← All talks

Black Mirror of Execution: How new artifacts have changed the 'O' and the 'D'

BSides Augusta · 201754:12192 viewsPublished 2017-09Watch on YouTube ↗
Speakers
Tags
CategoryTechnical
StyleTalk
About this talk
BSides Augusta 2017 Alissa Torres (@sibertor) Black Mirror of Execution: How new artifacts have changed the 'O' and the 'D' Windows tracks system/user activity with growing sophistication and granularity. Let's walk through some of this forensic evidence of execution that few examiners know about and seldom used by such a Srum, AmCache and SCCM data. Alissa will dissect 4 case studies where these newly identified artifacts cracked the case and unlocked the story of what happened on the system, and who did it and when.