Commit cdbba88b authored by BENOIT JEAN's avatar BENOIT JEAN
Browse files

Forensic training environment

Scripts and material to prepare the training environment ; includes:
- "deploy" script to deploy the training env. on several hosts
- all courses material (slides, disk images, handouts) that will be copied
- all support material (download script for SANS cheat sheets + forensics
C ampus Best Practice document) that will be copied
parent 7b844b8c
hostlist
out
err
hex_file_and_regex_cheat_sheet.pdf
linux-shell-survival-guide.pdf
netcat_cheat_sheet_v1.pdf
sift_cheat_sheet.pdf
#!/bin/sh
urls='
https://digital-forensics.sans.org/media/hex_file_and_regex_cheat_sheet.pdf
https://digital-forensics.sans.org/media/linux-shell-survival-guide.pdf
https://www.sans.org/security-resources/sec560/netcat_cheat_sheet_v1.pdf
https://digital-forensics.sans.org/media/sift_cheat_sheet.pdf
'
for i in $urls ; do wget -N "$i" ; done
All the cheat sheets are copyrighted by SANS (see www.sans.org)
- Hex File Headers and REgex for Forensics
https://digital-forensics.sans.org/media/hex_file_and_regex_cheat_sheet.pdf
- Linux Shell Survival Guide
https://digital-forensics.sans.org/media/linux-shell-survival-guide.pdf
- Netcat Cheat Sheet
https://www.sans.org/security-resources/sec560/netcat_cheat_sheet_v1.pdf
- SIFT Cheat Sheet
https://digital-forensics.sans.org/media/sift_cheat_sheet.pdf
The campus best practice document "Forensics Analysis and Incident
Handling" was written by Jean BENOIT & Aleš PADRTA, through the Geant
Campus Best Practice project
big_picture-principles.pdf - presentation with the brief introduction to the forensic analysis
alpine - Data Acquisition.ova Virtual Machine image for the hands-on
data_acquisition_hands-on.pdf hands-on outline
data_acquisition_hands-on_solution.zip hands-on solution (encrypted)
data_acquisition_presentation.pdf data acquisition presentation
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment