Nov. 23, 2023, 4:51 p.m. | /u/Iceman1123Trooper

Computer Forensics www.reddit.com

Hello there. I have been working through the *Gh0st in the Enterprise* portion of **The Art of Memory Forensics** (Chapter 18) in SIFT Workstation. However, when trying to use the Log2Timeline command under the section titled "Adding Packet Capture Data", I get an output stating that the "Filter PCAP" is not understood.

As such, I had to modify the command to get it to work. The command I used was *log2timeline.py* *-z UTC --storage-file pcap.dump jackcr-challenge.pcap*. When using **psort.py** to …

art capture command computerforensics data enterprise filter forensics hello memory memory forensics packet packet capture pcap sift under weird working workstation

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC