Open-Source DFIR Made Easy: The Setup - SANS Digital Forensics & Incident Response Summit 2017

A common challenge in the digital forensics and incident response (DFIR) community has been creating a DFIR toolkit that is cheap, simple to setup, scalable, and easy to use. Frequently, DFIR teams do not have the money to purchase, nor the time needed to develop a DFIR toolkit solution themselves. Although many open-source solutions exist, they typically require an advanced level of skill to setup and maintain. Alternatively, custom solutions present risk should the maintainer leave or become otherwise unable to maintain it. Another common issue faced by DFIR teams is the requirement for another agent constantly running on each host, exponentially consuming resources in already over-subscribed virtualized environments. This leads to the creation of custom scripts with varying levels of fidelity, based on the experience of the individual or team. This presentation will introduce and demonstrate the use of the “CyLR, CDQR Forensics – Virtual Machine” (CCF-VM). The CCF-VM was designed to provide an all-in-one solution to one of the most common issues facing DFIR teams. It provides a conveniently packaged, easy-to-use platform, designed from the ground up to enable teams to collect, process, and analyze critical forensics artifacts to triage and investigate intrusions both large and small. Including built-in, commonly used searches and dashboards, CCF-VM enables searching of both single or multiple hosts simultaneously based on analyst or incident needs. After completing this session, attendees will understand how to: collect data with CyLR; process forensic artifacts easily with CDQR; use Kibana (as setup in CCF-VM) for DFIR purposes; setup the CCF-VM; set up a CCF-VM DFIR toolkit for each analyst; and scale CCF-VM to the enterprise level. Stephen Hinck (@stephenhinck), Senior Technical Account Manager, ICEBRG Alan Orlikoski (@alanorlikoski), Senior Manager, Incident Response & Threat Protection Team

The Secret History of Cyber War - SANS Digital Forensics and Incident Response Summit 2017
▶︎

The Secret History of Cyber War - SANS Digital Forensics and Incident Response Summit 2017

Incident Response in the Cloud (AWS) - SANS Digital Forensics & Incident Response Summit 2017
▶︎

Incident Response in the Cloud (AWS) - SANS Digital Forensics & Incident Response Summit 2017

Start-Process PowerShell: Get Forensic Artifact- SANS DFIR Summit 2016
▶︎

Start-Process PowerShell: Get Forensic Artifact- SANS DFIR Summit 2016

ShimCache and AmCache enterprise-wide hunting - SANS Threat Hunting Summit 2017
▶︎

ShimCache and AmCache enterprise-wide hunting - SANS Threat Hunting Summit 2017

SQL Course for Beginners [Full Course]
▶︎

SQL Course for Beginners [Full Course]

Building the PERFECT Linux PC with Linus Torvalds
▶︎

Building the PERFECT Linux PC with Linus Torvalds

SANS DFIR WEBCAST - Network Forensics What Are Your Investigations Missing
▶︎

SANS DFIR WEBCAST - Network Forensics What Are Your Investigations Missing

Trump Gets Booed & Falls Asleep During NBA Finals, Claims War is Almost Over & Goodbye Spencer Pratt
▶︎

Trump Gets Booed & Falls Asleep During NBA Finals, Claims War is Almost Over & Goodbye Spencer Pratt

SANS DFIR Webcast - Memory Forensics for Incident Response
▶︎

SANS DFIR Webcast - Memory Forensics for Incident Response

Something is jamming GPS over Europe. Here's what we found
▶︎

Something is jamming GPS over Europe. Here's what we found

NOC-umentary: Inside the Black Hat NOC
▶︎

NOC-umentary: Inside the Black Hat NOC

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro
▶︎

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

Open Source Incident Response Platform - Your SOC Needs This!
▶︎

Open Source Incident Response Platform - Your SOC Needs This!

How Your Phone is Tracked in 2026 – And How to Stop It
▶︎

How Your Phone is Tracked in 2026 – And How to Stop It

Tracking Threat Actors through YARA Rules and Virus Total - SANS DFIR Summit 2016
▶︎

Tracking Threat Actors through YARA Rules and Virus Total - SANS DFIR Summit 2016

AmCache Investigation - SANS Digital Forensics & Incident Response Summit 2019
▶︎

AmCache Investigation - SANS Digital Forensics & Incident Response Summit 2019

Finding and Decoding Malicious Powershell Scripts - SANS DFIR Summit 2018
▶︎

Finding and Decoding Malicious Powershell Scripts - SANS DFIR Summit 2018

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source
▶︎

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source

The Mind Behind Linux | Linus Torvalds | TED
▶︎

The Mind Behind Linux | Linus Torvalds | TED

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026