Forensic Triage and Event Logs Flashcards
Steps of strategy for Forensic Triage
- Grab a forensic triage
- Start a full image
- Analyze the triage while the full image is being collected.
Good things to grab quickly
Recently Accessed
Directories recently opened
Executables recently executed
LNK Files
Recently Accessed in the recents
directory.
i.e. Desktop Shortcuts
Jump Lists
Recently Accessed + what application.
Right click on a Word Doc.
Shell Bags
Recently Opened Directories
Specific information about each particular folder.
Prefetch
Recently Executed
\Windows\Prefetch
How to collect triage items?
Custom content image with FTK Imager
Images using KAPE
Event Logs Characteristics
Type - Kind of log
Provider - What generated this?
Event ID - What happened?
Interesting log types
Security logs - Logon, logoff, program execution, security group membership.
Application Logs - Made by app developers
System logs - General info about the system.
What command to export logs?
wevtutil epl on evtx files