Hey All. Please let me know how useful this tool gonna be for your day to day life in Incident Response.. Also post all of your queries down here. I will be happy to help!! Enjoy IR Flash!!
@BlackPerl3 жыл бұрын
It does have Hindi Subtitle as well, so for anyone who needs can turn it on!! 😊
@anishdash20843 жыл бұрын
Awesome work mate!! You are on Fire!
@BlackPerl3 жыл бұрын
Thank you for your feedback!!
@samvarun41813 жыл бұрын
Here in 50secs of upload... Big fan of your work...Many thanks for sharing this will definitely try this out
@BlackPerl3 жыл бұрын
Thanks Buddy. Really appreciate it.
@futurebuddies53353 жыл бұрын
Excellent work!! This gonna make my life easier from now on!! 😍😍
@BlackPerl3 жыл бұрын
Happy to hear that!
@parulkhedwal13523 жыл бұрын
Nice Video Archan...Content Request: Can you make an exclusive video on MITRE please?
@BlackPerl3 жыл бұрын
Hey, Thanks for the feedback and appreciate your suggestion. Sure, I will compile one for sure. Please stay tuned!
@dipubabu24403 жыл бұрын
Brother, Can't thank you enough for the tool! I have been watching your training, it's really good. Kudos !! if you could do some training on forensics it would be appreciated.
@BlackPerl3 жыл бұрын
Hey Buddy. Thanks a lot for the feedback, really appreciate it. 😊 I have some episodes done for Windows and Memory Forensics. Please check the playlist, it might be useful. And there are lot more planned for coming up sessions for forensics, please stay tuned!! Link- kzbin.info/aero/PLjWEV7pmvSa50erciZUSnzvE7nK0FyvsH
@dipubabu24403 жыл бұрын
@@BlackPerl Appreciate it, keep rocking!!
@zivakhan48753 жыл бұрын
Can't Thank you enough for sharing this one.. Amazing...
@BlackPerl3 жыл бұрын
You are welcome Ziva!!
@VaibhavKrishna183 жыл бұрын
Awesome Archan !! How about getting these event logs into ELK test instance for further analysis? In an automated way.
@BlackPerl3 жыл бұрын
Yes Buddy. That will be more awesome!! You have a deployment ready for this? We can another episode on this
@ParlonsCybersecurite3 жыл бұрын
Hello Archan I have tried to run the batch file from D:\ drive I faced permission issue ( Access denied ) , so I copied "IR-Dump" at the root of C and run the batch file from there , then it worked ! This said , I would like to say thank you for sharing this
@BlackPerl3 жыл бұрын
Hey Buddy. Thanks for the feedback! M glad that you got it working! And yes, generally for Org machines, we tend to have only one drive and corporate policies don't allow multiple fragments for bitlocker security etc. So easiest way is, keep this set up in desktop and give admin permission while opening CMD!! 😊
@jackjk52033 жыл бұрын
Hi bro. Can you explain the each logs and it's usage for forensic investigation. Is there any automated way to find anomalies using the IR flash collect logs and data.
@BlackPerl3 жыл бұрын
Hey, for usage of each logs in forensic investigation you can check out basic forensics guidelines. There are several usecases and hence requirements of several logs. You can check out my previous video of Event Log forensics- 1. kzbin.info/www/bejne/f6vKoWaDmLeil8k 2. kzbin.info/www/bejne/roHaomlmbaeDiqc They will give you the idea how event logs can be used for forensics case studies. For findings anomaly; currently no functionality on IR Flash, since I had developed this only for log collection purpose. So, you might want to send those logs in your SIEM tools and then run correlation rules on them to find anomalies. Hope this helps 😊
@ronmac29343 жыл бұрын
Excellent work man!! Anything similar you have your arsenal for Linux?
@BlackPerl3 жыл бұрын
Yep, Spot on!! Will cover soon!
@ronmac29343 жыл бұрын
@@BlackPerl will be waiting.
@nuszkat99533 жыл бұрын
Excellent work. Thanks for sharing this with us. Recently I have started working in IR and learning about various artifacts that can be collected depending on the nature of the investigation. I have a question regarding the selection of artifacts this script collects, did you select these artifacts based your previous experience with DFIR investigations where these were found as most valuable or are these based on certain standard procedure guidelines for conducting IR investigations ?
@BlackPerl3 жыл бұрын
Hey Buddy. Thanks for lot for your feedback! So yes, these are compiled from my personal exp. and these are the most useful logs in any investigation. Also, these logs will cover most of the compliances!!
@ManojKumar-yt5ne2 жыл бұрын
Could you please guide how to develop your IR-Dump exe application?
@BlackPerl2 жыл бұрын
Hey, it's a bash script that's all.
@ManojKumar-yt5ne2 жыл бұрын
@@BlackPerl Ok, Got it. Thanks for your prompt response. can we make an exe software application to pull all endpoint logs and push them to the server? If you know something, please suggest me
@BlackPerl2 жыл бұрын
@@ManojKumar-yt5ne Yes we can. Just need to write a wrapper and make it executable.
@ManojKumar-yt5ne2 жыл бұрын
Sure, thanks a lot
@shabeeb093 жыл бұрын
Awesome tool
@BlackPerl3 жыл бұрын
Thank you Buddy!! Feel free to utilize it and also feel free to add your ideas!!