Summary
Keywords
Full Transcript
In this full series we will talk about Incident Response and it will be a Free Training Course for everyone. Today is Day-20 and we are going to talk about Browser Forensics. Browser Forensics is an important part of any investigation or incident response. There are various artifacts in every browser such as Favicons and Login Data, which could be helpful in exploring the browsing activities of the user. So in today's episode we are going to explore this from scratch and we will cover below things- ✅ Scope and Roles of Browser forensics ✅ Steps to Initiate the Process ✅ What are the common Browser Artifacts? ✅ IMPORTANT: Are we missing anything? Last but not the least, we are going to explore an Open Source Tool named Hindsight which can be used for Internet history forensics for Google Chrome/Chromium. Hindsight is a free tool for analyzing web artifacts. It started with the browsing history of the Google Chrome web browser and has expanded to support other Chromium-based applications (with more to come!). Hindsight can parse a number of different types of web artifacts, including URLs, download history, cache records, bookmarks, autofill records, saved passwords, preferences, browser extensions, HTTP cookies, and Local Storage records (HTML5 cookies). Once the data is extracted from each file, it is correlated with data from other history files and placed in a timeline. So watch the full episode to learn about this technology and aspect of forensics. 🔗LINKs for your requirements- ------------------------------------------------------------------------------------------------------------------------- 1. Hindsight- https://github.com/obsidianforensics/hindsight 🔗Related Episodes- ------------------------------------------------------------------------------------------------------------------------- 1. Autopsy- https://youtu.be/r7Zzf1s73PU 2. Digital Forensics Case Study- https://youtu.be/KYQSrNdNmj4 WATCH BELOW Playlists as well, if you want to make your career in DFIR and Security Operations!! ------------------------------------------------------------------------------------------------------------------------- INCIDENT RESPONSE TRAINING Full Course 👉https://youtube.com/playlist?list=PLjWEV7pmvSa4yvhzNsCjOJovOn1LLyBXB DFIR Free Tools and Techniques 👉 https://youtube.com/playlist?list=PLjWEV7pmvSa6f-NTpXsaUYWZLjLAB_0TS Windows and Memory Forensics 👉 https://youtube.com/playlist?list=PLjWEV7pmvSa50erciZUSnzvE7nK0FyvsH Malware Analysis 👉 https://youtube.com/playlist?list=PLjWEV7pmvSa6u32RongesgDtkfKBfrFWW SIEM Tutorial 👉 https://youtube.com/playlist?list=PLjWEV7pmvSa7cXTkCppnYHERUdy8Dd71x Threat Hunt & Threat Intelligence 👉 https://youtube.com/playlist?list=PLjWEV7pmvSa5UTZlsWp5wRnURNbeMS-fu ⌚ Timelines ------------------------------------------------------------------------------------------------------------------------- 0:00 ⏩ Introduction 1:10 ⏩ Agenda 2:26 ⏩ Scope & Role 7:15 ⏩ Steps to Initiate 10:45 ⏩ Common Browser Artifacts 14:47 ⏩ IMPORTANT: What we miss? 19:17 ⏩ Hindsight Demo 27:54 ⏩ Summarize 📞📲 FOLLOW ME EVERYWHERE- ------------------------------------------------------------------------------------------------------------------------- ✔ LinkedIn: https://www.linkedin.com/company/blackperl ✔ You can reach out to me personally in LinkedIn as well- https://bit.ly/38ze4L5 ✔ Twitter: @blackperl_dfir ✔ Git: https://github.com/archanchoudhury ✔ Insta: (blackperl_dfir)https://www.instagram.com/blackperl_dfir/ ✔ Can be reached via [email protected] SUPPORT BLACKPERL ------------------------------------------------------------------------------------------------------------------------- ╔═╦╗╔╦╗╔═╦═╦╦╦╦╗╔═╗ ║╚╣║║║╚╣╚╣╔╣╔╣║╚╣═╣ ╠╗║╚╝║║╠╗║╚╣║║║║║═╣ ╚═╩══╩═╩═╩═╩╝╚╩═╩═╝ ➡️ SUBSCRIBE, Share, Like, Comment ☕ Buy me a Coffee 👉 https://www.buymeacoffee.com/BlackPerl 📧 Sponsorship Inquiries: [email protected] ------------------------------------------------------------------------------------------------------------------------- 🙏 Thanks for watching!! Be CyberAware!! 🤞
