Showing posts with label Windows artifacts. Show all posts
Showing posts with label Windows artifacts. Show all posts

Friday, February 13, 2026

Windows Forensics

Windows Forensics


Windows Forensics
Photo credit:Cybersecurity by cyberKid

Windows Forensics
Photo credit:Cybersecurity by cyberKid

Windows Forensics
Photo credit:Cybersecurity by cyberKid

Windows Forensics
Photo credit:Cybersecurity by cyberKid

Windows Forensics
Photo credit:Cybersecurity by cyberKid

Windows Forensics
Photo credit:Cybersecurity by cyberKid

Windows Forensics
Photo credit:Cybersecurity by cyberKid

Time Zone Information:
Windows Forensics
Photo credit:Cybersecurity by cyberKid

Windows Forensics
Photo credit:Cybersecurity by cyberKid

Windows Forensics
Photo credit:Cybersecurity by cyberKid

Windows Forensics
Photo credit:Cybersecurity by cyberKid


Ref:Cybersecurity by cyberKid

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น ช่วยเตือนความจำ


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Tuesday, February 25, 2025

Digital Forensics:Windows Forensics with Belkasoft

Digital Forensics:Windows Forensics with Belkasoft

Digital Forensics:Windows Forensics with Belkasoft
Photo credit: belkasoft 

Belkasoft เป็นผู้นำระดับโลกในด้านการตรวจพิสูจน์หลักฐานดิจิทัลและซอฟต์แวร์ตอบสนองเหตุการณ์ แพลตฟอร์ม Belkasoft X  ช่วยในการไขคดีทางนิติวิทยาศาสตร์ดิจิทัล ตอบสนองต่อเหตุการณ์ทางไซเบอร์

This course is designed for digital forensics investigators who deal with Windows computers in their work. It offers an opportunity to enhance your knowledge and gain hands-on experience in discovering and analyzing Windows artifacts.

หลักสูตรนี้ได้รับการออกแบบมาสำหรับผู้สืบสวนนิติเวชดิจิทัลที่ต้องทำงานกับคอมพิวเตอร์ บนระบบปฏิบัติการวินโดวส์ และใช้สามารถโปรแกรม Belkasoft X   วิเคราะห์หลักฐานได้

Digital Forensics:Windows Forensics with Belkasoft
Photo credit: belkasoft 

Digital Forensics:Windows Forensics with Belkasoft
Photo credit: belkasoft 


Why should Digital Forensic Investigators take this training? You will
learn:

  • How to review common Windows file systems, and which file system
  • features might be useful in a DFIR investigation
  • How to examine Windows applications, such as chats, browsers, and
  • mail clients
  • How to inspect media files and documents, and utilize media-specific
  • analysis options, such as text recognition and keyframe extraction
  • How to identify and analyze forensically important Windows system
  • files, such as registry files, event logs, and LNK files
  • How to get more evidence from a Windows data source by using
  • carving, embedded data analysis, and other advanced forensic techniques

ปกติหลักสูตรนี้ราคา 999  USD แต่ในช่วงนี้ทางbelkasoft  จะให้คุณอบรมฟรี ในช่วงเดือน ม.ค -ก.พ เท่านั้น

Digital Forensics:Windows Forensics with Belkasoft
Photo credit: belkasoft 


Digital Forensics:Windows Forensics with Belkasoft

Photo credit: belkasoft 

Download the course data  คุณจำเป็นต้องดาวน์โหลด ไฟล์หลักฐาน Image file เพื่อมาวิเคราะห์และตอบคำถามในแต่ละบทเรียน

Digital Forensics:Windows Forensics with Belkasoft
Photo credit: belkasoft 


Install or update Belkasoft Evidence Center X  คุณสามารถใช้โปรแกรมสำหรับวิเคราะห์หลักฐานได้ เป็นรุ่นทดลองใช้

Digital Forensics:Windows Forensics with Belkasoft
Photo credit: belkasoft 

Final exam สอบได้ 2 ครั้ง
Windows Forensics with Belkasoft
Windows Forensics with Belkasoft Certificate

คุณสามารถอ่านบทความทั้งหมดเพิ่มเติมได้  Belkasoft
ทีมา :   belkasoft  สมัครฟรี, เรียนฟรี
หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูล  เผยแพร่ความรู้และให้โอกาสในการค้นคว้าหาข้อมูลเพื่อการศึกษา   บุคคลที่สนใจโดยทั่วไป รวมถึงนักเรียน นิสิต นักศึกษา  ในการเรียนรู้เท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Thursday, August 22, 2024

Digital Forensics:User Access Logging (UAL)

 Digital Forensics:UAL  Log

What Is User Access Logging?

