We will be using velociraptor and excel to find out malware execution on the system by differential analysis.
Context = Any true positive alert you get or you were targeted by a sophisticated advanced persistent threat. We need actionable intelligence to pivot more.
Following the below two links, collect the build the collector and collect the artifacts first from the fresh system and the infected system.
https://mahimfiroj.blogspot.com/2026/09/windows-rapid-triage-with-velociraptor.html
https://github.com/secure-cake/win-mal-investigations
Reference file: SLIDES_Windows-Malware-Investigations-02082024.pdf (Saved on my ovi.it88 google drive)
Here we also have some important script that will be helpful during IR.
https://github.com/secure-cake/win-mal-investigations/tree/main/misc-powershell
Once collection is done, now we need to follow the following workflow:
Avi
Comments
Post a Comment