4.9 • 696 Ratings
🗓️ 27 January 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Friday, January 27th, 2003 edition of the Sands and its Stormsendors Stormcast. |
0:09.6 | My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
0:15.6 | When doing incident response, it's often important to sort of quickly get a snapshot of relevant files |
0:24.3 | and settings from a system that you may assume to be compromised. |
0:30.1 | Tom today looked at a simple command line tool that can accomplish some of this for Linux. |
0:42.3 | It's called UAC or the Unix-like artifacts collector, and as the name implies, it runs on Unix-like systems |
0:46.3 | and then collects various artifacts. |
0:50.3 | Tom also took a look at what changes this tool makes to the system, and the most notable |
0:57.5 | here were access times, which isn't really all that surprising. |
1:02.9 | They should change. |
1:03.8 | Now, Tom points out some other tools and do those changes after they're done, but the UAC does |
1:10.6 | have an option actually to record these |
1:13.5 | access times before it accesses any files, so you still have the original values preserved. |
1:22.3 | Overall, it looks like a useful tool, also fairly transparent. |
1:26.0 | There are YAML files that sort of include all the commands |
1:29.2 | it runs, so you can also manage, update and change them to your specific needs. And as Tom |
1:36.5 | points out, you probably do want to run the tool first in a test environment. A few times |
1:41.7 | become really familiar with it before you are using it in an actual |
1:47.2 | incident. And well, password managers remain in the news. The latest is phishing sites |
1:56.1 | trying to impersonate Bitwarden logins. |
2:03.7 | Usually to log in to a Bitwarden account, |
2:04.9 | you log in to either vault.bitwarten.com |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.