SANS DFIR Summit

Tom Cross and I had a great time presenting and spending time with the incident responders at SANS Digitial Forensics and Incident Response Summit in Austin, TX this year. The deck we used is now available for download here: http://computer-forensics.sans.org/summit-archives/DFIR_Summit/Hunting-Attackers-with-Network-Audit-Trails-Tom-Cross-and-Charles-Herring.pdf. It was titled "Hunting Attackers with Network Audit Trails" and covered open source and commerical tools for processing NetFlow/IPFIX for forensic purposes.

A note on how this was written: I use artificial intelligence tools to help me research, check facts, and edit these posts. The ideas, the arguments, and any mistakes are mine. I read the sources, I check the claims, and I take full responsibility for what I publish here. The views are my own and the writing is my intellectual property.