Turning DFIR into leads - Part 2
Running investigation scripts over a forensic image tells you about the underlying system and services that ran on it, but getting there costs us time to take the snapshot, perform an extraction and run a full triage run. After an incident, sooner or later the question changes to: is this happening anywhere else, right now?
