- Samir EnnaasInternet Initiative Japan Inc.A Crash Course of Practical Fast Forensics with a Red Teaming Perspective for Knowing Your EnemyCody NelsonAugust 5 - 8, 32 Credit Hours

Samir Ennaas
Internet Initiative Japan Inc.
A Crash Course of Practical Fast Forensics with a Red Teaming Perspective for Knowing Your Enemy
Cody Nelson
August 5 - 8, 32 Credit Hours
A Crash Course of Practical Fast Forensics with a Red Teaming Perspective for Knowing Your Enemy
Samir Ennaas
Attendees will first attack a Windows domain network consisting of Windows 11 22H2 and Windows Server 2022 with in-the-wild targeted attack malware and a post-exploitation framework using the same techniques as attackers such as:NTLM Relay AttackGolden/Silver/Diamond Ticket AttackDCSync and DCShadowCredential HarvestingRemote Code Execution/LogonThen, they will acquire various artifacts from the environment and analyze them with DFIR techniques such as:Memory ForensicsLive Response/ForensicsPersistence AnalysisProgram Execution Artifacts AnalysisEvent Log AnalysisTimeline AnalysisTriage CollectionYou will learn how attacks work and how to detect them, so you will have a better understanding of both. Finally, even if new attacks emerge, you will already know how to evaluate and detect them yourself after completing this course.We will be waiting for you with numerous exercises!
Skills / Knowledge
- Malware
- Forensics
Issued on
August 8, 2023
Expires on
Does not expire