The inspector: automating the forensic investigation of infected computers

John Morris, Eric Kedrosky Nortel

  Corporate stream: Friday 13 October 2006, 10:40 - 11:20.

  download slides (PDF)

Zero day outbreaks of bots and viruses, undetected by current AV signatures, are common occurrences on corporate networks. When dealing with a significant outbreak of a new threat, there are many unknowns, not the least of which are knowing what common vulnerabilities may be allowing these systems to become infected and the malware files that have been deposited. By automating the forensic investigation process, IT security teams can be provided this critical information within minutes of the outbreak starting.

This presentation will cover why automated forensic investigations are needed, what information to gather and how to gather it remotely.


Poll

Have you ever been conned by a phishing email?
I have never seen/recognised a phishing email
I always ignore or delete phishing emails
I have responded but realised in time to prevent any damage
I have lost money/accounts have been compromised

Leave a comment
View 12 comments

Jobs Career Sidebar

VB2008

VB2008 VB2008 will take place 1-3 October 2008 at the Westin Ottawa, Canada. Registration has opened; please check the call for papers.
Virus Bulletin currently has 137,617 registered users.