Showing posts with label CTF. Show all posts
Showing posts with label CTF. Show all posts

Friday, March 6, 2026

Windows Forensic — Audit Log Cleared

Windows Forensic — Audit Log Cleared

picoCTF เป็นเกม ด้าน computer security ที่จัดโดย มหาวิทยาลัย Carnegie Mellon หรือ CMU ที่มุ่งเป้าไปที่นักเรียนมัธยมและ มหาวิทยาลัยให้มาแสดงทักษะความสามารถ

Windows Forensic — Audit Log Cleared
photo Credit:PicoCTF

Windows Forensic — Audit Log Cleared

Description

One of the employees at your company has their computer infected by malware! Turns out every time they try to switch on the computer, it shuts down right after they log in. The story given by the employee is as follows:
  1. They installed software using an installer they downloaded online
  2. They ran the installed software but it seemed to do nothing
  3. Now every time they bootup and login to their computer, a black command prompt screen quickly opens and closes and their computer shuts down instantly.
See if you can find evidence for the each of these events and retrieve the flag (split into 3 pieces) from the correct logs!
The analysis of Windows Event Logs should follow the digital forensic methodology recommended by the National Institute of Standards and Technology (NIST SP 800-86), which includes the stages of collection, examination, analysis, and reporting.

Collection of digital evidence


1️⃣ Evidence Identification (ระบุหลักฐาน)
File Name: Windows_Logs.evtx
Source: Employee Workstation(PicoCTF) Download the Windows Log file here
Evidence Type: Windows Event Log

Windows Forensic — Audit Log Cleared


2️⃣ Evidence Preservation (การรักษาหลักฐาน)

Windows Forensic — Audit Log Cleared

#Get-FileHash Windows_Logs.evtx
MD5    checksum:       630F28FF65702E0794256E87172C39CB
SHA1    checksum:      7D242525D3A1FA26923821F9C4416A895BB3C7F6
 
Step > Action
Receive evidence> Investigator
Calculate hash > SHA1 ,MD5
Store copy > Forensic workstation

3️⃣ Create Working Copy
Windows_Logs_original.evtx > Windows_Logs_analysis.evtx
4️⃣ Evidence Examination
Forensic tools
  • Event Viewer
  • PowerShell

Examination of forensic artifacts


5️⃣ Event Log Classification
Log TypeDescription
SecurityAuthentication events
6️⃣  Identify Suspicious Events

Event ID Description
  • 1102 Audit Log Cleared
  • 1033 Windows Installer
  • 4657 Registry Value Modified
  • 1074 System Shutdown

Windows Forensic — Audit Log Cleared

Windows Forensic — Audit Log Cleared

Event Analysis: Event ID 1102 – Audit Log Cleared
The screenshot shows a Windows Security Event Log entry with Event ID 1102.
 In digital forensic investigations, Event ID 1102 is considered a highly suspicious event because it may indicate an attempt to remove evidence from the system.

Attackers or malicious software may clear logs in order to:

  • hide malicious activities

  • remove traces of system compromise

  • prevent investigators from reconstructing the attack timeline

Therefore, this event is often associated with anti-forensic behavior.

Windows Forensic — Audit Log Cleared

Event Analysis: Event ID 1033 – Windows Installer Activity
The screenshot shows a Windows Application Event Log entry with Event ID 1033, generated by the Windows Installer service. However, the Manufacturer field contains an encoded value, which is unusual and may indicate hidden information. 

cGljb0NURntFdjNudF92aTN3djNyXw== This format resembles Base64 encoding, a common encoding method used to represent binary or text data. 
Malicious software installers sometimes embed encoded or obfuscated values in metadata fields to:
  • hide commands
  • store configuration data
  • conceal indicators of compromise

Windows Forensic — Audit Log Cleared


Event ID 4657 – Registry Value Modified 
The screenshot shows a Windows Security Event Log entry with Event ID 4657, which indicates that a registry value has been modified on the system.

The presence of Event ID 4657 suggests that the installed program modified the Windows Registry, which may indicate that malware created a persistence mechanism.

Windows Forensic — Audit Log Cleared

Event ID 1074 — System Shutdown Initiated The screenshot shows a Windows System Event Log entry with Event ID 1074, which records that a process initiated a system shutdown or restart.

Relationship to the Incident Scenario

The employee reported:

1️⃣ They installed software downloaded from the internet
2️⃣ The software appeared to do nothing
3️⃣ A command prompt briefly appears during login
4️⃣ The computer shuts down immediately

The forensic evidence supports this narrative.

