Sept. 19, 2023, 2:08 p.m. | SANS Digital Forensics and Incident Response

SANS Digital Forensics and Incident Response www.youtube.com

This presentation examines contemporary approaches to analyzing AWS snapshots and then switches to a particular focus on utilizing Elastic Block Storage (EBS) APIs to implement Read/Seek capabilities on top of snapshots, resulting in a novel analysis method. This new method can easily be used to help triage AWS snapshots by directly accessing the data within the snapshot itself. The practical implementation of this technique will be demonstrated (in Rust) to showcase how data within a snapshot can be directly accessed …

analysis apis aws block capabilities ebs elastic files focus handling novel presentation snap snapshots storage switches triage

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC