Digital Forensic Survival Podcast

DFSP # 428 - It’s all about that XML


Listen Later

When you're triaging a Windows system for evidence of compromise, it's ideal if your plan is focused on some quick wins upfront. There are certain artifacts that offer this opportunity, and Windows Events for New Scheduled Tasks are one of them. Sometimes overlooked, at least in part, because the good stuff contained within the XML portion of the log. This week I'm covering the artifact from a DFIR point of view, I'll go over all the elements of the log entry that are of interest for investigations, and I'll provide a triage methodology that you can employ to find evidence quickly.

...more
View all episodesView all episodes
Download on the App Store

Digital Forensic Survival PodcastBy Digital Forensic Survival Podcast

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

60 ratings


More shows like Digital Forensic Survival Podcast

View all
Adversary Universe Podcast by CrowdStrike

Adversary Universe Podcast

78 Listeners