Evidence Correlation Timeline

Analysis and timeline reconstruction


7️⃣ Timeline Reconstruction
Time Event ID     Event

03:55:14 1102     Audit log cleared

03:55:57 1033     Software installed

03:56:19 4657     Registry modified

05:02:35 1074     System shutdown


Reporting and documentation of findings


Investigation Conclusion

The analysis of Windows Event Logs revealed a sequence of suspicious events.

Key findings include:

  • Installation of potentially malicious software

  • Registry modification suggesting persistence mechanism

  • Programmatic system shutdown initiated by shutdown.exe

These events indicate a likely malware infection affecting the system.

Further investigation should include:

  • malware analysis

  • registry artifact examination

  • disk forensic analysis

Windows Forensic — Audit Log Cleared

Windows Forensic — Audit Log Cleared

Ref: 

PicoCTF

Digital forensic analysis conducted according to:

    • NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response

อ่านเพิ่มเติม: 


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น ช่วยเตือนความจำ


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Saturday, January 3, 2026

DIGITAL FORENSICS:BINWALK CTF II

DIGITAL FORENSICS:BINWALK CTF II

Binwalk เป็นเครื่องมือแบบ Command-line ที่ใช้สำหรับวิเคราะห์ ตรวจสอบ และสกัดข้อมูล (Extract) ที่ซ่อนอยู่ในไฟล์ไบนารี หรือไฟล์เฟิร์มแวร์ โดยอาศัยการตรวจหา "File Signatures" (Magic bytes) เพื่อดูว่าภายในไฟล์หนึ่งๆ มีไฟล์อื่นซ่อนอยู่หรือไม่

Binwalk เป็นเครื่องมือสำคัญในงาน Steganography Analysis (การวิเคราะห์การซ่อนข้อมูล) โดยทำหน้าที่ตรวจสอบและสกัด(Extract) ไฟล์ที่ถูกนำมาซ่อนไว้ในอีกไฟล์หนึ่ง 


แบบฝึกหัด: การตรวจหาและสกัดข้อมูลที่ซ่อนอยู่ในไฟล์ภาพ

ขั้นตอนที่ 1: การวิเคราะห์โครงสร้างไฟล์ (Initial Scan)

เริ่มต้นด้วยการใช้คำสั่งเพื่อตรวจสอบว่าไฟล์ sky.jpg มีอะไรซ่อนอยู่ภายในบ้าง

DIGITAL FORENSICS:BINWALK CTF II

# Scan a file's contents
  • คำสั่ง: binwalk Desktop/sky.jpg

  • DIGITAL FORENSICS:BINWALK CTF II

  • สิ่งที่พบ: * ที่ Offset   0x396: เป็นข้อมูลภาพ JPEG  

    • ที่ Offset    0x4807E : พบไฟล์ RAR archive data ซ่อนอยู่

    • นี่คือจุดพิรุธ (Artifact) เพราะปกติไฟล์ภาพไม่ควรมีไฟล์ Archive ซ่อนอยู่ข้างใน


# Scan and extract a file's contents
ขั้นตอนที่ 2: การศึกษาตัวเลือกการสกัดข้อมูล (Extraction Options)

เมื่อเราพบไฟล์ซ่อนอยู่ เราต้องหาวิธีนำมันออกมา

  • คำสั่ง binwalk (เมื่อรันโดยไม่มีพารามิเตอร์) จะแสดงคู่มือการใช้งาน


  • Option ที่สำคัญ: -e หรือ --extract ใช้สำหรับการสกัดไฟล์ที่ตรวจพบออกมาโดยอัตโนมัติ

ขั้นตอนที่ 3: การสกัดไฟล์ที่ซ่อนอยู่ (Automatic Extraction)

ทำการรันคำสั่งเพื่อสกัดไฟล์ RAR ออกจากภาพ sky.jpg

  • คำสั่งที่ใช้ (โดยประมาณ): binwalk -e Desktop/sky.jpg


  • ผลลัพธ์: Binwalk จะสร้างโฟลเดอร์ใหม่ชื่อ _sky.jpg.extracted ขึ้นมาใน Directory ปัจจุบัน

    DIGITAL FORENSICS:BINWALK CTF II

ขั้นตอนที่ 4: ตรวจสอบผลลัพธ์การสกัดข้อมูล

เข้าไปตรวจสอบภายในโฟลเดอร์ที่ได้จากการสกัด

  • ภายในโฟลเดอร์พบไฟล์ 2 ไฟล์:

    1. 4807E.rar: คือไฟล์ RAR ที่ถูกสกัดออกมา 

    2. ls.txt: ไฟล์ข้อความขนาด 25 bytes

ขั้นตอนที่ 5: การกู้คืนหลักฐาน (Finding the Flag)

