How to Collect System Logs within 5 minutes | Best Tool for Incident Response | Easy Log Collection

  Рет қаралды 2,258

BlackPerl

BlackPerl

Күн бұрын

Пікірлер: 39
@BlackPerl
@BlackPerl 3 жыл бұрын
Hey All. Please let me know how useful this tool gonna be for your day to day life in Incident Response.. Also post all of your queries down here. I will be happy to help!! Enjoy IR Flash!!
@BlackPerl
@BlackPerl 3 жыл бұрын
It does have Hindi Subtitle as well, so for anyone who needs can turn it on!! 😊
@anishdash2084
@anishdash2084 3 жыл бұрын
Awesome work mate!! You are on Fire!
@BlackPerl
@BlackPerl 3 жыл бұрын
Thank you for your feedback!!
@samvarun4181
@samvarun4181 3 жыл бұрын
Here in 50secs of upload... Big fan of your work...Many thanks for sharing this will definitely try this out
@BlackPerl
@BlackPerl 3 жыл бұрын
Thanks Buddy. Really appreciate it.
@futurebuddies5335
@futurebuddies5335 3 жыл бұрын
Excellent work!! This gonna make my life easier from now on!! 😍😍
@BlackPerl
@BlackPerl 3 жыл бұрын
Happy to hear that!
@parulkhedwal1352
@parulkhedwal1352 3 жыл бұрын
Nice Video Archan...Content Request: Can you make an exclusive video on MITRE please?
@BlackPerl
@BlackPerl 3 жыл бұрын
Hey, Thanks for the feedback and appreciate your suggestion. Sure, I will compile one for sure. Please stay tuned!
@dipubabu2440
@dipubabu2440 3 жыл бұрын
Brother, Can't thank you enough for the tool! I have been watching your training, it's really good. Kudos !! if you could do some training on forensics it would be appreciated.
@BlackPerl
@BlackPerl 3 жыл бұрын
Hey Buddy. Thanks a lot for the feedback, really appreciate it. 😊 I have some episodes done for Windows and Memory Forensics. Please check the playlist, it might be useful. And there are lot more planned for coming up sessions for forensics, please stay tuned!! Link- kzbin.info/aero/PLjWEV7pmvSa50erciZUSnzvE7nK0FyvsH
@dipubabu2440
@dipubabu2440 3 жыл бұрын
@@BlackPerl Appreciate it, keep rocking!!
@zivakhan4875
@zivakhan4875 3 жыл бұрын
Can't Thank you enough for sharing this one.. Amazing...
@BlackPerl
@BlackPerl 3 жыл бұрын
You are welcome Ziva!!
@VaibhavKrishna18
@VaibhavKrishna18 3 жыл бұрын
Awesome Archan !! How about getting these event logs into ELK test instance for further analysis? In an automated way.
@BlackPerl
@BlackPerl 3 жыл бұрын
Yes Buddy. That will be more awesome!! You have a deployment ready for this? We can another episode on this
@ParlonsCybersecurite
@ParlonsCybersecurite 3 жыл бұрын
Hello Archan I have tried to run the batch file from D:\ drive I faced permission issue ( Access denied ) , so I copied "IR-Dump" at the root of C and run the batch file from there , then it worked ! This said , I would like to say thank you for sharing this
@BlackPerl
@BlackPerl 3 жыл бұрын
Hey Buddy. Thanks for the feedback! M glad that you got it working! And yes, generally for Org machines, we tend to have only one drive and corporate policies don't allow multiple fragments for bitlocker security etc. So easiest way is, keep this set up in desktop and give admin permission while opening CMD!! 😊
@jackjk5203
@jackjk5203 3 жыл бұрын
Hi bro. Can you explain the each logs and it's usage for forensic investigation. Is there any automated way to find anomalies using the IR flash collect logs and data.
@BlackPerl
@BlackPerl 3 жыл бұрын
