A goldmine within an ocean of data – basics of network forensics

Presented at BruCON 0x0A (2018), Oct. 5, 2018, 10:30 a.m. (120 minutes)

**/!\ Important Notice /!\** For The workshop, the participants are requested to download the SOF-ELK Virtual Machine. You can find the VM at the following address: [https://github.com/philhagen/sof-elk/blob/master/VM\_README.md](https://github.com/philhagen/sof-elk/blob/master/VM_README.md) Please have the VM ready to use for the workshop. Thank you! ------------------------------------------------------------------------------------------------------------------------------------- Loads of data passes over a corporate network. Finding usefull things in this stream can be overwelming. This workshop will give a brief introduction on how you can capture this data. Next we'll tackle the main focus of this workshop: handling the huge load of data with mostly Free and Open Source Software. To finalize we'll tackle the subject of automating the process.

Presenters:

  • Andy Deweirt
    I’m a security consultant with over 10 year of experience in infosecurity. I've built firewalls, architected solutions, tested security, broke infrastructure and built soc capabilities, A main thread within the multiple roles and assignments has mostly been network security. As a freelance consultant I mainly focus on assignments related to Incident Response. I’m a big fan of data, lots of data, and getting useful information out of it. In my free time I like to spend time with my family, do a lot of sports, tinker with stuff, play with Arduino/Raspberry Pi/other gadgets.

Links:

Similar Presentations: