- •The project has been funded by the European Commission. The Education, Audiovisual and
- •Windows Artefacts
- •Content
- •Introduction
- •Introduction
- •Introduction
- •Introduction
- •Introduction
- •Introduction
- •Introduction
- •Introduction
- •Introduction
- •Introduction
- •Windows Artefacts
- •Methodology
- •Methodology
- •Leaves on harddisk
- •Leaves on Harddisk
- •Leaves on Harddisk
- •Approach to analyzing local tracks
- •Limits: Portable Software
- •Limits: Portable Software
- •Limits Malware
- •Special software
- •Approaches
- •Sandboxies
- •What is a Sandbox
- •What is Sandboxies
- •Advances of Sandboxies
- •Alternatives for sandboxies
- •Virtualization with EvaLaze
- •Virtualization with EvaLaze
- •Sanboxies
- •How does Sandboxies work?
- •Automasition commandline
- •Recovery in Sandboxie
- •Analyse of Sandboxie Results
- •Redirecting Registry
- •Redirecting Registry
- •Logfiles of Hives
- •Analyzing Sanboxie-Registry Hives
- •Analyzing Sanboxie-Registry Hives
- •Runtime behavior
- •Overview
- •Using of Jabber with Jabbin
- •Usage in practise
- •The project has been funded by the European Commission. The Education, Audiovisual and
- •Windows OS-Artifacts
- •Typical application traces
- •File access via mailer
- •FTP-Client
- •FTP-Client
- •FTP-Client
- •FileShare P2P:eMule
- •FileShare P2P: BitTorrent
- •FileShare P2P: BitTorrent
- •FileShare P2P: μTorrent
- •BitTorrent Forensic
- •Virusscanner
- •Firewall Win 7
- •Windows Eventlogs
- •Windows Eventlogs
- •Windows Eventlogs
- •Windows Eventlogs
- •Windows Eventlogs
- •Windows Eventlogs
- •Windows Eventlogs
- •Windows Eventlogs
- •Windows Eventlogs
- •openVPN
- •openVPN
- •The project has been funded by the European Commission. The Education, Audiovisual and
- •Windows OS-Artifacts
- •Operating System
- •Windows Operating System
- •Windows Folder Structure
- •Artifacts of Forensic Interest
- •USER PROFILES
- •Which Version ?
- •Application Data
- •Application Data (subfolders)
- •AppData Local
- •Appdata LocalLow
- •AppData Roaming
- •SUMMARY
- •Registry Description
- ••what kind of information is actually stored there?
- •Registry Information
- •Registry’s Structure
- •HKEY_LOCAL_MACHINE -HKML
- •HKEY_LOCAL_MACHINE -HKML
- •And what about user data?
- •NTUSER.DAT location in Windows XP
- •NTUSER.DAT location in Windows 7
- •Registry Files Examination
- •From Forensics point of view
- •Examples
- •RESTORE POINTS vs. VOLUME SHADOW COPY
- •RESTORE POINTS vs. VOLUME SHADOW COPY
- •RESTORE POINTS (Windows XP)
- •RESTORE POINTS (Windows 7)
- •RESTORE POINTS vs. VOLUME SHADOW COPY
- •RESTORE POINTS (Windows XP)
- •RESTORE POINTS vs. VOLUME SHADOW COPY
- •VOLUME SHADOW COPY
openVPN
•openVPN Client ist auf dem Rechner installiert
•Binaries und Konfig. unter
C:\Program Files\OpenVPN
•\Bin Binaries
•GUI
•Libraries
•Openvpn Client und Server
SVA Modul Internet 2.2.5 Teil 2 |
71 |
openVPN
•Config Zertifikat and Key, configuration file
•Findings on infrastructure
•\log Ordner contains the Client Logs
The project has been funded by the European Commission. The Education, Audiovisual and Culture Executive program (EACEA), TEMPUS IV. The content of this presentation reflects the opinion of the author.
Windows Artifacts
Digital Forensic
Developers:
C. Yesil
Windows OS-Artifacts
By the end of the presentation participants will be able to:
•Identify at least 2 artifacts of forensic interest;
•Identify, at a glance differences between Windows XP and Windows Vista /7
•Overview of Registry Hives & RPs/Shadow Copy
Operating System
•An operating system communicates with the hardware.
•It is comprised of system software.
•Common desktop operating systems:
•Windows,
•Mac OS X,
•and Linux.
Windows Operating System
Windows Folder Structure
•Folder structures within OS may vary.
•The “OS” will install the hierarchical structure in a unique way.
•OS decides Where and What info is stored.
Artifacts of Forensic Interest
•User Profiles
•Application Data
•Registry
•Restore Points (RP)
•Volume Shadow Copies (VSS)
USER PROFILES
•Contains user configuration settings / files on a Windows XP\Vista\7 system.
|
|
Location Found |
Windows Version |
SystemRoot |
Note: XP systems upgrade |
|
from NT may have profile |
|
located here |
|
|
Documents and Settings\Username |
XP |
\Users |
Vista, 7, 8 |
|
|
Which Version ?
Windows 7 / 8
Windows
XP
