the other hand, it becomes a challenging environment when the sensitivity level of the data traversing the...

The osquery File Carver

Osquery is a cross platform open source agent designed to pull system telemetry without modifying system state of the host. This observe and report premise has served us well but as our needs and security goals change so must the demands we make of our tools. In 2017...

Turbinia: Automation of Forensic Processing in the Cloud

Ever wanted to do forensics and feel good about it? This talk will introduce you to Turbinia: A forensic tools automation framework for the cloud. Throughout this talk, we’ll reveal the details of how Turbinia operates, showing how tools like dftimewolf can integrate...

MacOS Host Monitoring – The Open Source Way

MacOS host monitoring – the open source way, I will talk about a example piece of malware(Handbrake/Proton) and how you can use open source tooling detection tooling to do detection and light forensics. Since I will be talking about the handbrake malware, I will...