Introduction to Plaso Heimdall

Поделиться
HTML-код
  • Опубликовано: 27 дек 2024

Комментарии •

  • @thomasburnette9202
    @thomasburnette9202 4 года назад

    Any tips on optimizing the time via defining more workers, assigning resources, etc.? I have a lot of compute power available to me and it still took almost 2 hours with 256 workers on a 125GB image. A lot of time it seems the workers were waiting on jobs to be queued to start.

  • @BlueWolfCyberSecurity
    @BlueWolfCyberSecurity 6 лет назад +4

    Very nice video cheers! Any thoughs on creating a video to combine plaso and the elk stack?

    • @13Cubed
      @13Cubed  6 лет назад +1

      No, but I will add this to my suggestion list. :)

    • @babygrinch2419
      @babygrinch2419 6 лет назад +3

      I second this ^ or something like Timesketch.

    • @lautarob
      @lautarob 5 лет назад

      Very interesting and helpful. Thanks!
      Did you mention at some point In other vídeo that you use Linux for convenience but this can be run from a windows system with python installed on it?

  • @smh4536
    @smh4536 5 лет назад

    instead of using DD can you use e01?

    • @13Cubed
      @13Cubed  5 лет назад

      Yes, absolutely. Here's a cheat sheet that may be handy: digital-forensics.sans.org/media/Plaso-Cheat-Sheet.pdf

    • @smh4536
      @smh4536 5 лет назад

      @@13Cubed thanks for the info. What I mean was if i had an e01 image could i just point psteal at it like this : psteal.py --source petya.e01 -o xlsx -w output.xlsx. C and get the same results or do i have to mount the e01?

  • @edinatl2008
    @edinatl2008 3 года назад +1

    Thanks