Turning DFIR into leads - Part 1
Incident response investigations often start with a large amount of raw data spread across multiple sources. Forensic images will contain lots of valuable information, but identifying the relevant indicators can easily become overwhelming and time-consuming.
We took a set of playbooks provided by our partner NRD Cyber Security and used them as a starting point to improve our forensics workflows.
Our ultimate goal is to turn qcow2 snapshots into investigation leads as easily as possible.