Talk With an Expert

Putting it all together through Automation

Putting it all together through Automation (PDF, 3.94MB)Published: 22 Apr, 2019
Created by:
Kenneth Ray

Most problems faced in Information Security are typically time sensitive. For Forensic Engineers and Analysts, it's not the problem related to when a Forensic Analyst has a local physical drive in hand; rather the problem is how quickly they can obtain forensic evidence to support or disprove data exfiltration, exploitation, or infection when the system is not locally accessible. Most times this requires remote collection and, in some cases, covert data collection. This paper will explain methods to automate collection using scripts and functions formatted mostly in PowerShell to accomplish goals. This paper will include the heavily commented version of the Yet Another Forensic Tool(YAFORTO). Where possible, prerequisites will be identified to alleviate failures already discovered during the development and testing of the scripts and functions.

Putting it all together through Automation