Question: Incident Response Using Kansa Framework to detect and respond to Incident of Compromise ( IOC ) Using VM machine Step 1 : start PowerShell -

Incident Response
Using Kansa Framework to detect and respond to Incident of Compromise( IOC)
Using VM machine
Step1: start PowerShell- in the search bar, type PowerShell, right click, and run it as admin, click yes
Step2: Change directory to Kansa
Step3: Change directory to Modules and
Step4: Exploring Kansa Modules
Q1(20p): Using ASEP module (cd to ASEP),
- Display and list all services presents in the system
- display and list all scheduled tasks in the system.
Q2(10p): Using Config module (cd to Config),
- display and list the local admins in your VM.
Q3(10p): Using Disk module (cd to Disk)
- display and list the template directories in your VM (malware usually live here).
Q4(10p): Using Log module (cd to Log)
- display and list the users accounts and the binary they executed in your VM
Step5: Run Kansa
You first need to cd back to Kansa directory, and we will use kansa.ps1
Running this command:
- it will produce CSV files and they will be stored in a directory name start with output_
Q1(10p): Include your screenshots for CSV files here:
- Using the Timeline Explorer tool, open one of the CSV files. Some CSV file will not open, look for the ones that can be opened and open one of them.
Q2(5p): List CSV files here:

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!