DFSP # 425 - SSH Forensics: Host-Based Artifacts

09/04/2024 30 min
DFSP # 425 - SSH Forensics: Host-Based Artifacts

Listen "DFSP # 425 - SSH Forensics: Host-Based Artifacts"

Episode Synopsis

In the last episode on this topic, I covered SSH from a investigation point of view. I explained SSH and the artifacts that typically come up when your investigating. In this episode, we're getting into the triage methodology. This includes the artifacts targeted for a fast, but yet effective triage for notable SSH activity on a given host.