• Share
  • Email
  • Embed
  • Like
  • Save
  • Private Content
Windows forensic artifacts
 

Windows forensic artifacts

on

  • 4,881 views

null Pune November'11 Meet

null Pune November'11 Meet

Statistics

Views

Total Views
4,881
Views on SlideShare
4,258
Embed Views
623

Actions

Likes
5
Downloads
0
Comments
0

1 Embed 623

http://null.co.in 623

Accessibility

Categories

Upload Details

Uploaded via as Microsoft PowerPoint

Usage Rights

© All Rights Reserved

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Processing…
Post Comment
Edit your comment

    Windows forensic artifacts Windows forensic artifacts Presentation Transcript

    • Windows Forensic Artifacts http://null.co.in/ http://nullcon.net/ Pardhasaradhi.ch a.k.a babloo 09762310104 [email_address]
    • http://null.co.in/ http://nullcon.net/ Agenda Introduction Steps of forensics investigation Rules of Forensics investigations Terminology Windows Artifacts Browser artifacts Tools which can be used Evidence gathering Without Tools
    • http://null.co.in/ http://nullcon.net/ Introduction to Forensics
        • It is the application of computer investigation and analysis techniques to gather evidence
        • It is also called as cyber forensics
        • The goal of computer forensics is to perform a structured investigation while maintaining a documented chain of evidence to find out exactly what happened on a computer and who was responsible for it.
    • http://null.co.in/ http://nullcon.net/ Steps of Forensics
    • http://null.co.in/ http://nullcon.net/ Rules of Forensics investigation
        • Never mishandle Evidence
        • Never trust the subject operating system
        • Never work on original evidence
        • Never work on original evidence
    • http://null.co.in/ http://nullcon.net/ Terminology C
      • Cloning
        • Storing contents of one disk to another
      • Imaging
        • Storing of contents of a disk to a image / disk
      • Carving
        • Process of extracting data from the disk / image
      • File Slack
      • The space between the end of a file and the end of the disk cluster it is stored in.
      • Unallocated Space
        • Free space which is available to write the data
      • Steganography
        • A technique of hiding text in images
      • Orphan
      • A file that was once associated with a program that still remains on the
      • Computer even after the program has been uninstalled.
    • http://null.co.in/ http://nullcon.net/ Windows Artifacts
      • Thumbs.db
      • Index.dat
      • Hiberfil.sys
      • System volume information
      • Pagefile.sys
      • Prefetch
      • Sticky notes
      • NTUSER.dat and Usrclass.dat
      • Event Logs and audit logs
    • http://null.co.in/ http://nullcon.net/ Browser artifacts in Windows Default auto bookmarks location for Firefox C:Users......AppDataRoamingMozillaFirefoxProfiles,,,,.default Default location Saved Passwords C:Users...AppDataRoamingMozillaFirefoxProfilesl6jq0hlt.defaultKey3.db C:Users...AppDataRoamingMozillaFirefoxProfilesl6jq0hlt.defaultsignons.Sqllite
    • http://null.co.in/ http://nullcon.net/ Using a Dump File We can get User details System Activity Almost every thing using third party tools
    • http://null.co.in/ http://nullcon.net/ Tools Can be used FTK Encase DFF ADDONS Parbens Stegosuite Volatility TZwork sbag
    • http://null.co.in/ http://nullcon.net/ Without tools How can we extract the data ? USB devices :: HKLMSystemControlset00xEnumUSBSTOR what Information can be found Vendor ID, Product ID, Revision, Device ID / Serial Number Mounted Devices HKLMSystemMounted Devices What information can be found This key views each drive connected to the system 
    • http://null.co.in/ http://nullcon.net/ Task manager Event logs Network and performance monitor Task scheduler Windows Update history System files MAC table Commands in cli / Powershell Computer management Regedit Msconfig Prefetch
    • Thank You Pardhasaradhi.ch 09762310104 www.pardhasaradhi.info [email_address]