SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsBaselining is an important tool for troubleshooting, audit, incident response and forensics. It involves documenting the features of a known good state of a system. This can be used to do a comparative analysis of the current system state to determine what has changed and how it was changed. In practice, doing a complete and documented system baseline can be time consuming and cumbersome and is infrequently done. The goal of this paper is to highlight a pair of tools and a methodology that can provide the ability to baseline a Windows system in a more complete manner across a number of areas. More importantly, the methodology will demonstrate the ability to do a quick, effective comparative analysis of a baseline and the current state to determine what has changed.