ขั้นตอนสุดท้ายคือการอ่านเนื้อหาภายในไฟล์เพื่อหาข้อมูลสำคัญ

  • คำสั่ง: cat //home/kali/Desktop/_sky.jpg.extracted/ls.txt

  • DIGITAL FORENSICS:BINWALK CTF II

  • หลักฐานที่พบ (Flag): csictf{j0ker_w4snt_happy}


สรุปขั้นตอนตามลำดับ

  1. สแกนไฟล์: พบ JPEG (หลัก), TIFF (Metadata), JPEG (Thumbnail ที่ 0x396) และ RAR (ไฟล์ซ่อน)

  2. สั่งสกัด: ใช้คำสั่งสกัดไฟล์บีบอัดออกมา

  3. ตรวจสอบโฟลเดอร์: พบไฟล์ ls.txt ที่ถูกซ่อนไว้ใน RAR อีกทีหนึ่ง

  4. อ่านข้อมูล: พบข้อความลับที่ซ่อนอยู่


สรุปผลการสืบสวน

จากการใช้ Binwalk เราพบว่าไฟล์ภาพ sky.jpg มีการใช้เทคนิค Steganography เบื้องต้นเพื่อซ่อนไฟล์ RAR ,txt ไว้ข้างท้ายไฟล์ภาพ ซึ่งภายในมีไฟล์ ls.txt ที่บรรจุรหัส Flag สำคัญอยู่

"ข้อควรระวังสำหรับผู้ใช้ทั่วไป" (เช่น อย่าโหลดโปรแกรมจากแหล่งไม่น่าเชื่อถือ) และ "ความรู้เพิ่มเติมสำหรับสาย Forensic" (เช่น การใช้ Hex Editor เพื่อดู Header ของไฟล์ที่ซ่อนอยู่)


อ่านเพิ่มเติม: 

BINWALK CTF


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Friday, July 11, 2025

Hashcat A practical Guide

Hashcat A practical Guide

Hashcat A practical Guide
How hashing works
Hashcat A practical Guide
How to Defend Against Hashcat

Hashcat A practical Guide

How to Install Hashcat
Hashcat A practical Guide

Hashcat A practical Guide

How to Work with Hashcat
Hashcat A practical Guide


Hashcat A practical Guide

What is Hashcat?
Hashcat A practical Guide

Summary
Hashcat A practical Guide

LAB Hashcat 

1.Crack the hash “d0199f51d2728db6011945145a1b607a” using the ainbow table manually.?

As mentioned at the beginning, let’s use Crack Station without taking the long route: www.crackstation.net or  Hashes.com

Hashcat A practical Guide

Ans:

2.Crack the hash “eb61eead90e3b899c6bcbe27ac581660” using online tools?

Normally, I would say “Let’s Google it, and go with the first result,” accepting that information can come from everywhere. However, I definitely do not recommend that in this case. If Crack Station isn’t working, the next site to try would be https://md5.gromweb.com/. That’s because some other sites can be quite problematic. Result:

Hashcat A practical Guide

Ans:

3.Identify the hash type: c44a471bd78cc6c2fea32b9fe028d30a  ?


As mentioned at the beginning, let’s use "Identify hash types" without taking the long route:https://hashes.com/en/tools/hash_identifier or  https://www.tunnelsup.com/hash-analyzer/ 

Hashcat A practical Guide

ANS:

4.Bored of this yet? Crack this hash: b6b0d451bbf6fed658659a9e7e5598fe ?

Ans:

5.Password Cracking : cb5e8a23ec9e46a858372247af29a414 ?

Ans:

6.Bored of this yet? Crack this hash: c44a471bd78cc6c2fea32b9fe028d30a ?


Ans: 

7.Crack an MD5 hash using a wordlist: hash_lab.txt ? (Basic Dictionary Attack)


Hashcat A practical Guide

Ans:

8.Crack an MD5 hash using a wordlist: hash_lab2.txt ? (Basic Dictionary Attack)

Hashcat A practical Guide

ANS:


อ่านเพิ่มเติม:
ที่มา
  • https://hashcat.net/hashcat/
  • https://github.com/hashcat/hashcat
  • https://hashcat.net/wiki/
  • hashingcrypto101

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูล  เผยแพร่ความรู้และให้โอกาสในการค้นคว้าหาข้อมูลเพื่อการศึกษา   บุคคลที่สนใจโดยทั่วไป รวมถึงนักเรียน นิสิต นักศึกษา  ในการเรียนรู้เท่านั้น


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD #คดีอาชญากรรมคอมพิวเตอร์ #พยานหลักฐานดิจิทัล

Tuesday, March 11, 2025

Digital Forensics:KAPE

Digital Forensics:An introduction to Kroll Artifact Parser and Extractor (KAPE) 

Kroll Artifact Parser And Extractor (KAPE)

Kroll's Artifact Parser and Extractor (KAPE) – created by Kroll senior director and three-time Forensic 4:cast DFIR Investigator of the Year Eric Zimmerman – lets forensic teams collect and process forensically useful artifacts within minutes.