UAL is a feature included by default in Server editions of Microsoft Windows, starting with Server 2012. As defined by Microsoft, UAL is a feature that “logs unique client access requests, in the form of IP addresses and user names, of installed products and roles on the local server.”(Patrick Bennettuser, access-logging-ual-overview ,June 8, 2021)

  • User Access Logging (UAL) is enabled by default on Windows Server operating systems, starting with 2012 and later 
  • Collects user access and system-related statistical data in near real-time 
  • Examples of services and roles from which data is collected include DNS, DHCP, IIS, WSUS, etc.
  • Stored within multiple .mdb files (ESE databases) located in %SYSTEMROOT%\System32\ LogFiles\SUM 
Digital Forensics:User Access Logging (UAL)
Export  UAL log with Autopspy

  • SystemIdentity.mdb, Current.mdb, and one or more files with a GUID-based name should exist in this location
Current.mdb : The database for the current year
{GUID}.mdb : Archived data from the Current.mdb, and previous years
SystemIdentity.mdb : Contains role information and system details

Digital Forensics:User Access Logging (UAL)

Digital Forensics:User Access Logging (UAL)
Open with Autopspy

  • The GUID-based file names will hold data from the current year, the previous year, and two (2) years prior 
The GUID-based file names
Open with ESEDB Viewer

Digital Forensics:User Access Logging (UAL)
Open with ESEDB Viewer


  • Every 24 hours, data from Current.mdb will be copied to the GUID-named database for the current year 
  • SystemIdentity.mdb will track the other UAL databases and contain basic server configuration info
Digital Forensics:User Access Logging (UAL)

  • This artifact is only present on Windows Server operating systems, 2012 and later 
  • The IP address tracked is the location from which the associated activity originated; the destination is the Windows Server system from which UAL was obtained 
  • On the first day of the year, UAL will create a new GUIDnamed .mdb file 
    • The old GUID-named file is retained as an archive; after two (2) years, the original GUID.mdb will be overwritten 
Digital Forensics:User Access Logging (UAL)

  • The activity is tracked by server role, which maps to the roles configured on the Windows Server from which the data was acquired
  • This artifact can be used to identify abnormal access to systems and to profile lateral movement from various clients to servers running Windows Server 2012 or later 
  • The InsertDate is logged in UTC, and represents the first access for the year for a combination of the specific user, source IP address, and role 
  • The LastAccess is logged in UTC, and represents the last access for the year for a combination of the specific user, source IP address, and role 
  • The “File Server” role is usually associated with SMB access, but in some cases, access via other protocols may be associated with this role
Photo Credit: Microsoft  Incident Responders Team


Reference 


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น ช่วยเตือนความจำ

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD 

Monday, April 29, 2024

Digital Forensics:Guidance for Incident Responders

Guidance for Incident Responders

Digital Forensics:Guidance for Incident Responders

 It includes the following topics:
  • AmCache’s contribution to forensic investigations: The AmCache registry hive’s role in storing information about executed and installed applications is crucial, yet it’s often mistakenly believed to capture every execution event. This misunderstanding can lead to significant gaps in forensic narratives, particularly where malware employs evasion techniques. Moreover, the lack of execution timestamp specificity in AmCache data further complicates accurate timeline reconstruction.
AmCache’s contribution to forensic investigations:
  • Browser forensics: Uncovering digital behaviors: The comprehensive analysis of browser artifacts is fraught with challenges, particularly regarding the interpretation of local file access records. The misconception that browsers do not track local file access can lead to significant oversight in understanding user behavior, underscoring the need for thorough and nuanced analysis of browser data.
  • The role of Link files and Jump Lists in forensics: Link, or LNK, files and Jump Lists are pivotal for documenting user behaviors. However, investigators sometimes neglect the fact that they’re prone to manipulation or deletion by users or malware. This oversight can lead to flawed conclusions. Furthermore, Windows’ automatic maintenance tasks, which can alter or delete these artifacts, add another layer of complexity to their analysis.
The role of Link files and Jump Lists in forensics

