Finding and Decoding Malicious PowerShell Scripts

Malicious PowerShell scripts are becoming the tool of choice for attackers. Although sometimes referred to as “fileless malware”, they can leave behind forensic artifacts for examiners to find. Learn how to locate and identify activity of these malicious PowerShell...

Massively Parallel Forensics with Turbinia

Turbinia, an open source project to allow for massively parallel forensic artifact extraction, was demonstrated at OSDFCon 2015. Three years later, what was originally a limited (albeit functional) tech demo has evolved into a platform capable of automatically...

Unfolding an Investigation Using Forensic Tools and Techniques

This is a 3 hour long, fast-paced forensics challenge where participants will work in teams and perform memory and hard drive analysis to solve an investigation. Students will be provided with forensic workstations loaded with free, open source tools like autopsy and...