Photo cradit:kroll.com
  • We will use the forensics tool KAPE to collect and process files from a device.
  • KAPE does not need to be installed. It is portable and can be used from network locations or USB drives. 


Prerequisite steps:

  • Download KAPE and unzip.
  • Create a new ZIP file named ‘kape.zip’ by compressing only two items: ‘kape.exe’ and the ‘Target’ directory.
    Digital Forensics:KAPE
Q1.
  • From amongst kape.exe and gkape.exe, which binary is used to run GUI version of KAPE?
  • Ans:gkape.exe

Digital Forensics:KAPE

Now that we have learned about the different components of KAPE let's take it for a test drive. In the attached host, double-click to open the gkape.exe file. You will see the following Window:

Digital Forensics:KAPE
  • Use the search bar to search for the targets needed based on reading what is being asked in the challenge questions.
  • You can also use the “KapeTriage” compound Target which collects most of the files needed for a DFIR investigation.
Digital Forensics:KAPE

In particular, the KapeTriage Compound Target was created to selectively collect the most important artifacts from a computer in minutes, rather than creating a full disk image, with forensically reliable, quick win results.

Photo credit:kapetriage-mindmap-for-dfir-practitioners (Kroll)


  • Select the “Use Module options” option.
  • Set the “Module destination” as the path to an empty folder created on the desktop
  • Select the !EZParser module


We have selected the KapeTriage compound Target and !EZParser Compound Module. The command line below shows the CLI command that will be run. The Execute! button in the bottom right corner will execute the command. 

Digital Forensics:KAPE

We can press any key to terminate the command window.

Digital Forensics:KAPE
  • Open EZViewer.
  • File > Open.
  • Open this csv file in EZViewer:

Digital Forensics:KAPE

Digital Forensics:KAPE

Q2.
  • What is the name of the file that was deleted on 30/05/2024?
  • See the “DeleteOn” column:
Explanation:
  • In EZViewer go to File > Open.
  • Open this csv file in EZViewer:
  • EZparser\FileDeletion

Digital Forensics:KAPE

The RecycleBin_InfoFiles Target collects metadata files that reside within a user’s Recycle Bin. Parsing these files will provide information about which files were deleted by a given user. These files do NOT contain the original files that were deleted. 

Q3.
  • How many times did this program py.exe run?
  • 10
  • What is the full path to the program executable?
  • \WINDOWS\PY.EXE 
  • Interesting Directories Accessed?
  • \ZIP-PASSWORD-BRUTEFORCER-MASTER\ZIP-PASSWORD-BRUTEFORCER.PY
  • See the “ExecutableName” column:
Explanation:
  • In EZViewer go to File > Open.
  • Open this csv file in EZViewer:
  • EZparser\ProgramExecution
Digital Forensics:KAPE

EvidenceOfExecution

The EvidenceOfExecution Target will collect files related to various program execution artifacts, including Prefetch and Amcache that reside within Windows.

Q4.
  • When was the last time the USB drive was removed?
  • See the “LastRemove” column:
Explanation:
  • In EZViewer go to File > Open.
  • Open this csv file in EZViewer:
  • EZparser\Registry
Digital Forensics:KAPE

RegistryHives

The RegistryHives Target collects the Registry Hives specified within the following Targets: RegistryHivesSystem.tkape and RegistryHivesUser.tkape. This means the following Registry Hives will be collected: SAM, SOFTWARE, SYSTEM, SECURITY, NTUSER.dat, DEFAULT, UsrClass.dat.

Credit Video : Kroll Artifact Parser and Extractor (KAPE) Official Demo



Digital Forensics:An introduction to Kroll Artifact Parser and Extractor (KAPE)

ทีมา :   Kape
อ่านเพิ่มเติม: Timeline Explorer

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูล  เผยแพร่ความรู้และให้โอกาสในการค้นคว้าหาข้อมูลเพื่อการศึกษา   บุคคลที่สนใจโดยทั่วไป รวมถึงนักเรียน นิสิต นักศึกษา  ในการเรียนรู้เท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...