If you had 90 minutes to deliver "Foundations in Digital Forensics" to infosec professionals, what would you include? #DFIR
11
1
1
@sibertor "Hire a professional. Don't f--- with s--- on your own." Eh, I suppose that's not what they want to hear.
1
2
@hal_pomeranz I like that! I can soften the message a bit ;P but addressing the "brittleness of forensic artifacts" is a great idea!
1
1
Replying to @sibertor
@sibertor Maybe also, "Capture memory before you turn it off!"

Apr 10, 2015 · 3:18 PM UTC

1
1
Replying to @hal_pomeranz
@hal_pomeranz @sibertor I guess my live linux boot CD with kik-rad ram dump tool isn’t going to be all that useful after all. ;-)