May 11, 2024, 9:26 a.m. | /u/FinishAdditional6006

cybersecurity www.reddit.com

Are there any decent/recommended tools out there (ideally free/open source) which would be useful in undertaking some forensic work on a Windows Domain Controller which has been compromised? As I've not done it before, I was looking for something where the learning curve isn't too steep (at least initially).

Also, are there any good procedures to follow that can guide you through the process of what/how to look for on a compromised server? It was a ransomware incident, so there …

compromised controller curve cybersecurity digital digital forensics domain domain controller forensic forensics free good isn open source procedures tools windows work

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States