Nov. 23, 2023, 4:51 p.m. | /u/Iceman1123Trooper

Computer Forensics www.reddit.com

Hello there. I have been working through the *Gh0st in the Enterprise* portion of **The Art of Memory Forensics** (Chapter 18) in SIFT Workstation. However, when trying to use the Log2Timeline command under the section titled "Adding Packet Capture Data", I get an output stating that the "Filter PCAP" is not understood.

As such, I had to modify the command to get it to work. The command I used was *log2timeline.py* *-z UTC --storage-file pcap.dump jackcr-challenge.pcap*. When using **psort.py** to …

art capture command computerforensics data enterprise filter forensics hello memory memory forensics packet packet capture pcap sift under weird working workstation

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Associate Principal Security Engineer

@ Activision Blizzard | Work from Home - CA

Security Engineer- Systems Integration

@ Meta | Bellevue, WA | Menlo Park, CA | New York City

Lead Security Engineer (Digital Forensic and IR Analyst)

@ Blue Yonder | Hyderabad

Senior Principal IAM Engineering Program Manager Cybersecurity

@ Providence | Redmond, WA, United States

Information Security Analyst II or III

@ Entergy | The Woodlands, Texas, United States