#LearnDFIR to score your KAPE #DFIR data with Cyber Triage. Quickly identify processes, startup items, and remote logins that are suspicious. Blog post also shows how the Cyber Triage collection tool and KAPE are similar, but different.
cybertriage.com/blog/analyzi…
#LearnDFIR from Joseph Edwards at #ResponderCon as he talks about how LNK and ISO files are used to deliver #Ransomware attacks. The talk covers how attackers make the payloads and what the files do so that an attack can start.
youtube.com/watch?v=3Hpb6oVk…
#LearnDFIR from @keydet89 at #ResponderCon as he talks about all of the other things to worry about during a #Ransomware attack besides the encryption EXE. Learn about what living off the land commands to watch out for or disable.
youtube.com/watch?v=OJ4U3ZBN…