OSDF Conference Links

Plaso Talk Links

We just came back from the OSDF conference where we organized two workshops (intro into plaso development and a hack-a-thon) and I gave a talk that focused a bit on the usage of the tool.

However the talk was only 30 minute long, which meant that I had to cut out quite a few slides that I had prepared, so without further ado I give you those slides here:



Or if you don't want to view that inline, you can click this link or get the PDF version here.

There will also be a video of the talk released, presumably accessible on the OSDF web site.

Intro Into Plaso Development

One of the tutorials we held was Elizabeth's intro into plaso development, which is accessible from here.

Codelab

If you are interested in trying out the codelab it has been released on the tool's site, and is accessible here: http://plaso.kiddaland.net/developer/code-lab

The cheat sheet for the codelab is also accessible here.

We will then both try to improve this codelab and create new ones to make it easier for people to learn how to start developing for plaso.

And as always, if someone has suggestions on how to improve the codelabs (or suggestions for new ones), or some feedback on what walls they hit when they started to attempt to develop plugins, then please send them to the dev mailing list and we'll incorporate that into the documentation.

Comments

Popular posts from this blog

Parsing the $MFT NTFS metadata file

Incident Response in the Cloud

Container Forensics with Docker Explorer