DFSP # 425 - SSH Forensics: Host-Based Artifacts

Published: April 9, 2024, 11:54 a.m.

In the last episode on this topic, I covered SSH from a investigation point of view. I explained SSH and the artifacts that typically come up when your investigating. In this episode, we're getting into the triage methodology. This includes the artifacts targeted for a fast, but yet effective triage for notable SSH activity on a given host.