July 22, 2022, 11:22 a.m. | /u/netw0rknovice

Computer Forensics www.reddit.com

Hi All,


Has anyone here used Windows virtual machines or devices as a honeypot(s) to capture malicious activity and artifacts?

I'm interested in gathering logs, pcaps, memory and images much like the content published by the [dfir report](https://thedfirreport.com/). I'm curious to hear what risks and challenges were faced, as well as what lessons were learnt.
Cheers

analysis computerforensics forensic forensic analysis honeypots windows

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Architect - Hardware

@ Intel | IND - Bengaluru

Elastic Consultant

@ Elastic | Spain

OT Cybersecurity Specialist

@ Emerson | Abu Dhabi, United Arab Emirates

Security Operations Program Manager

@ Kaseya | Miami, Florida, United States

Senior Security Operations Engineer

@ Revinate | Vancouver