12.07.2013 Views

DFIR SANS360 Talks

DFIR SANS360 Talks

DFIR SANS360 Talks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Path-Based Analysis<br />

• Lets you instantly determine if a particular<br />

registry path exists in any number of hives<br />

• Great for detecting the presence of malware<br />

samples, rogue software, specific USB devices…<br />

• If you were given 20 computers and wanted to<br />

know which of them had a particular service<br />

installed or used a specific wireless network, how<br />

would you do it?

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!