  • Prefetch files and program execution: Prefetch files’ role in improving application launch times and their forensic value in tracking application usage is well-documented. However, the common error of conflating the prefetch file’s creation date with the last execution date of an application leads to mistaken conclusions about usage patterns. Also, overlooking the aggregation of data from multiple prefetch files can result in a fragmented understanding of application interactions over time.
Prefetch files and program execution

  • ShellBags forensic analysis: ShellBags, with their ability to record user interactions with the File Explorer environment, offer a rich source of information. Yet not all investigators recognize that ShellBags track deleted and moved folders, in addition to current ones. This oversight can lead to incomplete reconstructions of user activities.
  • Shimcache’s forensic evolution: The Shimcache has long served as a source of forensic information, particularly as evidence of program execution. However, the changes in Windows 10 and later have significantly impacted the forensic meaning of Shimcache artifacts: indicating file presence, and not indicating execution. This misunderstanding can mislead investigators, especially since Shimcache logs the last modification timestamp, not execution time, and data is only committed to disk upon shutdown or reboot.
  • Forensic insights with SRUM: SRUM’s tracking of application execution, network activity, and resource consumption is a boon for forensic analysts. However, the wealth of data can also be overwhelming, leading to crucial details being missed or misinterpreted. For instance, the temporal discrepancies between the SRUM database and system logs can confuse investigators, making it challenging to align activities accurately. Additionally, the finite storage of SRUM data means older information can be overwritten without notice, a fact that’s often overlooked, resulting in gaps in data analysis.

Forensic insights with SRUM

  • The importance of User Access Logging (UAL): UAL’s tracking of user activities based on roles and access origins is essential for security analysis, especially since this feature is designed for Windows Server operating systems (specifically 2012 and later). Its vast data volume can be daunting, leading to potential oversight of unusual access patterns or lateral movements. Additionally, the annual archiving system of UAL data can cause confusion regarding the longevity and accessibility of logs, impacting long-term forensic investigations.
  • Decoding UserAssist for forensic evidenceThe UserAssist feature’s tracking of GUI-based program interactions is often misunderstood, with analysts mistakenly prioritizing run counts over focus time. This misstep can lead to inaccurate assumptions about application usage, as focus time—a more reliable indicator of execution—gets overlooked.
Decoding UserAssist for forensic evidence

Reference Microsoft Incident Response guide

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น ช่วยเตือนความจำ

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD 

Friday, February 9, 2024

Digital Forensics:SRUDB.dat

Digital Forensics:SRUDB.dat


System Resource Utilization Monitor (SRUM) was introduced in Windows 8 and Windows Server 2019 and was designed to track the utilization of various system resources such as CPU usage, network activity, and even battery consumption. Some of the details collected as part of SRUM can be viewed in the App History tab within Task Manager, but there is much more information not displayed in the GUI

  • SRUM data is stored in a Windows ESE database located in the following file: %SYSTEMROOT%\System32\ sru\SRUDB.dat
  • SRUM is only available on Windows 8 and later and Windows Server 2019 and later

Digital Forensics:SRUDB.dat
Figure  Output of running Autopsy against the Run Programs > Data Artifacts  

SRUM tracks key information regarding application execution such as the name and path of every executed application on the system and the SID of the identity that executed the application, even if the application has since been deleted

SRUM, or System Resource Utilization Monitor, is a feature of modern Windows systems , intended to track the application usage, network utilization and system energy state.

Download Eric Zimmerman's Tools




running SrumECmd  against the location where these files reside:

 SrumECmd version 0.5.1.0

 Author: Eric Zimmerman (saericzimmerman@gmail.com)
 https://github.com/EricZimmerman/Srum

 Examples: SrumECmd.exe -f "C:\Temp\SRUDB.dat" -r "C:\Temp\SOFTWARE" --csv
 "C:\Temp\"
           SrumECmd.exe -f "C:\Temp\SRUDB.dat" --csv "c:\temp"
           SrumECmd.exe -d "C:\Temp" --csv "c:\temp"

