Académique Documents
Professionnel Documents
Culture Documents
Categories of Artifacts
What will we • Account Usage, Browser Usage, File Download,
talk about? File/Folder Opening, Program Execution, Deleted
Files, USB Devices, Services & Tasks, PowerShell
Timelines
• $MFT
• PLASO/Super TimeLine
Hints, Tips & Tricks
What is DFIR? DFIR Intro
Digital Forensics &
Incident Response
File/Folder Opening – Open/Save MRU, Recent Files, Shell Bags, LNK Files, Jump
Lists, Prefetch
Categories Program Execution – UserAssist, Last-Visited MRU, Run MRU, AppCompatCache,
Amcache, Jump Lists, Prefetch
of Artifacts Deleted Files – Recycle.bin
Services & Tasks – Service Events, Scheduled Tasks events, .job Files
• TerminalServices-
RemoteConnectionManager
Log – Event ID 1149
• History • Cache
• IE10,11,Edge – • IE11 –
%UserProfile%\AppData\Local\Micro
Browser %UserProfile%\AppData\Local\Microsoft\
Windows\WebCache\WebCacheV*.dat • Edge -
soft\Windows\INetCache\IE
• Firefox – %UserProfile%\AppData\Local\Packa
Usage %UserProfile%\AppData\Roaming\Mozilla\
Firefox\Profiles\<random
ges\Microsoft.microsoftedge_<Ap
pID>\AC\MicrosoftEdge\Cache
text>.default\places.sqlite • Firefox –
• Chrome – %UserProfile%\AppData\Local\Mozill
%UserProfile%\AppData\Local\Google\Chr a\Firefox\Profiles\<randomtext>.d
ome\User Data\Default\History efault\Cache
• Chrome –
• Cookies
%UserProfile%\AppData\Local\Googl
• IE11 – e\Chrome\User Data\Default\Cache
%UserProfile%\AppData\Local\Microsoft\
Windows\INetCookies • Flash & Super Cookies
• Edge – • Local Stored Objects (LSOs) or Flash
Cookies are stored when visited website
%UserProfile%\AppData\Local\Packages\M uses Flash. These cookies do not expire,
icrosoft.microsoftedge_<AppID>\AC\Micros and rarely get cleared
oftEdge\Cookies
%APPDATA%\Roaming\Macromedia\FlashPla
• Firefox – yer\#SharedObjects\<randomprofileid>
%UserProfile%\AppData\Roaming\Mozilla\
Firefox\Profiles\<randomtext>.default\cook
ies.sqlite
• Chrome –
%UserProfile%\AppData\Local\Google\Chr
ome\User Data\Default\Local Storage\
Open/Save Most Recently Used History
Deleted Files
USB Devices
• USBStor
SYSTEM\CurrentControlSet\Enum\
USBSTOR
SYSTEM\CurrentControlSet\Enum\
USB
• PnP Events
• SYSTEM Event Log
• Event ID 20001 – Plug and
Play driver install attempted
• LNK Files
• Services
• Event Logs
SYSTEM Event Logs – Event IDs
7034,7035,7036,7040
• Registry
SYSTEM\CurrentControlSet\Services
• Scheduled Tasks
• Event Logs
SECURITY Event Logs – Event ID 4698,
4702
• Tasks .xml Config Files
• %ROOT%\Windows\SYSTEM32\Tasks
• Event Logs
• Microsoft-Windows-PowerShell-
Operational
Event IDs 4104-4106
Cool Example of
Obfuscated Code
TIMELINES!
Hints, Tips and Tricks