Hey, for usage of each logs in forensic investigation you can check out basic forensics guidelines. There are several usecases and hence requirements of several logs. You can check out my previous video of Event Log forensics- 1. kzbin.info/www/bejne/f6vKoWaDmLeil8k 2. kzbin.info/www/bejne/roHaomlmbaeDiqc They will give you the idea how event logs can be used for forensics case studies. For findings anomaly; currently no functionality on IR Flash, since I had developed this only for log collection purpose. So, you might want to send those logs in your SIEM tools and then run correlation rules on them to find anomalies. Hope this helps 😊
@ronmac2934
@ronmac2934 3 жыл бұрын
Excellent work man!! Anything similar you have your arsenal for Linux?
@BlackPerl
@BlackPerl 3 жыл бұрын
Yep, Spot on!! Will cover soon!
@ronmac2934
@ronmac2934 3 жыл бұрын
@@BlackPerl will be waiting.
@nuszkat9953
@nuszkat9953 3 жыл бұрын
Excellent work. Thanks for sharing this with us. Recently I have started working in IR and learning about various artifacts that can be collected depending on the nature of the investigation. I have a question regarding the selection of artifacts this script collects, did you select these artifacts based your previous experience with DFIR investigations where these were found as most valuable or are these based on certain standard procedure guidelines for conducting IR investigations ?
@BlackPerl
@BlackPerl 3 жыл бұрын
Hey Buddy. Thanks for lot for your feedback! So yes, these are compiled from my personal exp. and these are the most useful logs in any investigation. Also, these logs will cover most of the compliances!!
@ManojKumar-yt5ne
@ManojKumar-yt5ne 2 жыл бұрын
Could you please guide how to develop your IR-Dump exe application?
@BlackPerl
@BlackPerl 2 жыл бұрын
Hey, it's a bash script that's all.
@ManojKumar-yt5ne
@ManojKumar-yt5ne 2 жыл бұрын
@@BlackPerl Ok, Got it. Thanks for your prompt response. can we make an exe software application to pull all endpoint logs and push them to the server? If you know something, please suggest me
@BlackPerl
@BlackPerl 2 жыл бұрын
@@ManojKumar-yt5ne Yes we can. Just need to write a wrapper and make it executable.
@ManojKumar-yt5ne
@ManojKumar-yt5ne 2 жыл бұрын
Sure, thanks a lot
@shabeeb09
@shabeeb09 3 жыл бұрын
Awesome tool
@BlackPerl
@BlackPerl 3 жыл бұрын
Thank you Buddy!! Feel free to utilize it and also feel free to add your ideas!!
@cyberwarriorall6260
@cyberwarriorall6260 3 жыл бұрын
Awesome Awesome Awesome
@BlackPerl
@BlackPerl 3 жыл бұрын
Thank you so Much!!
@Nick-sn3bl
@Nick-sn3bl 3 жыл бұрын
A linux tool like this would be awesome!
@BlackPerl
@BlackPerl 3 жыл бұрын
Yes, it's getting built. Will be released shortly
Quilt Challenge, No Skills, Just Luck#Funnyfamily #Partygames #Funny
00:32
Family Games Media
Рет қаралды 55 МЛН
She made herself an ear of corn from his marmalade candies🌽🌽🌽
00:38
Valja & Maxim Family
Рет қаралды 18 МЛН
What Event Logs?  Part 1:  Attacker Tricks to Remove Event Logs
1:06:21
SANS Digital Forensics and Incident Response
Рет қаралды 27 М.
Don't Let Logs FILL Your Server (Rotate Them!)
11:24
Shawn Powers
Рет қаралды 4,8 М.
Quick-witted Craig Ferguson + More
12:16
The Jayleno Fly
Рет қаралды 12 МЛН
Is Skynet watching you already?
1:04:00
David Bombal
Рет қаралды 1,1 МЛН
How do hackers hide themselves? - staying anonymous online
11:55
Grant Collins
Рет қаралды 1,5 МЛН
How to Stalk People Effectively and Legally Through OSINT
18:34
What is a Passkey?
18:05
Ask Leo!
Рет қаралды 135 М.
Quilt Challenge, No Skills, Just Luck#Funnyfamily #Partygames #Funny
00:32
Family Games Media
Рет қаралды 55 МЛН