           Short options (single letter) are prefixed with a single dash. Long

 commands are prefixed with two dashes


sage:
 SrumECmd [options]

ptions:
 -f <f>                  SRUDB.dat file to parse
 -r <r>                  SOFTWARE hive to process. This is optional, but
                         recommended
 -d <d>                  Directory to recursively process, looking for
                         SRUDB.dat and SOFTWARE hive. This mode is primarily
                         used with KAPE so both SRUDB.dat and SOFTWARE hive
                         can be located
 --csv <csv> (REQUIRED)  Directory to save CSV formatted results to. Be sure
                         to include the full path in double quotes
 --dt <dt>               The custom date/time format to use when displaying
                         time stamps. See https://goo.gl/CNVq0k for options
                          [default: yyyy-MM-dd HH:mm:ss]
 --debug                 Show debug information during processing [default:
                         False]
 --trace                 Show trace information during processing [default:
                         False]
 --version               Show version information
 -?, -h, --help          Show help and usage information

Command 
#C:\Users\...\Downloads\SrumECmd>SrumECmd.exe -f "C:\VM\...\AD01\0001\Exp
ort\srudb.dat" --csv "C:\VM\...\AD01\0001\Export\temp"


Examine output in Timeline Explorer!

System Resource Utilization Monitor artifacts :

  • SRUM Application Resource Usage
  • SRUM Network Connections
  • SRUM Network Usage
  • SRUM Push Notification Data
  • SRUM Energy Usage


Windows artifacts


Refer:  

     

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น ช่วยเตือนความจำ

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD 



Wednesday, February 22, 2023

DIGITAL FORENSICS:How To Check If Someone Else Is Using Your Computer

DIGITAL FORENSICS:How To Check If Someone Else Is Using Your Computer

This is another digital forensics image that was prepared to cover a full Windows Forensics course.

System Image: here

Forensic Artifacts

Windows Logon Events  วิธีการเช็ค Logon events

Windows  will automatically annotate a login every time one occurs. This means that each time you log in, the time and date is tracked and noted for you to see. 

Export Security event
Export Event security.evtx ('c:/Windows/System32/Winevt/logs/Security.evtx)
Export Security event

Event ID: 4608 Windows is starting up 21-6-2016 6:40


Event ID: 4624 An account was successfully logged on. 21-6-2016 8:07

Windows Logon Events 4624

Event ID: 4672 Special privileges assigned to new logon 21-6-2016 8:07

Event ID: 4672 Special privileges assigned to new logon

Event ID: 4616 The system time was changed. 21-6-2016 7:58

Event ID: 6013 The system uptime is <number> seconds. 21-6-2016 8:41

The system uptime is <number> seconds.


Anonymous Logon / Null



Program execution artifacts

Program execution artifacts indicate programs or applications that were run on the system. The user could cause the execution, or it could be an autostart/run event managed by the system. Some categories overlap with the file knowledge category we discussed earlier in the chapter. I am not going to re-examine those specific artifacts in this section. Just be aware that the artifacts from recent apps, JumpLists, an MRU, and prefetch files will also contain information about program/application activity. 

Program execution artifacts

Prefetch  Windows Prefetch files, are designed to speed up the application startup process. The Prefetch files are stored into the path

 %windir%\Prefetch

and contains the name of the executable, a Unicode list of DLLs used by that executable, a count of how many times the executable has been run, and a timestamp indicating the last time the program was run.

Prefetch
Export *.pf file 
Prefetch
Last Run Time CCLEANER.exe  21-6-2016 12:28

Prefetch

Browser History & Web Search เช็คประวัติบราวเซอร์

Google Chrome, Firefox, and Edge all have a way of allowing you to see your search history. You can usually find it in the Settings, whichever icon that may be, toward the top-right of the screen. Click on it and locate History, then backtrack through it to see if you can notice any inconsistencies. Look for unfamiliar websites as they can be a classic sign that someone else has been accessing your computer.

Web Search 21-6-2016 15:53 "Skype" , 21-6-2016 16:29"kitties"

Browser History

Browser History

Recent Activities เช็คเปิดใช้ไฟล์ล่าสุด

Status checks on specific files and folders is a great way to determine if unauthorized users have been accessing your computer.

How To Check If Someone Else Is Using Your Computer

วิธีตรวจสอบว่ามีคนอื่นใช้คอมพิวเตอร์ของคุณหรือไม่

อ่านเพิ่มเติม : How to Determine the Last Shutdown Time and Date in Windows

                 LastActivityView , 


ที่มา: ultimatewindowssecurity

         Digital Forensic Challenge Images (Datasets)


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics #digitalforensics #investigation #cybercrime #fraud

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...