Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.
日本語の概要は準備中です。原文の説明を表示しています。
13 件 ・ 関連度順
概要と使いどころ
Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.
日本語の概要は準備中です。原文の説明を表示しています。
Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py, psort.py, and psteal.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then triage and filter the results in Timesketch. Use when reconstructing the full sequence of events on a compromised or forensically imaged host during a DFIR investigation.
日本語の概要は準備中です。原文の説明を表示しています。
Parse Windows Prefetch (.pf) files with the windowsprefetch Python library to reconstruct application execution history, run counts, and accessed file/volume lists. Use when investigating renamed or masquerading binaries, verifying program execution timelines, or hunting for suspicious execution patterns in incident response.
日本語の概要は準備中です。原文の説明を表示しています。
Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.
日本語の概要は準備中です。原文の説明を表示しています。
Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis. References industry-standard tools including Splunk, ELK Stack, and Wireshark. Provides forensic workflow from initial evidence collection through final investigation report. Keywords: digital forensics, breach investigation, evidence preservation, chain of custody, root cause analysis, Splunk, ELK, Wireshark.
日本語の概要は準備中です。原文の説明を表示しています。
Use when a task needs the judgment of a Digital Forensics Analyst — capturing volatile evidence before it's lost, creating and hash-verifying a forensic disk image, documenting chain of custody from point of seizure, correcting for clock skew and timezone mismatches when building a cross-source timeline, or identifying anti-forensic activity (log wiping, timestomping) in an investigation.
日本語の概要は準備中です。原文の説明を表示しています。
Generate log2timeline and Plaso super-timelines and triage them in Timesketch.
日本語の概要は準備中です。原文の説明を表示しています。
Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.
日本語の概要は準備中です。原文の説明を表示しています。
Expert en forensique numérique (disk imaging, memory analysis, network forensics, chain of custody)
日本語の概要は準備中です。原文の説明を表示しています。
Digital forensics v3 — disk imaging, memory analysis, network forensics, chain of custody, legal
日本語の概要は準備中です。原文の説明を表示しています。
Expert en forensique numérique avancée (disk imaging, memory analysis, network forensics, reporting, chain of custody, incident response)
日本語の概要は準備中です。原文の説明を表示しています。
Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.
日本語の概要は準備中です。原文の説明を表示しています。
Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.
日本語の概要は準備中です。原文の説明を表示しています。