One Week Only! Get an iPad Air with Smart Keyboard, Surface Go, or $300 Off with OnDemand & vLive!

Webcasts

To attend this webcast, login to your SANS Account or create your Account.

Forensic Timeline Analysis Using Wireshark

  • Wednesday, October 25th, 2017 at 10:30 AM EDT (14:30:00 UTC)
  • David Fletcher
This webcast has been archived. You can view the webcast presentation and download the slides by logging into your SANS Portal Account or creating an Account. Click the Register Now button after you have logged in to view the Webcast.

You can now attend the webcast using your mobile device!

Overview

Forensic timelines performed on captured hard disk images create a large volume of output. Organizing and analyzing this information can be challenging for an investigator. Colorization of the timeline can make this task easier but often relies on inflexible single-purpose tools. As an alternative, use of the Wireshark protocol analyzer will be investigated for this purpose. Useful features such as through put statistics, colorization profiles, packet comments, and packet marking will be applied to forensic analysis to illustrate the power of leveraging a mature and flexible application to replace single purpose tools.

Speaker Bio

David Fletcher

David Fletcher is a security analyst with Black Hills Information Security (BHIS). In his current role, he performs a wide array of different penetration testing activities to assist customers in improving their security posture. Before moving to BHIS, David worked for the United States Air Force for twenty-three years. During this time, he worked in a wide array of disciplines including system administration, vulnerability management, boundary defense, web application programming, database programming/administration, installation level network operations, and offensive cyber research and development.

David is a candidate for the Master of Science degree in Information Security Engineering from the SANS Technology Institute.

The SANS Technology Institute is the only graduate program that combines SANS technical training, recognized as the industry's best, with leadership and management curriculum specifically developed for the unique needs of aspiring leaders. Learn more at www.sans.edu.

Need Help? Visit our FAQ page or email webcast-support@sans.org.

Not able to attend a SANS webcast? All Webcasts are archived so you may view and listen at a time convenient to your schedule. View our webcast archive and access webcast recordings/PDF slides.